Altigen MAXCS ACC 6.5 Administration Manual page 252

Maxcs acc system
Table of Contents

Advertisement

Chapter 17: AltiGen IP Phone Configuration
Parameter
SIP
Transport
238
MAXCS ACC 6.5 Administration Manual
Description
These settings secure the SIP signaling messages and the RTP.
SIP signaling is secured using transport layer security (TLS).
RTP or SIP-associated media is secured using the secure RTP
(SRTP) protocol.
• Persistent TLS—Check this setting to have the selected
extension communicate using TLS. The TLS protocol allows
applications to communicate across a network in a way
designed to prevent eavesdropping, tampering, and
message forgery. TLS provides endpoint authentication and
communications privacy for VoIP systems using
cryptography.
If either side initiates SIP messaging with an alternate
transport like UDP or TCP, these are supported, as well.
If Persistent TLS is checked for a third-party IP
Note:
phone, you also need to configure the phone, itself, for
TLS.
If the third-party phone initiates a UDP SIP message,
and Persistent TLS is checked in MAXCS, then the
SIP connection will fail.
• SRTP—Check this setting to have the selected extension use
SRTP. SRTP is a version of RTP that provides confidentiality
and message authentication. Since the SRTP session key is
sent in the SIP signaling via SDP, the key can be exposed to
eavesdropping. So SRTP needs to co-exist with TLS for the
communication to be fully secure.
If SRTP is checked, the voice stream always goes through
the server.
If the IP phone is behind NAT, UDP will be used even if TLS and
SRTP are checked, since TLS cannot penetrate NAT.
IP Phone Configuration vs Enterprise Manager
configuration:
SIP calls from one Altigen server to another go through a SIP
Tie Trunk. Configuring TLS for this scenario is done in
Enterprise Manager. See "SIP Transport" in the table on page
346.
Extension level policy has priority over the codec profile policy.
If the IP extension supports TLS and the codec profile set in
Enterprise Manager does not, then the IP extension policy
holds. That way you can configure a range of IP addresses in
the IP Dialing table or IP Codec screen, and have only a few IP
addresses/extensions support TLS.
If the IP extension does not have TLS configured as its
transport, but the codec profile supports TLS for that extension,
then the codec profile policy holds.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Max communication server acc 6.5

Table of Contents