Altigen ACM 6.7 Administrator's Manual page 237

Max communication server
Table of Contents

Advertisement

Parameter
Description
Debug
This is for debugging the IP phone using Telnet. You need to enter a
Diagnostic password when logging in to MaxAdmin (before you enter
your Admin password) to enable this configuration.
SIP
These settings secure the SIP signaling messages and the RTP. SIP
Transport
signaling is secured using transport layer security (TLS). RTP or SIP-
associated media is secured using the secure RTP (SRTP) protocol.
• Persistent TLS—Check this setting to have the selected extension
communicate using TLS. The TLS protocol allows applications to
communicate across a network in a way designed to prevent
eavesdropping, tampering, and message forgery. TLS provides
endpoint authentication and communications privacy for VoIP systems
using cryptography.
If either side initiates SIP messaging with an alternate transport like
UDP or TCP, these are supported, as well.
Note:
• SRTP—Check this setting to have the selected extension use SRTP.
SRTP is a version of RTP that provides confidentiality and message
authentication. Since the SRTP session key is sent in the SIP signaling
via SDP, the key can be exposed to eavesdropping. So SRTP needs to
co-exist with TLS for the communication to be fully secure.
If SRTP is checked, the voice stream always goes through the server.
If the IP phone is behind NAT, UDP will be used even if TLS and SRTP
are checked, since TLS cannot penetrate NAT.
IP Phone Configuration vs Enterprise Manager configuration:
SIP calls from one Altigen server to another go through a SIP Tie Trunk.
Configuring TLS for this scenario is done in Enterprise Manager. See "SIP
Transport" in the table on page 322.
Extension level policy has priority over the codec profile policy.
If the IP extension supports TLS and the codec profile set in Enterprise
Manager does not, then the IP extension policy holds. That way you can
configure a range of IP addresses in the IP Dialing table or IP Codec
screen, and have only a few IP addresses/extensions support TLS.
If the IP extension does not have TLS configured as its transport, but the
codec profile supports TLS for that extension, then the codec profile
policy holds.
If Persistent TLS is checked for a third-party IP phone, you
also need to configure the phone, itself, for TLS.
If the third-party phone initiates a UDP SIP message, and
Persistent TLS is checked in MAXCS, then the SIP connection
will fail.
MAXCS ACM 6.7 Administration Manual 223
Configuring the AltiGen IP Phone

Advertisement

Table of Contents
loading

Table of Contents