AudioCodes Mediant 4000 SBC User Manual page 198

Hide thumbs Also See for Mediant 4000 SBC:
Table of Contents

Advertisement

'a=setup' attribute. The 'a=setup:actpass' attribute value is used in the SDP offer by the
device. This indicates that the device is willing to be either a client ('act') or a server ('pass')
in the handshake. The 'a=setup:active' attribute value is used in the SDP answer by the
device. This means that the device wishes to be the client ('active') in the handshake.
a=setup:actpass
a=fingerprint: SHA-1
\4A:AD:B9:B1:3F:82:18:3B:54:02:12:DF:3E:5D:49:6B:19:E5:7C:AB
DTLS cipher suite reuses the TLS cipher suite. The DTLS handshake is done for every
new call configured for DTLS. In other words, unlike TLS where the connection remains
"open" for future calls, a new DTLS connection is required for every new call. Note that the
entire authentication and key exchange for securing the media traffic is handled in the
media path through DTLS. The signaling path is used only to verify the peers' certificate
fingerprints. DTLS messages are multiplexed onto the same ports that are used for the
media.
To configure DTLS:
1.
In the TLS Context table (see ''Configuring TLS Certificate Contexts'' on page 95),
configure a TLS Context for DTLS.
2.
Open the IP Groups table (see ''Configuring IP Groups'' on page 326) and for the IP
Group associated with the SIP entity, assign it the TLS Context for DTLS, using the
'DTLS Context' parameter (IPGroup_DTLSContext).
3.
Open the IP Profiles table (see ''Configuring IP Profiles'' on page 384) and for the IP
Profile associated with the SIP entity, configure the following:
Configure the 'SBC Media Security Mode' parameter
(IPProfile_SBCMediaSecurityBehavior) to SRTP or Both.
Configure the 'Media Security Method' parameter
(IPProfile_SBCMediaSecurityMethod) to DTLS.
Configure the 'RTCP Mux' parameter (IpProfile_SBCRTCPMux) to Supported.
Multiplexing is required as the DTLS handshake is done for the port used for RTP
and thus, RTCP and RTP must be multiplexed onto the same port.
Configure the ini file parameter, SbcDtlsMtu (or CLI command configure voip >
sbc settings > sbc-dtls-mtu) to define the maximum transmission unit (MTU) size
for the DTLS handshake.
Note:
The 'Cipher Server' parameter must be configured to "ALL".
The device does not support forwarding of DTLS transparently between endpoints.
User's Manual
198
Mediant 4000 SBC
Document #: LTRT-41729

Advertisement

Table of Contents
loading

Table of Contents