Srtp Configuration - Yealink SIP-T2 Series Administrator's Manual

Hide thumbs Also See for SIP-T2 Series:
Table of Contents

Advertisement

Administrator's Guide for SIP-T2 Series/T4 Series/T5 Series/CP920 IP Phones
The callee receives the INVITE message with the RTP encryption algorithm, and then answers the call by responding
with a 200 OK message which carries the negotiated RTP encryption algorithm.
Example of the RTP encryption algorithm carried in the SDP of the 200 OK message:
m=audio 11780 RTP/SAVP 0 101
a=rtpmap:0 PCMU/8000
a=rtpmap:101 telephone-event/8000
a=crypto:1 AES_CM_128_HMAC_SHA1_80 inline:NGY4OGViMDYzZjQzYTNiOTNkOWRiYzRlMjM0Yzcz
a=sendrecv
a=ptime:20
a=fmtp:101 0-15
When SRTP is enabled on both IP phones, RTP streams will be encrypted, and a lock icon appears on the LCD screen of
each IP phone after successful negotiation.
Note
If you enable SRTP, then you should also enable TLS. This ensures the security of SRTP encryption. For more information on
Transport Layer Security (TLS)
TLS, refer to
SDP offers by "account.X.srtp.unencrypted_rtp.enable"/"account.X.srtp.unencrypted_rtcp.enable".
Topic

SRTP Configuration

SRTP Configuration
The following table lists the parameters you can use to configure the SRTP.
Parameter account.X.srtp_encryption
Description It configures whether to use voice encryption service.
0-Disabled
Permitted
1-Optional, the IP phone will negotiate with the other IP phone what type of encryption to use for the ses-
Values
sion.
2-Compulsory, the IP phone must use SRTP during a call.
Default
0
Web UI
Account->Advanced->RTP Encryption(SRTP)
Parameter account.X.srtp_lifetime
It configures the lifetime of the master key used for the cryptographic parameter in SDP. The value spe-
cified is the number of SRTP packets.
When the lifetime is set, a re-invite with a new key is sent when the number or SRTP packets sent for an
Description
outgoing call exceeds half the value of the master key lifetime.
Note: Setting this parameter to a non-zero value may affect the performance of the phone. It works only
if "account.X.srtp_encryption" is set to 1 (Optional) or 2 (Compulsory).
Permitted Integer greater than or equal to 0
388
. You can configure the IP phone to include unencrypted RTP/RTCP streams in
[1]
[1]
<MAC>.cfg
<MAC>.cfg

Advertisement

Table of Contents
loading

Table of Contents