Configuring A Timeout For A Sip Media Secure Port; Enabling Instant Messaging - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring a SIP Parameter Map

Configuring a Timeout for a SIP Media Secure Port

Enabling Instant Messaging

Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
3-118
To remove the parameter map from the configuration, enter:
host1/Admin(config)# no parameter-map type sip SIP_PARAMMAP
The ACE opens a temporary secure port (pinhole) to stream media to a SIP client.
To prevent a hacker from exploiting this port, set a timeout for SIP media by using
the timeout command in parameter map SIP configuration mode.
The syntax of this command is as follows:
timeout sip-media number
The number argument is the timeout in seconds for the media port. Enter an
integer from 1 to 65535 seconds. The default is 5 seconds. Be sure to provide a
timeout value that is large enough for streaming media applications to complete.
For example, to specify a secure streaming media port timeout value of 1 hour,
enter:
host1/Admin(config)# parameter-map type sip SIP_PARAMMAP
host1/Admin(config-parammap-sip)# timeout sip-media 3600
To return the streaming media port timeout value to the default of 5 seconds,
enter:
host1/Admin(config-parammap-sip)# no timeout sip-media 3600
You can enable instant messaging (IM) over SIP after it has been disabled by
using the im command in parameter map SIP configuration mode. By default, IM
is disabled.
The syntax of this command is as follows:
im
For example, to enable instant messaging, enter:
host1/Admin(config)# parameter-map type sip SIP_PARAMMAP
host1/Admin(config-parammap-sip)# im
Chapter 3
Configuring Application Protocol Inspection
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents