Provisioning Overview - Cisco SPA921 - - IP Phone Provisioning Manual

Voice system, voice gateways, and ip telephones
Hide thumbs Also See for SPA921 - Cisco - IP Phone:
Table of Contents

Advertisement

Provisioning Cisco Small Business VoIP Devices

Provisioning Overview

Provisioning Overview
NOTE
Cisco Small Business IP Telephony Devices Provisioning Guide
The Cisco Small Business IP Telephony Devices support secure remote
provisioning and firmware upgrades. Configuration profiles can be generated by
by using common, open source tools that facilitate integration into service
provider provisioning systems. Supported transport protocols include TFTP, HTTP,
and HTTPS with a client certificate. Cisco Small Business provisioning solutions
are designed for high-volume residential deployment, where each IP Telephony
Device typically resides in a separate LAN environment that is connected to the
Internet with a NAT device.
An IP Telephony Device can be configured to resynchronize its internal
configuration state to a remote profile periodically and on power up. A 256-bit
symmetric key encryption of profiles is supported. In addition, an unprovisioned IP
Telephony Device can receive an encrypted profile specifically targeted for that
device without requiring an explicit key. Secure first-time provisioning is provided
through a mechanism that uses SSL functionality.
Remote customization (RC) units are customized by Cisco so that when the unit is
started, it tries to contact the Cisco provisioning server to download its customized
profile.
User intervention is not required to initiate or complete a profile update or
firmware upgrade. Remote firmware upgrade is achieved via TFTP or HTTP, but
not using HTTPS because the firmware does not contain sensitive information that
can be read by a customer. The upgrade logic is capable of automating multi-
stage upgrades, if intermediate upgrades are required to reach a future upgrade
state from an older release. A profile resync is only attempted when the IP
Telephony Device is idle, because this may trigger a software reboot.
General purpose parameters are provided to help service providers to manage
the provisioning process. Each IP Telephony Device can be configured to
periodically contact a normal provisioning server (NPS). Communication with the
NPS does not require the use of a secure protocol because the updated profile is
encrypted by a shared secret key. The NPS can be a standard TFTP, HTTP or
HTTPS server.
1
12

Advertisement

Table of Contents
loading

Table of Contents