Security Parameters; Table 4-4: Security Parameters - AudioCodes Mediant 1000 User Manual

Voice-over-ip (voip) sip media gateways
Hide thumbs Also See for Mediant 1000:
Table of Contents

Advertisement

4.4.4

Security Parameters

ini File Parameter
EnableMediaSecurity
MediaSecurityBehaviou
r
EnableSIPS
TLSVersion
TLSLocalSIPPort
TLSReHandshakeInterv
al
PeerHostNameVerificati
onMode
VerifyServerCertificate Determines whether the device, when acting as client for TLS connections,
OCSPEnable
SIP User's Manual

Table 4-4: Security Parameters

For a description of this parameter, refer to ''Configuring the General
Security Settings'' on page 123.
For a description of this parameter, refer to ''Configuring the General
Security Settings'' on page 123.
For a description of this parameter, refer to ''General Parameters'' on page
166.
For a description of this parameter, refer to ''Configuring the General
Security Settings'' on page 123.
For a description of this parameter, refer to ''General Parameters'' on page
166.
Defines the time interval (in minutes) between TLS Re-Handshakes
initiated by the device.
The interval range is 0 to 1,500 minutes. The default is 0 (i.e., no TLS Re-
Handshake).
Determines whether the device verifies the Subject Name of a remote
certificate when establishing TLS connections.
[0] = Disable (default).
[1] = Verify Subject Name only when acting as a server for the TLS
connection.
[2] = Verify Subject Name when acting as a server or client for the TLS
connection.
When a remote certificate is received and this parameter is not disabled,
the SubjectAltName value is compared with the list of available Proxies. If a
match is found for any of the configured Proxies, the TLS connection is
established.
The comparison is performed if the SubjectAltName is either a DNS name
(DNSName) or an IP address. If no match is found and the
SubjectAltName is marked as 'critical', the TLS connection is not
established.
If the SubjectAltName is not marked as 'critical' and there is no match, the
CN value of the SubjectName field is compared with the parameter
TLSRemoteSubjectName. If a match is found, the connection is
established. Otherwise, the connection is terminated.
verifies the Server certificate. The certificate is verified with the Root CA
information.
[0] = Disable (default).
[1] = Enable.
Note: If Subject Name verification is necessary, the parameter
PeerHostNameVerificationMode must be used as well.
Enables or disables certificate checking using Online Certificate Status
Protocol (OCSP).
[0] = Disable (default).
[1] = Enable.
314
Mediant 1000 & Mediant 600
Description
Document #: LTRT-83303

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mediant 600

Table of Contents