Data Security; Data Security Overview; Secure Http - Dialogic DMG1000 User Manual

Dialogic 1000 and 2000 media gateway series
Hide thumbs Also See for DMG1000:
Table of Contents

Advertisement

Data Security

Information about data security and how it is supported by the Dialogic
described in the following sections:

Data Security Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171

Secure HTTP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171

SIP Call Control Security using TLS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 173
Secure Voice Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
Installing Certificate Using Internet Explorer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
7.1
Data Security Overview
Data security on the Media Gateway includes the use of various secure protocols when transmitting
and receiving data. The Media Gateway secures three types of data:
HTTP - The data transmitted between the Media Gateway and a Web browser. To secure
HTTP, the Media Gateway uses the Secure HTTP (HTTPS) protocol.
Call Control - The data used to setup and tear down a call. To secure Call Control, the Media
Gateway uses Transport Layer Security (TLS) on top of SIP
Voice - The actual conversation once a call is connected. To secure voice, the Media Gateway
uses Secure RTP (SRTP).
Note: The Media Gateway does not support security for the H.323 protocol. If H.323 protocol is selected,
TLS and SRTP are not supported and call control and voice data can't be secured.
Note: H.323 is only supported in Version 5.1 SU1 Software or earlier.
The HTTPS and TLS protocols require digital identity certificates (e.g. public key certificates).
Therefore, certificate management is also covered in this section.
7.2
Secure HTTP
HTTP data is transmitted as messages between the Media Gateway and a Web browser. These
messages travel on the network as clear text and can be "listened" to by anyone. Even though the
HTTP interface has access security (via a password), privacy is not secure.
As an example, if a message containing a request to change a password were captured by a hacker
or third party, the hacker or third party could log on to the Media Gateway and change the
configuration. HTTPS safeguards HTTP data by encryption and authentication. With HTTPS,
messages are no longer transmitted as clear text and are not readily readable.
®
Dialogic
1000 and 2000 Media Gateway Series User's Guide — September 2007
Dialogic Corporation
7
Media Gateway is
®
171

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents