Sip Authentication Trust - Cisco TelePresence Video Communication Server Administrator's Manual

Hide thumbs Also See for TelePresence Video Communication Server:
Table of Contents

Advertisement

SIP
The behavior for SIP messages depends upon whether the message was received from a local
domain (a domain for which the VCS is authoritative) or a non-local domain.
Authentication
In local domain
policy
Check
Messages are challenged for
credentials
authentication and those that
pass are classified as
authenticated.
Messages (including
registration requests) that fail
authentication are rejected.
Do not check
Messages are not challenged
credentials
for authentication.
All messages are classified as
unauthenticated.
Treat as
Messages are not challenged
authenticated
for authentication.
All messages are classified as
authenticated.

SIP authentication trust

If a VCS is configured to use
INVITE requests. If the VCS then forwards the request on to a neighbor zone such as another VCS,
that receiving system will also authenticate the request. In this scenario the message has to be
authenticated at every hop.
To simplify this so that a device's credentials only have to be authenticated once (at the first hop), and
to reduce the number of SIP messages in your network, you can configure neighbor zones to use the
Authentication trust mode setting.
This is then used in conjunction with the zone's Authentication Policy to control whether pre-
authenticated SIP messages received from that zone are trusted and are subsequently treated as
authenticated or unauthenticated within the VCS. Pre-authenticated SIP requests are identified by the
presence of a P-Asserted-Identity field in the SIP message header as defined by RFC 3325 [35]
The Authentication trust mode settings are:
On: pre-authenticated messages are trusted without further challenge and subsequently treated as
n
authenticated within the VCS. Unauthenticated messages are challenged if the Authentication
Policy is set to Check credentials.
Off: any existing authenticated indicators (the P-Asserted-Identity header) are removed from the
n
message. Messages from a local domain are challenged if the Authentication Policy is set to
Check credentials.
Note: you are recommended to enable authentication trust only if the neighbor zone is part of a
network of trusted SIP servers.
Cisco VCS Administrator Guide (X6.1)
Outside local domain
SIP messages received from non-local
domains are all treated in the same manner,
regardless of the subzone's Authentication
policy setting:
Messages are not challenged for
authentication.
All messages are classified as
unauthenticated.
device authentication
it will authenticate incoming SIP registration and
Device authentication
Page 74 of 401

Advertisement

Table of Contents
loading

Table of Contents