Advanced Operational Features

Aastra Web UI

3.In the “Root and Intermediate Certificates Filename” field, enter the filename that contains the root and intermediate certificates related to the local certificate. For example: root_Intermed_certifi.pem.

4.In the “Local Certificate Filename” field, enter the filename that contains the local certificate. For example: localcertificate.pem.

5.In the “Private Key Filename” field, enter the filename that contains the private key. For example: privatekey.pem.

6.In the “Trusted Certificates Filename” field, enter the filename that contains the trusted certificates. For example: trusted_certificates.pem.

7.Click Save Settings to save your changes.

Symmetric UDP Signaling

By default, the IP phones use symmetric UDP signaling for outgoing UDP SIP messages. When symmetric UDP is enabled, the IP phone generates and listens for UDP messages using port 5060.

You can manually disable symmetric UDP signaling using the IP phone’s configuration file. When you disable symmetric UDP signaling, then the IP phone chooses a random source port for UDP messages.

The IP phone also chooses a random source port for UDP messages to the registrar if you configure a backup registrar server. Likewise, the IP phone chooses a random source port for UDP messages with regards to communication with the respective proxy server if you configure a backup proxy server or backup outbound proxy server. If you configure a backup registrar server as well as a backup proxy server and/or a backup outbound proxy server, one random source port will be used for all UDP messages (i.e. for communication with the proxy server[s] and for registration).

An Administrator can configure symmetric UDP signaling using the configuration files only.

Configuring Symmetric UDP Signaling Using the Configuration Files

You use the following parameter to enable or disable Symmetric UDP Signaling in the configuration files:

sip symmetric udp signaling

Configuration Files

For the specific parameter you can set in the configuration files, see Appendix A, the section, “Symmetric UDP Signaling Setting” on page A-210.

Symmetric TLS Signaling

The IP phones also use symmetric TLS signaling for outgoing TLS SIP messages by default. When symmetric TLS is enabled, the IP phone uses port 5061 as the persistent TLS connection source port.

Administrators can manually disable symmetric TLS signaling using the IP phone’s configuration files. When you disable symmetric TLS signaling, the IP phone chooses a random persistent TLS connection source port from the TCP range (i.e. 49152...65535) for TLS messages after each reboot regardless of whether the parameter sip outbound support is enabled or disabled.

Note:

If multiple persistent TLS connections are required, the persistent TLS connection source ports will follow the structure

of random_port, random_port + 1, random_port + 2, etc....

An Administrator can configure symmetric TLS signaling using the configuration files only.

41-001343-02 REV04 – 05.2014

6-25

Page 541
Image 541
Aastra Telecom 41-001343-02 manual Symmetric UDP Signaling, Symmetric TLS Signaling, Sip symmetric udp signaling