IP Phone Administrator Guide

Operational, Basic, and Advanced Parameters

Appendix A

Parameter

IP Phone UI

Options->Administrator Menu->

https block http post xml

 

Network Settings->HTTPS->

 

 

HTTPS Server->XML

HTTPS Server - Block XML

Aastra Web UI

Advanced Settings->Network->

HTTP POSTs

 

Advanced Network Settings

(in Web UI)

Configuration Files

aastra.cfg, <mac>.cfg

 

 

Description

Enables or disables the blocking of XML scripts from HTTP POSTs.

 

Some client applications use HTTP POSTs to transfer XML scripts. The

 

phones’s HTTP server accepts these POSTs even if server redirection is

 

enabled, effectively bypassing the secure connection. When this

 

parameter is enabled (blocking is enabled), receipt of an HTTP POST

 

containing an XML parameter header results in the following response:

 

“403 Forbidden”. This forces the client to direct the POSTs to the HTTPS

 

server through use of the “https://” URL.

 

 

 

Format

Boolean

 

 

 

Default Value

0 (disables blocking of XML HTTP POSTs)

 

 

Range

0 (disables blocking of XML HTTP POSTs)

 

1 (enables blocking of XML HTTP POSTs)

 

 

Example

https block http post xml: 1

 

 

 

A-24

41-001160-00, Release 2.1, Rev 04

Page 526
Image 526
Aastra Telecom 57I CT, 55I, 53I manual Https block http post xml