Cisco Systems OL-14619-01 manual When Data Is Encrypted, Setting, Effect, 6-15

Models: OL-14619-01

1 106
Download 106 pages 43.76 Kb
Page 71
Image 71
When Data Is Encrypted

Chapter 6 Integrating Cisco Unity with the Phone System

Integrating with Cisco Unified Communications Manager (by Using SCCP or SIP)

The process of authentication and encryption of Cisco Unity voice messaging ports is as follows:

1.Each Cisco Unity voice messaging port connects to the TFTP server, downloads the CTL file, and extracts the certificates for all Cisco Unified CM servers.

2.Each Cisco Unity voice messaging port establishes a network connection to the Cisco Unified CM TLS port through Winsock. By default, the TLS port is 2443, though the port number is configurable.

3.Each Cisco Unity voice messaging port establishes a TLS connection to the Cisco Unified CM server, verifies the device certificate, and authenticates the voice messaging port.

4.Each Cisco Unity voice messaging port registers with the Cisco Unified CM server, specifying whether the voice messaging port will also use media encryption.

When Data Is Encrypted

When a call is made between Cisco Unity and Cisco Unified CM, the call-signaling messages and the media stream are handled in the following manner:

If both end points are set for encrypted mode, the call-signaling messages and the media stream are encrypted.

If one end point is set for authenticated mode and the other end point is set for encrypted mode, the call-signaling messages are authenticated, but neither the call-signaling messages nor the media stream are encrypted.

If one end point is set for non-secure mode and the other end point is set for encrypted mode, neither the call-signaling messages nor the media stream are encrypted.

Cisco Unified Communications Manager Cluster Security Mode Settings in Cisco Unity

 

 

The Cisco Unified CM cluster security mode settings in the Cisco Unity Telephony Integration Manager

 

 

(UTIM) determine how the ports handle call-signaling messages and whether encryption of the media

 

 

stream is possible. Table 6-4describes the effect of the Cluster Security Mode settings in UTIM.

Table 6-4

Cisco Unified Communications Manager Cluster Security Mode Settings for Voice Messaging Ports

 

 

 

Setting

 

Effect

 

 

 

Non-secure

 

The integrity and privacy of call-signaling messages will not be ensured because call-signaling

 

 

messages will be sent as clear (unencrypted) text and will be connected to Cisco Unified CM through

 

 

a non-authenticated port rather than an authenticated TLS port.

 

 

The media stream is not encrypted.

 

 

 

 

 

Design Guide for Cisco Unity Release 5.x

 

 

 

 

 

 

OL-14619-01

 

 

6-15

 

 

 

 

 

Page 71
Image 71
Cisco Systems OL-14619-01 manual When Data Is Encrypted, Setting, Effect, 6-15