Polycom SIP 3.1 manual Incoming Signaling Validation, Secure Real-Time Transport Protocol

Models: SIP 3.1

1 347
Download 347 pages 532 b
Page 136
Image 136
Incoming Signaling Validation

Administrator’s Guide SoundPoint IP / SoundStation IP

Configuration changes can performed locally:

Local

Local Phone User Interface

The custom certificate can be specified and the type of certificate to trust can be set under the Settings menu.

Incoming Signaling Validation

The three optional levels of security for validating incoming network signaling are:

Source IP address validation

Digest authentication

Source IP address validation and digest authentication Configuration changes can performed centrally at the boot server:

Central

Configuration File:

Specify the type of validation to perform on a request-by-request

(boot server)

sip.cfg

basis, appropriate to specific event types in some cases.

 

 

For more information, refer to Request Validation

 

 

 

<requestValidation/> on page A-15.

 

 

 

 

Secure Real-Time Transport Protocol

Secure Real-Time Transport Protocol (SRTP) provides means of encrypting the audio stream(s) of VoIP phone calls to avoid interception and eavesdropping on phone calls.

For detailed configuration instructions, refer to “Technical Bulletin 25751: Secure Real-Time Transport Protocol on SoundPoint IP Phones” at http://www.polycom.com/usa/en/support/voice/soundpoint_ip/VoIP_T echnical_Bulletins_pub.html .

Configuration File Encryption

Configuration files (excluding the master configuration file), contact directories, and configuration override files can all be encrypted.

Note

The SoundPoint IP 300 and 500 phones will always fail at decrypting files. These

 

phones will recognize that a file is encrypted, but cannot decrypt it and will display

 

an error. Encrypted configuration files can only be decrypted on the SoundPoint IP

 

301, 320, 330, 430, 501,550, 560, 600, 601, 650, and 670 and the SoundStation IP

 

4000, 6000, and 7000 phones.

 

The master configuration file cannot be encrypted on the boot server. This file is

 

downloaded by the bootROM that does not recognize encrypted files. For more

 

information, refer to Master Configuration Files on page A-2.

 

 

4 - 82

Page 136
Image 136
Polycom SIP 3.1 manual Incoming Signaling Validation, Secure Real-Time Transport Protocol, Configuration File Encryption