Clearspan® Product Overview R19
Aastra – 2740-007
2014 Clearspan® is a Registered Trademark of Aastra Technologies Ltd.
Page 26 of 93
2.3.1
XSP Server Security
The XSP is a hardened web server built upon Red Hat Linux and runs Apache Tomcat to support
http and https requests. This pooled resource is used for many purposes, including:
User client interfaces
Web portal for feature control
Microsoft Lync integration
Simplified API for custom integration
User client interfaces include Assistant Toolbar, Clearspan Communicator soft client, call center
agent and supervisor clients and receptionist clients. These clients will be discussed in detail in
later sections.
The web portal gives end users easy ability to control their calling features. Through this portal,
user can turn on and turn off many key features including Clearspan Anywhere (a find me
– follow
me service), Do Not Disturb, Remote Office, and many more.
The simplified API (called XSI) runs on this server type and support custom integration of call
control. This API is RESTful and uses http PUTs and GETs to interface to the platform.
2.3.2
SSM Server Security
The SSM Server type is a fully function SBC from the leading vendor of SBCs. The SBCs are
deployed as high-availability clusters and their purposes are:
VoIP/SIP firewall
SIP session security management
NAT traversal
Topology hiding
DoS and intrusion prevention
Header manipulation
Registration proxy
The SSMs participate in the registration and authentication of all endpoints, whether those
endpoints reside in the LAN or WAN. As endpoints register with the Clearspan platform, the SSMs
filter and check these registrations to prevent unauthorized access. Assuming the first phase of
filtering is passed, the registrations are then passed to the AS for authentication, the SSMs wait for
a response before binding the source IP address of the endpoints. Once binding occurs, the
endpoints are granted access to service.
2.3.3
Web Portal and CLI Access
Based upon the login identity and password, the appropriate Application Server or Network Server
portal is entered by the system administrator (or provisioning administrator), enterprise
administrator, group administrator, or end user. SSL support provides a secure link for logins on
the web server.
Clearspan has five tiers of password management (system administrator, enterprise administrator,
provisioning administrator, group administrator, and user), the format of each determined by the
next higher level of user. For instance, user passwords may or may not be required to be of a
certain length, contain numeric or special characters, be different than the user ID, and expire at
regular intervals. Group administrators determine which of these format requirements to impose