CHAPTER 14 Security
Mediant 4000 SBC | User's Manual
●
When a TLS connection with the device is initiated by a SIP client, the device also
responds using TLS, regardless of whether or not TLS was configured.
●
The device regulates the number of new concurrent TLS connections that can be
established per second. This protects the device from flooding (avalanches) of new
TLS connections which may be caused from TLS-based malicious attacks or
distributed denial-of-service (DDoS) attacks.
➢
To configure SIPS:
1.
Configure a TLS Context as required (see
Configuring TLS Certificate Contexts
).
2.
Assign the TLS Context to a Proxy Set or SIP Interface (see
and
, respectively).
3.
Configure a SIP Interface with a TLS port number.
4.
Configure various SIPS parameters in the Security Settings page (
Setup
menu >
IP Network
tab >
Security
folder >
Security Settings
).
For a description of the TLS parameters, see
.
5.
By default, the device initiates a TLS connection only for the next network hop. To enable TLS
all the way to the destination (
over multiple hops
), configure the 'SIPS' (EnableSIPS)
parameter to
Enable
on the Transport Settings page (
Setup
menu >
Signaling & Media
tab >
SIP Definitions
folder >
Transport Settings
):
- 144 -
Summary of Contents for Mediant 4000 SBC
Page 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Page 40: ...Part I Getting Started with Initial Connectivity...
Page 48: ...Part II Management Tools...
Page 113: ...Part III General System Settings...
Page 118: ...Part IV General VoIP Configuration...
Page 525: ...Part V Session Border Controller Application...
Page 654: ...Part VI Cloud Resilience Package...
Page 663: ...Part VII High Availability System...
Page 685: ...Part VIII Maintenance...
Page 759: ...Part IX Status Performance Monitoring and Reporting...
Page 844: ...Part X Diagnostics...
Page 888: ...Part XI Appendix...