CHAPTER 15 Media
Mediant 4000 SBC | User's Manual
DTLS cipher suite reuses the TLS cipher suite. The DTLS handshake is done for every new call
configured for DTLS. In other words, unlike TLS where the connection remains "open" for future
calls, a new DTLS connection is required for every new call. Note that the entire authentication and
key exchange for securing the media traffic is handled in the media path through DTLS. The
signaling path is used only to verify the peers' certificate fingerprints. DTLS messages are
multiplexed onto the same ports that are used for the media.
➢
To configure DTLS:
1.
In the TLS Context table (see
Configuring TLS Certificate Contexts
), configure a TLS Context
with the DTLS version (TLSContexts_DTLSVersion).
2.
Open the IP Groups table (see
) and for the IP Group associated with the
SIP entity, assign it the TLS Context for DTLS, using the 'DTLS Context' parameter (IPGroup_
DTLSContext).
3.
Open the IP Profiles table (see
) and for the IP Profile associated with
the SIP entity, configure the following:
●
Configure the 'SBC Media Security Mode' parameter (IPProfile_
SBCMediaSecurityBehavior) to
SRTP
or
Both
.
●
Configure the 'Media Security Method' parameter (IPProfile_SBCMediaSecurityMethod)
to
DTLS
.
●
Configure the 'RTCP Mux' parameter (IpProfile_SBCRTCPMux) to
Supported
.
Multiplexing is required as the DTLS handshake is done for the port used for RTP and
thus, RTCP and RTP must be multiplexed onto the same port.
●
Configure the ini file parameter, SbcDtlsMtu (or CLI command configure voip > sbc
settings > sbc-dtls-mtu) to define the maximum transmission unit (MTU) size for the DTLS
handshake.
●
The 'Cipher Server' parameter must be configured to "ALL".
●
The device does not support forwarding of DTLS transparently between endpoints.
- 183 -
Summary of Contents for Mediant 4000 SBC
Page 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Page 40: ...Part I Getting Started with Initial Connectivity...
Page 48: ...Part II Management Tools...
Page 113: ...Part III General System Settings...
Page 118: ...Part IV General VoIP Configuration...
Page 525: ...Part V Session Border Controller Application...
Page 654: ...Part VI Cloud Resilience Package...
Page 663: ...Part VII High Availability System...
Page 685: ...Part VIII Maintenance...
Page 759: ...Part IX Status Performance Monitoring and Reporting...
Page 844: ...Part X Diagnostics...
Page 888: ...Part XI Appendix...