CHAPTER 16 Services
Mediant 4000 SBC | User's Manual
Parameter
Description
Note:
If configured to
HTTPS
, you must assign a TLS Context
(see the 'Device Login TLS Context' parameter, below).
'Device Login TLS Context'
device-login-tls-
context
[OVOCService_
LoginInterfaceTLSContext]
Assigns a TLS Context (TLS certificate) for the interface with
the requesting client. This is required if you have configured the
'Device Scheme' parameter to
HTTPS
(see above). To
configure TLS Contexts, see
Note:
The NGINX directive for this parameter is "proxy_ssl_
certificate", "proxy_ssl_certificate_key", "proxy_ssl_ciphers",
and "proxy_ssl_protocols".
'Device Login Interface
Verify Certificate'
device-interface-
verify-cert
[OVOCService_
LoginInterfaceVerifyCert]
Enables the verification of the TLS certificate that is used in the
incoming client connection request.
■
[0]
No
= (Default) No certificate verification is done.
■
[1]
Yes
= The device verifies the authentication of the
certificate received from the client. The device authenticates
the certificate against the trusted root certificate store
associated with the assigned TLS Context (see 'Device
Login TLS Context' parameter above) and if ok, allows
communication with the client. If authentication fails, the
device denies communication (i.e., handshake fails). The
device can also authenticate the certificate by querying with
an Online Certificate Status Protocol (OCSP) server
whether the certificate has been revoked. This is also
configured for the associated TLS Context.
Note:
The NGINX directive for this parameter is "proxy_ssl_
verify".
OVOC
'OVOC Listening Interface'
ovoc-interface
[OVOCService_
EMSListeningInterface]
Assigns an IP network interface (local, listening HTTP
interface:port) for communication with OVOC. To configure IP
Interfaces, see
Configuring IP Network Interfaces
By default, no value is defined.
Note:
■
The parameter is mandatory.
■
The NGINX directive for this parameter is "proxy_bind".
'OVOC Listening Port'
ovoc-port
[OVOCService_
EMSListeningPort]
Defines the listening port for the OVOC interface.
Note:
The NGINX directive for this parameter is "proxy_bind".
'OVOC Scheme'
ovoc-scheme
[OVOCService_
EMSScheme]
Defines the security scheme for the connection with OVOC.
■
[0]
HTTP
(default)
■
[1]
HTTPS
Note:
■
If configured to
HTTPS
, you must assign a TLS Context
(see the 'OVOC Interface TLS Context' parameter, below).
- 280 -
Summary of Contents for Mediant 4000 SBC
Page 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Page 40: ...Part I Getting Started with Initial Connectivity...
Page 48: ...Part II Management Tools...
Page 113: ...Part III General System Settings...
Page 118: ...Part IV General VoIP Configuration...
Page 525: ...Part V Session Border Controller Application...
Page 654: ...Part VI Cloud Resilience Package...
Page 663: ...Part VII High Availability System...
Page 685: ...Part VIII Maintenance...
Page 759: ...Part IX Status Performance Monitoring and Reporting...
Page 844: ...Part X Diagnostics...
Page 888: ...Part XI Appendix...