background image

 

 

 
 
 

  

P a g e    13 

We recommend users to consider the following options for added security when deploying the FAP with 

provisioning. 

 

Upgrade Via: HTTPS: 

By default, HTTPS is selected. This is recommended so the traffic is encrypted while travelling through 

the network. 

 

HTTP/HTTPS/FTP/FTPS User Name and Password: 

This can be set up as required on the provisioning server when HTTP/HTTPS/FTP/FTPS is used. Only 

when  the  FAP  has  the  correct  username  and  password  configured,  it  can  be  authenticated  by  the 

Upgrade/provisioning server and the config file can be downloaded. 

 

Authenticate Config file: 

This sets  the  FAP  to  authenticate  the  configuration  file  before  applying  it.  Whe

n set to “Yes”, the 

configuration file must include P value P1 with FAP 

system’s administration password. If it is missed 

or does not match the password, the FAP will not apply the config file. 

 

XML Config File Password: 

The FAP XML config file can be encrypted using OpenSSL. When 

it’s encrypted, the FAP must supply 

the correct password in this field so it can decrypt XML configuration file after downloading it. Then 

the configuration can be applied. Please note this feature is supported on XML config file instead of 
the binary config file. Therefore, it’s recommended to use XML config file format and encrypt it with 

this feature. 

 

Validate Server Certificates: (

under 

Maintenance 

 

Security settings 

 

Security) 

This configures whether to validate the server certificate when downloading the firmware/config file. 

If set to "Yes", the FAP will download the firmware/config file only from the legitimate server. 

 

 

TR-069 

 

TR-

069 is disabled by default, it’s recommended to disable it if not used. 

When TR-069 is enabled under Maintenance 

 

TR-069, and the service is to be used, users can set up 

the following: 

 

ACS URL

: Specifies URL of TR-069 Auto Configuration Servers. 

 

 

ACS Username/Password

: Enters username/Password to authenticate to ACS. 

 

 

Periodic Inform Enable

: Sends periodic inform packets to ACS. 

 

 

Periodic Inform Interval

: Sets frequency that the inform packets will be sent out to ACS. 

 

 

Connection Request Username/Password

: Enters username/Password for ACS to connect to the 

FAP. 

 

 

CPE SSL Certificate

: Configures the Cert File for the ATA to connect to the ACS via SSL. 

Summary of Contents for FAP26 Series

Page 1: ...FIBERME Communications LLC FAP26xx Series Security Manual...

Page 2: ...tocols 4 Admin Login 5 User Management Levels 6 SECURITY FOR SIP ACCOUNTS AND CALLS 8 Protocols and Ports 8 Anonymous Unsolicited Calls Protection 9 SRTP 11 SNMP 11 SECURITY FOR FAP SERVICES 12 Firmwa...

Page 3: ...nge User Level password 7 Figure 6 Configure TLS as SIP Transport 8 Figure 7 SIP TLS Settings 8 Figure 8 Additional SIPTLS Settings 9 Figure 9 Anonymous Call Rejection 9 Figure 10 Settings to Block An...

Page 4: ...or signaling and media stream transmission It also offers configurable options to block anonymous calls and unsolicited calls Security for FAP Services FAP supports service such as HTTP HTTPS TFTP FTP...

Page 5: ...rted to access the FAP s web UI and can be configured under web UI Maintenance Security settings Security To secure transactions and prevent unauthorized access it is highly recommended to 1 Use HTTPS...

Page 6: ...he default password is a random password available on the sticker at the back of the unit Changing the default password at first time login is highly recommended When accessing the FAP phones for the...

Page 7: ...Pages Allowed User Level user 123 Only Status and Basic Settings Administrator Level admin Random password available on the sticker at the back of the unit All pages NOTES It is recommended to keep ad...

Page 8: ...P a g e 7 Figure 5 Change User Level password...

Page 9: ...rect IP Call to Yes SIP transport protocol The FAP supports SIP transport protocol UDP TCP and TLS By default it s set to UDP It s recommended to use TLS so the SIP signaling is encrypted SIP transpor...

Page 10: ...or Account 2 Local SIP port when using TLS The SIP TLS port is the UDP SIP port plus 1 For example if Account 1 SIP port is 5060 its TLS port would be 5061 Anonymous Unsolicited Calls Protection If th...

Page 11: ...essages Set Yes to Validate incoming messages by checking caller ID and CSeq headers If the message does not include the headers it will be rejected Check SIP User ID for Incoming INVITE Set Yes to en...

Page 12: ...ured under Web GUI Account X Audio Settings Figure 11 SRTP Settings Selects SRTP mode to choose No Enabled but not forced Enabled and forced or Optional Default is No It uses SDP Security Description...

Page 13: ...ware Upgrade and Provisioning The FAP IP Phones support downloading configuration file via TFTP HTTP HTTPS FTP FTPS Below figure shows the related options under Web GUI Maintenance Upgrade and Provisi...

Page 14: ...eld so it can decrypt XML configuration file after downloading it Then the configuration can be applied Please note this feature is supported on XML config file instead of the binary config file There...

Page 15: ...P a g e 14 CPE SSL Private Key Specifies the Cert Key for the ATA to connect to the ACS viaSSL Figure 14 TR 069 Connection Settings...

Page 16: ...s sending Syslog to a remote syslog server By default it s sent via UDP and we recommend changing it to SSL TLS so the syslog messages containing device information will be sent securely over TLS conn...

Page 17: ...Local SIP Port defines the local SIP port used to listen and transmit The default value when using SIP transport protocol UDP TCP is 5060 for Account 1 5062 for Account 2 5064 for Account 3 5066 for...

Page 18: ...ic network for normal usage Use HTTPS for firmware downloading and config file downloading Use HTTPS for firmware downloading and provisioning Besides that set up username and password for the HTTP HT...

Reviews: