294 Gateway
Configuration
Software Configuration Guide Release 2.10, Revision 1.00
configuration of the master password was successful. Note that this last verification step can be done
securely even over insecure links (subject to wire-tapping) since the algorithm used for hash value
Mode
Gateway H.323
Command
Purpose
Step 1
node
(gw-h323)[h323]# [no] q931-tunneling
[isoip-2 | isoip-sp | isoip-ig ]
Select the appropriate Q.931 tunneling
protocol.
Example: Configuring Q.931 Tunneling and Tunneling Option
The following example shows how to enable Q.931 tunneling and tunneling option isoip-2 on the
H.323 gateway.
SN (cfg)#gateway h323 h323
SN (cfg)#q931-tunneling isoip-2
30.7 Configure H.235 Security for H.323
H.235 is an ITU-T Recommendation for security and encryption for H-series (H.323 and other H.245-
based) multimedia terminals. It describes enhancements within the framework of the H.3xx-Series
Recommendations to incorporate security services such as
Authentication
and
Privacy
(data
encryption).
SmartWare implements H.235 Annex D, which provides H.323 RAS and H.225 message
authentication and integrity check thus thwarting any replay and spoofing attacks on H.323 calls. If
H.235 is switched on, the following security attacks are thwarted:
•
Denial of Service attacks
•
Man-in-the-middle attacks
•
Replay attacks (replay of recorded messages)
•
Spoofing
•
Connection hijacking
Among other information such as time stamp, sender and general ID, the H.235 needs a password
for crypto token generation. Since this password is intelligible when being configured by means of a
telnet session or displayed in a running configuration, it is possible to configure an encrypted
password, which will be decrypted on the SmartNode. For decryption a master password is needed.
Configuration of the master password should not be done over insecure links (links subject to wire-
tapping). It is recommended to do so in a secure network (local area network) only (before delivery
to the customer).
Henceforth, the H.235 password can be reconfigured securely even over insecure links.
To generate an H.235 encrypted password by means of the master password as key, the password
encryption tool is used (‘getcryptopassword.exe’). The usage of the Windows based command line
tool is as follows :
getcryptopassword <h235-password> <master-password>
The H.235 password must be a random alphanumeric character string of 1 through 12 characters (e.g.
12ygR34230kG). The master password must be a 32 digit hex number (characters 0-9, a-f). To achieve
best encryption security, choose a random value (no repeating character sequences). The tool
generates the encrypted H.235 password and the hash of the master password. The encrypted H.235
password is then to be used for remote (over insecure link) configuration of the H.235 password. The
hash value of the master password can be used to verify proper configuration of all parameters. The
command 'show h235security' displays all H.235 settings including a hash value of the master
password. If this value is identical to the hash value output by the tool 'gencryptopassword.exe', the
Summary of Contents for SmartWare Release 2.10
Page 2: ...2 Legal Notice Software Configuration Guide Release 2 10 Revision 1 00...
Page 15: ...Terms and Definitions 15 Software Configuration Guide Release 2 10 Revision 1 00...
Page 218: ...218 PPP Configuration no shutdown Software Configuration Guide Release 2 10 Revision 1 00...
Page 272: ...272 Tone Configuration Software Configuration Guide Release 2 10 Revision 1 00...