User's Manual
186
Document #: LTRT-65432
MP-11x & MP-124
14.6 Configuring Media Security
The device supports Secured RTP (SRTP) according to RFC 3711. SRTP is used to
encrypt RTP and RTCP transport for protecting VoIP traffic. SRTP requires a key
exchange mechanism that is performed according to RFC 4568 – “Session Description
Protocol (SDP) Security Descriptions for Media Streams”. The key exchange is done by
adding a 'crypto' attribute to the SDP. This attribute is used (by both sides) to declare the
various supported cipher suites and to attach the encryption key. If negotiation of the
encryption data is successful, the call is established.
SRTP supports the following cipher suites (all other suites are ignored):
AES_CM_128_HMAC_SHA1_32
AES_CM_128_HMAC_SHA1_80
When the device is the offering side, it generates an MKI of a size configured by the
'Master Key Identifier (MKI) Size' parameter. The length of the MKI is limited to four bytes.
If the remote side sends a longer MKI, the key is ignored. The key lifetime field is not
supported. However, if it is included in the key it is ignored and the call does not fail.
The device supports the following session parameters (as defined in RFC 4568, SDP
Security Descriptions for Media Streams):
UNENCRYPTED_SRTP
UNENCRYPTED_SRTCP
UNAUTHENTICATED_SRTP
Session parameters should be the same for the local and remote sides. When the device is
the offering side, the session parameters are configured by the following parameter -
'Authentication On Transmitted RTP Packets', 'Encryption On Transmitted RTP Packets,
and 'Encryption On Transmitted RTCP Packets'. When the device is the answering side,
the device adjusts these parameters according to the remote offering. Unsupported
session parameters are ignored, and do not cause a call failure.
Below is an example of crypto attributes usage:
a=crypto:1 AES_CM_128_HMAC_SHA1_80
inline:PsKb5X0YLuSvNrImEh/dAe
a=crypto:2 AES_CM_128_HMAC_SHA1_32
inline:IsPtLc6XVzRuMqHlDnEiAd
The device also supports symmetric MKI negotiation, whereby it can be configured to
forward the MKI size received in the SDP offer crypto line in the SDP answer crypto line.
To configure the device's mode of operation if negotiation of the cipher suite fails, use the
'Media Security Behavior' parameter. This parameter can be set to enforce SRTP, whereby
incoming calls that don’t include encryption information are rejected.
Notes:
•
For a detailed description of the SRTP parameters, see SRTP Parameters on
page
•
When SRTP is used, the channel capacity may be reduced.
Содержание Media Pack MP-11x
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 25: ...Part I Getting Started with Initial Connectivity...
Страница 26: ......
Страница 35: ...Part II Management Tools...
Страница 36: ......
Страница 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 109: ...Part III General System Settings...
Страница 110: ......
Страница 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 121: ...Part IV General VoIP Configuration...
Страница 122: ......
Страница 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 231: ...Part V Gateway Application...
Страница 232: ......
Страница 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 327: ...Part VI Stand Alone Survivability Application...
Страница 328: ......
Страница 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 361: ...Part VII Maintenance...
Страница 362: ......
Страница 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 409: ...Part VIII Status Performance Monitoring and Reporting...
Страница 410: ......
Страница 441: ...Part IX Diagnostics...
Страница 442: ......
Страница 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 471: ...Part X Appendix...
Страница 472: ......
Страница 650: ...International Headquarters Contact us www audiocodes com info Website www audiocodes com Document LTRT 65432...