User's Manual
13. Security
Version 6.8
145
Mediant 500 E-SBC
The firewall rules in the above configuration example do the following:
Rules 1 and 2:
Typical firewall rules that allow packets ONLY from specified IP
addresses (e.g., proxy servers). Note that the prefix length is configured.
Rule 3:
A more "advanced” firewall rule - bandwidth rule for ICMP, which allows a
maximum bandwidth of 40,000 bytes/sec with an additional allowance of 50,000 bytes.
If, for example, the actual traffic rate is 45,000 bytes/sec, then this allowance would be
consumed within 10 seconds, after which all traffic exceeding the allocated 40,000
bytes/sec is dropped. If the actual traffic rate then slowed to 30,000 bytes/sec, the
allowance would be replenished within 5 seconds.
Rule 4:
Allows traffic from the LAN voice interface and limits bandwidth.
Rule 5:
Blocks all other traffic.
13.2 Configuring General Security Settings
The device uses TLS over TCP to encrypt and optionally, authenticate SIP messages. This
is referred to as Secure SIP (SIPS). SIPS uses the X.509 certificate exchange process, as
described in 'Configuring SSL/TLS Certificates' on page
, where you need to configure
certificates (TLS Context).
Notes:
•
When a TLS connection with the device is initiated by a SIP client, the device also
responds using TLS, regardless of whether or not TLS was configured.
•
For backward compatibility, the following parameters can be used:
√
SIPTransportType to enable TLS.
√
TLSLocalSIPPort to configure the device's port used for TLS traffic.
To configure SIPS:
1.
Configure a TLS Context as required.
2.
Assign the TLS Context to a Proxy Set or SIP Interface (see Configuring Proxy Sets
on page
and Configuring SIP Interfaces on page
, respectively).
3.
Configure a SIP Interface with a TLS port number.
4.
Configure various SIPS parameters in the General Security Settings page
(
Configuration
tab >
VoIP
menu >
Security
>
General Security Settings
).
For a description of the TLS parameters, see TLS Parameters on page
5.
By default, the device initiates a TLS connection only for the next network hop. To
enable TLS all the way to the destination (over multiple hops), set the 'Enable SIPS'
(EnableSIPS) parameter to
Enable
in the SIP General Parameters page
(
Configuration
tab >
VoIP
menu >
SIP Definitions
>
General Parameters
).
Содержание Mediant 500 E-SBC
Страница 2: ......
Страница 16: ...User s Manual 16 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 22: ...User s Manual 22 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 23: ...Part I Getting Started with Initial Connectivity...
Страница 24: ......
Страница 26: ...User s Manual 26 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 28: ...User s Manual 28 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 33: ...Part II Management Tools...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 64: ...User s Manual 64 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 82: ...User s Manual 82 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 89: ...Part III General System Settings...
Страница 90: ......
Страница 106: ...User s Manual 106 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 107: ...Part IV General VoIP Configuration...
Страница 108: ......
Страница 238: ...User s Manual 238 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 250: ...User s Manual 250 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 280: ...User s Manual 280 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 329: ...Part V Gateway Application...
Страница 330: ......
Страница 332: ...User s Manual 332 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 352: ...User s Manual 352 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 412: ...User s Manual 412 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 441: ...Part VI Session Border Controller Application...
Страница 442: ......
Страница 489: ...User s Manual 28 SBC Configuration Version 6 8 489 Mediant 500 E SBC...
Страница 510: ...User s Manual 510 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 511: ...Part VII Cloud Resilience Package...
Страница 512: ......
Страница 521: ...Part VIII High Availability System...
Страница 522: ......
Страница 536: ...User s Manual 536 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 537: ...Part IX Maintenance...
Страница 538: ......
Страница 544: ...User s Manual 544 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 546: ...User s Manual 546 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 548: ...User s Manual 548 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 582: ...User s Manual 582 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 600: ...User s Manual 600 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 602: ...User s Manual 602 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 603: ...Part X Status Performance Monitoring and Reporting...
Страница 604: ......
Страница 654: ...User s Manual 654 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 655: ...Part XI Diagnostics...
Страница 656: ......
Страница 672: ...User s Manual 672 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 687: ...Part XII Appendix...
Страница 688: ......
Страница 914: ...User s Manual 914 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 919: ...User s Manual 56 Technical Specifications Version 6 8 919 Mediant 500 E SBC This page is intentionally left blank...
Страница 920: ...User s Manual Ver 6 8 www audiocodes com...