User's Manual
456
Document #: LTRT-10437
Mediant 500 E-SBC
3.
The device validates the SIP message according to the AuthNonceDuration,
AuthChallengeMethod and AuthQOP parameters.
♦
If validation fails, the device rejects the message and sends a 403
(Forbidden) response to the client.
♦
If validation succeeds, the device verifies client identification. It checks that
the username and password received from the client is the same username
and password in the device's User Information table / database (see ''SBC
User Information for SBC User Database'' on page
). If the client is not
successfully authenticated after three attempts, the device sends a SIP 403
(Forbidden) response to the client. If the user is successfully identified, the
device accepts the SIP message request.
The device's Authentication server functionality is configured per IP Group, using the
'Authentication Mode' parameter in the IP Group table (see ''Configuring IP Groups'' on
page
).
27.6.2 User Authentication based on RADIUS
The device can authenticate SIP clients (users) using a remote RADIUS server. The device
supports the RADIUS extension for digest authentication of SIP clients, according to draft-
sterman-aaa-sip-01. Based on this standard, the device generates the nonce (in contrast to
RFC 5090, where it is done by the RADIUS server).
RADIUS based on draft-sterman-aaa-sip-01 operates as follows:
1.
The device receives a SIP request without an Authorization header from the SIP
client.
2.
The device generates the nonce and sends it to the client in a SIP 407 (Proxy
Authentication Required) response.
3.
The SIP client sends the SIP request with the Authorization header to the device.
4.
The device sends an Access-Request message to the RADIUS server.
5.
The RADIUS server verifies the client's credentials and sends an Access-Accept (or
Access-Reject) response to the device.
6.
The device accepts the SIP client's request (sends a SIP 200 OK or forwards the
authenticated request) or rejects it (sends another SIP 407 to the SIP client).
To configure this feature, set the SBCServerAuthMode ini file parameter to 2.
Содержание Mediant 500 E-SBC
Страница 2: ......
Страница 16: ...User s Manual 16 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 22: ...User s Manual 22 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 23: ...Part I Getting Started with Initial Connectivity...
Страница 24: ......
Страница 26: ...User s Manual 26 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 28: ...User s Manual 28 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 33: ...Part II Management Tools...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 64: ...User s Manual 64 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 82: ...User s Manual 82 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 89: ...Part III General System Settings...
Страница 90: ......
Страница 106: ...User s Manual 106 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 107: ...Part IV General VoIP Configuration...
Страница 108: ......
Страница 238: ...User s Manual 238 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 250: ...User s Manual 250 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 280: ...User s Manual 280 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 329: ...Part V Gateway Application...
Страница 330: ......
Страница 332: ...User s Manual 332 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 352: ...User s Manual 352 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 412: ...User s Manual 412 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 441: ...Part VI Session Border Controller Application...
Страница 442: ......
Страница 489: ...User s Manual 28 SBC Configuration Version 6 8 489 Mediant 500 E SBC...
Страница 510: ...User s Manual 510 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 511: ...Part VII Cloud Resilience Package...
Страница 512: ......
Страница 521: ...Part VIII High Availability System...
Страница 522: ......
Страница 536: ...User s Manual 536 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 537: ...Part IX Maintenance...
Страница 538: ......
Страница 544: ...User s Manual 544 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 546: ...User s Manual 546 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 548: ...User s Manual 548 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 582: ...User s Manual 582 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 600: ...User s Manual 600 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 602: ...User s Manual 602 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 603: ...Part X Status Performance Monitoring and Reporting...
Страница 604: ......
Страница 654: ...User s Manual 654 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 655: ...Part XI Diagnostics...
Страница 656: ......
Страница 672: ...User s Manual 672 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 687: ...Part XII Appendix...
Страница 688: ......
Страница 914: ...User s Manual 914 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Страница 919: ...User s Manual 56 Technical Specifications Version 6 8 919 Mediant 500 E SBC This page is intentionally left blank...
Страница 920: ...User s Manual Ver 6 8 www audiocodes com...