Version 7.2
1025
Mediant 500 MSBR
User's Manual
74. Configuration Parameters Reference
[TLSReHandshakeInterv
al]
TLS Mutual
Authentication
configure network
> security-
settings >
SIPSREQUIRECLIENTC
ERTIFICATE
[SIPSRequireClientCertifi
cate]
Defines the device's mode of operation regarding mutual authentication
and certificate verification for TLS connections.
[0] Disable = (Default)
Device acts as a client: Verification of the server’s certificate
depends on the VerifyServerCertificate parameter.
Device acts as a server: The device does not request the client
certificate.
[1] Enable =
Device acts as a client: Verification of the server certificate is
required to establish the TLS connection.
Device acts as a server: The device requires the receipt and
verification of the client certificate to establish the TLS
connection.
Note:
For the parameter to take effect, a device reset is required.
This feature can be configured per SIP Interface (see Configuring SIP
Interfaces on page 325).
The SIPS certificate files can be changed using the parameters
HTTPSCertFileName and HTTPSRootFileName.
Peer Host Name
Verification Mode
configure network
> security-
settings >
PEERHOSTNAMEVERIFI
CATIONMODE
[PeerHostNameVerificati
onMode]
Enables the device to verify the Subject Name of a TLS certificate
received from SIP entities for authentication and establishing TLS
connections.
[0] Disable (default).
[1] Server Only = Verify Subject Name only when acting as a client for
the TLS connection.
[2] Server & Client = Verify Subject Name when acting as a server or
client for the TLS connection.
If the device receives a certificate from a SIP entity (IP Group) and the
parameter is configured to
Server Only
or
Server & Client
, it attempts
to authenticate the certificate based on the certificate's address.
The device searches for a Proxy Set that contains the same address (IP
address or FQDN) as that specified in the certificate's SubjectAltName
(Subject Alternative Names). For Proxy Sets with an FQDN, the device
checks the FQDN itself and not the DNS-resolved IP addresses. If a
Proxy Set is found with a matching address, the device establishes a
TLS connection.
If a matching Proxy Set is not found, one of the following occurs:
If the certificate's SubjectAltName is marked as "critical", the device
rejects the call.
If the SubjectAltName is not marked as "critical", the device checks if
the FQDN in the certificate's Common Name (CN) of the
SubjectName is the same as that configured for the
TLSRemoteSubjectName parameter or for the Proxy Set. If they are
the same, the device establishes a TLS connection; otherwise, the
device rejects the call.
Note:
If you configure the parameter to
Server & Client
, you also need to
configure the SIPSRequireClientCertificate parameter to
Enable
.
For FQDN, the certificate may use wildcards (*) to replace parts of the
domain name.
Содержание Mediant 500 MSBR
Страница 1: ...User s Manual AudioCodes Family of Multi Service Business Routers MSBR Mediant 500 MSBR Version 7 2 ...
Страница 2: ......
Страница 33: ...Part I Getting Started with Initial Connectivity ...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 45: ...Part II Management Tools ...
Страница 46: ......
Страница 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 115: ...Part III General System Settings ...
Страница 116: ......
Страница 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 137: ...Part IV General VoIP Configuration ...
Страница 138: ......
Страница 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Страница 455: ...Part V Gateway Application ...
Страница 456: ......
Страница 458: ...User s Manual 458 Document LTRT 10375 Mediant 500 MSBR IP to Tel Call Figure 24 1 IP to Tel Call Processing Flowchart ...
Страница 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 625: ...Part VI Session Border Controller Application ...
Страница 626: ......
Страница 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 741: ...Part VII Cloud Resilience Package ...
Страница 742: ......
Страница 751: ...Part VIII Data Router Configuration ...
Страница 752: ......
Страница 753: ......
Страница 754: ......
Страница 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 757: ...Part IX Maintenance ...
Страница 758: ......
Страница 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Страница 837: ...Part X Status Performance Monitoring and Reporting ...
Страница 838: ......
Страница 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 927: ...Part XI Diagnostics ...
Страница 928: ......
Страница 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 977: ...Part XII Appendix ...
Страница 978: ......
Страница 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...