User's Manual
408
Document #: LTRT-10375
Mediant 500 MSBR
Parameter
Description
The corresponding global parameter is
SRTPTxPacketMKISize.
SBC Enforce MKI Size
sbc-enforce-mki-size
[IpProfile_SBCEnforceMKISize]
Enables negotiation of the Master Key Identifier (MKI) length for
SRTP-to-SRTP flows between SIP networks (i.e., IP Groups).
This includes the capability of modifying the MKI length on the
inbound or outbound SBC call leg for the SIP entity associated
with the IP Profile.
[0] Don't enforce = (Default) Device forwards the MKI size as
is.
[1] Enforce = Device changes the MKI length according to the
settings of the IP Profile parameter, MKISize.
SBC Media Security Method
sbc-media-security-method
[IpProfile_SBCMediaSecurityMet
hod]
Defines the media security protocol for SRTP, for the SIP entity
associated with the IP Profile.
[0] SDES = (Default) The device secures RTP using the
Session Description Protocol Security Descriptions (SDES)
protocol to negotiate the cryptographic keys (RFC 4568). The
keys are sent in the SDP body ('a=crypto') of the SIP
message and are typically secured using SIP over TLS
(SIPS). The encryption of the keys is in plain text in the SDP.
SDES implements TLS over TCP.
[1] DTLS = The device uses Datagram Transport Layer
Security (DTLS) protocol to secure UDP-based media
streams (RFCs 5763 and 5764). For more information on
DTLS, see SRTP using DTLS Protocol.
[2] Both = SDES and DTLS protocols are supported.
Note:
To support DTLS, you must also configure the following for
the SIP entity:
TLS Context for DTLS (see Configuring TLS Certificate
Contexts on page 117). The server cipher ('Cipher
Server') must be configured to All.
IpProfile_SBCMediaSecurityBehaviourMedia configured
to SRTP or Both.
IpProfile_SBCRTCPMux configured to Supported. The
setting is required as the DTLS handshake is done for
the port used for RTP. Therefore, RTCP and RTP should
be multiplexed over the same port.
The device does not support forwarding of DTLS
transparently between endpoints (SIP entities).
As DTLS has been defined by the WebRTC standard as
mandatory for encrypting media channels for SRTP key
exchange, the support is important for deployments
implementing WebRTC. For more information on WebRTC,
see WebRTC.
Reset SRTP Upon Re-key
reset-srtp-upon-re-key
[IpProfile_ResetSRTPStateUpon
Rekey]
Enables synchronization of the SRTP state between the device
and a server when a new SRTP key is generated upon a SIP
session expire. This feature ensures that the roll-over counter
(ROC), one of the parameters used in the SRTP
encryption/decryption process of the SRTP packets is
synchronized on both sides for transmit and receive packets.
[0] Disable = (Default) ROC is not reset on the device side.
[1] Enable = If the session expires causing a session refresh
Содержание Mediant 500 MSBR
Страница 1: ...User s Manual AudioCodes Family of Multi Service Business Routers MSBR Mediant 500 MSBR Version 7 2 ...
Страница 2: ......
Страница 33: ...Part I Getting Started with Initial Connectivity ...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 45: ...Part II Management Tools ...
Страница 46: ......
Страница 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 115: ...Part III General System Settings ...
Страница 116: ......
Страница 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 137: ...Part IV General VoIP Configuration ...
Страница 138: ......
Страница 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Страница 455: ...Part V Gateway Application ...
Страница 456: ......
Страница 458: ...User s Manual 458 Document LTRT 10375 Mediant 500 MSBR IP to Tel Call Figure 24 1 IP to Tel Call Processing Flowchart ...
Страница 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 625: ...Part VI Session Border Controller Application ...
Страница 626: ......
Страница 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 741: ...Part VII Cloud Resilience Package ...
Страница 742: ......
Страница 751: ...Part VIII Data Router Configuration ...
Страница 752: ......
Страница 753: ......
Страница 754: ......
Страница 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 757: ...Part IX Maintenance ...
Страница 758: ......
Страница 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Страница 837: ...Part X Status Performance Monitoring and Reporting ...
Страница 838: ......
Страница 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 927: ...Part XI Diagnostics ...
Страница 928: ......
Страница 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 977: ...Part XII Appendix ...
Страница 978: ......
Страница 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...