
Version 7.2
155
Mediant 500 MSBR
User's Manual
16. Security
16
Security
This section describes the VoIP security-related configuration.
16.1 Configuring TLS for SIP
The device uses TLS over TCP to encrypt and optionally, authenticate SIP messages. This
is referred to as Secure SIP (SIPS). SIPS uses the X.509 certificate exchange process, as
described in Configuring SSL/TLS Certificates on page 117, where you need to configure
certificates (TLS Context).
Note:
When a TLS connection with the device is initiated by a SIP client, the device
also responds using TLS, regardless of whether or not TLS was configured.
To configure SIPS:
1.
Configure a TLS Context as required (see Configuring TLS Certificate Contexts on
page 117).
2.
Assign the TLS Context to a Proxy Set or SIP Interface (see Configuring Proxy Sets
on page 348 and Configuring SIP Interfaces on page 325, respectively).
3.
Configure a SIP Interface with a TLS port number.
4.
Configure various SIPS parameters in the Security Settings page (
Setup
menu >
IP
Network
tab >
Security
folder >
Security Settings
).
For a description of the TLS parameters, see TLS Parameters on page 1024.
5.
By default, the device initiates a TLS connection only for the next network hop. To
enable TLS all the way to the destination (
over multiple hops
), configure the 'Enable
SIPS' (EnableSIPS) parameter to
Enable
on the Transport Settings page (
Setup
menu >
Signaling & Media
tab >
SIP Definitions
folder >
Transport Settings
):
Figure
16-1: Enabling SIPS
16.2 Intrusion Detection System
The device's Intrusion Detection System (IDS) feature detects malicious attacks on the
device and reacts accordingly. A remote host is considered malicious if it has reached or
exceeded a user-defined threshold (counter) of specified malicious attacks.
If malicious activity is detected, the device can do the following:
Block (blacklist) remote hosts (IP addresses / ports) considered by the device as
malicious. The device automatically blacklists the malicious source for a user-defined
period after which it is removed from the blacklist.
Send SNMP traps to notify of malicious activity and/or whether an attacker has been
added to or removed from the blacklist. For more information, see Viewing IDS Alarms
on page 162.
The Intrusion Detection System (IDS) is an important feature for Enterprises to ensure
legitimate calls are not being adversely affected by attacks and to prevent Theft of Service
and unauthorized access.
There are many types of malicious attacks, the most common being:
Содержание Mediant 500 MSBR
Страница 1: ...User s Manual AudioCodes Family of Multi Service Business Routers MSBR Mediant 500 MSBR Version 7 2 ...
Страница 2: ......
Страница 33: ...Part I Getting Started with Initial Connectivity ...
Страница 34: ......
Страница 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 45: ...Part II Management Tools ...
Страница 46: ......
Страница 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 115: ...Part III General System Settings ...
Страница 116: ......
Страница 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 137: ...Part IV General VoIP Configuration ...
Страница 138: ......
Страница 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Страница 455: ...Part V Gateway Application ...
Страница 456: ......
Страница 458: ...User s Manual 458 Document LTRT 10375 Mediant 500 MSBR IP to Tel Call Figure 24 1 IP to Tel Call Processing Flowchart ...
Страница 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 625: ...Part VI Session Border Controller Application ...
Страница 626: ......
Страница 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 741: ...Part VII Cloud Resilience Package ...
Страница 742: ......
Страница 751: ...Part VIII Data Router Configuration ...
Страница 752: ......
Страница 753: ......
Страница 754: ......
Страница 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 757: ...Part IX Maintenance ...
Страница 758: ......
Страница 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Страница 837: ...Part X Status Performance Monitoring and Reporting ...
Страница 838: ......
Страница 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 927: ...Part XI Diagnostics ...
Страница 928: ......
Страница 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Страница 977: ...Part XII Appendix ...
Страница 978: ......
Страница 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...