background image

 

P a g e

 |

 

16

 

 

GRP26XX Security Manual 

SECURITY GUIDELINES FOR GRP DEPLOYMENT

 

Often  the  GRP  are  deployed  behind  NAT.  The  network  administrator  can  consider  following  security 
guidelines for the GRP to work properly and securely.

 

 

 

Turn off SIP ALG on the router

 

On the customer’s router, it’s recommended to turn off SIP ALG (Application Layer Gateway). SIP ALG 
is common in many routers intending to prevent some problems caused by router firewalls by inspecting 
VoIP packets and modifying it if necessary. Even though SIP ALG intends to prevent issues for VoIP 
devices,  it  can  be  implemented  imperfectly  causing  problems,  especially  in  some  cases  SIP ALG 
modifies SIP packets improperly which might cause VoIP devices fail to register or establish calls.

 

 

 

Use TLS and SRTP for SIP calls

 

On the GRP, it’s recommended to use TLS for SIP transport with “sips” in SIP URL scheme for SIP 
signaling encryption and use SRTP for media encryption. 

 

Below the SIP ports and  RTPs port used on the  GRP if the network administrator needs to create 
firewall rules.

 

 

 

Under  web  UI 

  Account  x 

  SIP  Settings 

  Basic  Settings, 

the  feature  “Local  SIP  Port” 

defines the local SIP port used to listen and transmit. The default value when using SIP transport 
protocol UDP/TCP is 5060 for Account 1, 5062 for Account 2, 5064 for Account 3, 5066 for Account 
4… When using TLS as SIP transport protocol the default value is 5061 for Account 1, 5063 for 
Account 2, 5065 for Account 3, … The valid range is from 1 to 65535.

 

 

 

Under web UI 

 

Settings 

 General Settings

, the feature “Local RTP Port” defines the local RTP 

port used to listen and transmit. Local RTP port ranges from 1024 to 65400 and must be even. It is 
the base RTP port for channel 0. When configured channel 0 will use this port_value for RTP, and 
por1 for RTCP. Channel 1 will use por2 for RTP and so on, until reaching the limit 
and then it will be reset to first port_value. The default value is 5004 for RTP and 5005 for RTCP. 

 

 

For the GRP26XX phones, it is possible to select a range for the Local RTP port from 48 to 10000. 
Default setting is 200.

 

Note

: On the customer’s firewall, it’s recommended to ensure SIP port is opened for the SIP accounts 

on the GRP. It’s not necessary to use the default port 5060/5062/… on the firewall. Instead, the network 
administrator can consider mapping a different port on the firewall for GRP SIP port 5060 for security 
purpose.

 

 

Содержание GRP26 Series

Страница 1: ...Grandstream Networks Inc GRP26XX Series Security Manual...

Страница 2: ...I Access Protocols 4 Admin Login 5 User Management Levels 6 SECURITY FOR SIP ACCOUNTS AND CALLS 8 Protocols and Ports 8 Anonymous Unsolicited Calls Protection 9 SRTP 11 SNMP 11 SECURITY FOR GRP SERVIC...

Страница 3: ...Figure 5 Change User Level password 7 Figure 6 Configure TLS as SIP Transport 8 Figure 7 SIP TLS Settings 8 Figure 8 Additional SIP TLS Settings 9 Figure 9 Anonymous Call Rejection 9 Figure 10 Setting...

Страница 4: ...ecific port for signaling and media stream transmission It also offers configurable options to block anonymous calls and unsolicited calls Security for GRP Services GRP supports service such as HTTP H...

Страница 5: ...are supported to access the GRP s web UI and can be configured under web UI Maintenance Security settings Security To secure transactions and prevent unauthorized access it is highly recommended to 1...

Страница 6: ...password available on the sticker at the back of the unit Changing the default password at first time login is highly recommended When accessing the GRP phones for the first time or after factory rese...

Страница 7: ...3 Only Status and Basic Settings Administrator Level admin Random password available on the sticker at the back of the unit All pages NOTES It is recommended to keep admin login for administrator only...

Страница 8: ...P a g e 7 GRP26XX Security Manual Figure 5 Change User Level password...

Страница 9: ...under Settings Call Features Set Disable Direct IP Call to Yes SIP transport protocol The GRP supports SIP transport protocol UDP TCP and TLS By default it s set to UDP It s recommended to use TLS so...

Страница 10: ...Account 1 the port numbers increase by 2 for each account For example 5062 is the default local SIP port for Account 2 Local SIP port when using TLS The SIP TLS port is the UDP SIP port plus 1 For ex...

Страница 11: ...m ringing the phones Please see below the settings Validate Incoming SIP Messages Set Yes to Validate incoming messages by checking caller ID and CSeq headers If the message does not include the heade...

Страница 12: ...an be configured under Web GUI Account X Audio Settings Figure 11 SRTP Settings Selects SRTP mode to choose No Enabled but not forced Enabled and forced or Optional Default is No It uses SDP Security...

Страница 13: ...ERVICES Firmware Upgrade and Provisioning The GRP IP Phones support downloading configuration file via TFTP HTTP HTTPS FTP FTPS Below figure shows the related options under Web GUI Maintenance Upgrade...

Страница 14: ...ted the GRP must supply the correct password in this field so it can decrypt XML configuration file after downloading it Then the configuration can be applied Please note this feature is supported on...

Страница 15: ...urity Manual CPE SSL Certificate Configures the Cert File for the ATA to connect to the ACS via SSL CPE SSL Private Key Specifies the Cert Key for the ATA to connect to the ACS via SSL Figure 14 TR 06...

Страница 16: ...GRP supports sending Syslog to a remote syslog server By default it s sent via UDP and we recommend changing it to SSL TLS so the syslog messages containing device information will be sent securely o...

Страница 17: ...the feature Local SIP Port defines the local SIP port used to listen and transmit The default value when using SIP transport protocol UDP TCP is 5060 for Account 1 5062 for Account 2 5064 for Account...

Страница 18: ...cess to public network for normal usage Use HTTPS for firmware downloading and config file downloading Use HTTPS for firmware downloading and provisioning Besides that set up username and password for...

Отзывы: