VoIP Security
343
Figure 60: Media and Signaling Path Encryption
The signalling paths with security do not take different network routes compared to those without
security. The only difference is that the contents of the payload are encrypted. The only additions
for security are messages to establish the point-to-point secure connections and the negotiation
of the secure voice connection. Thus the signalling is secured; MiNET becomes Secure-MiNET
and MiTAI becomes Secure-MiTAI.
Once the signalling paths are established and a voice connection can be made, the two end
devices will negotiate the keys and method of voice encryption. Once agreed, the voice now
streams directly between the two devices. This is the same as the unencrypted case, only the
voice data is encrypted.
VOICE STREAMING SECURITY (SRTP)
Mitel controllers and selected IP sets and applications support RFC 3711 standard Secure
RTP. This provides added confidentiality, message authentication and replay protection over
the standard RTP protocol. A call will be encrypted, and will use the most secure method if both
ends support encryption. Calls initiated on a controller, an IP Phone, or an end device that does
not support encryption are still supported, but will not be encrypted.
Media (voice) streaming between Mitel sets and controllers will use a version of SRTP with a
predefined algorithm (Mitel SRTP), so that negotiation of the secure connection is very quick.
Mitel products connecting to third-party equipment must negotiate the key exchange for the
security algorithm, and the process will be more processor intensive.
SIGNALLING SECURITY
Two main methods are used to secure a signalling channel. These are:
•
SSL (Secure Socket Layer) or TLS (Transport Layer Security), both open standards
•
Secure MiNET (a Mitel proprietary standard)
Mitel's Secure MiNET protocol uses the Advanced Encryption Standard (AES) to encrypt call
control packets. Using secure MiNET ensures that call control signalling packets between the
Содержание MiVOICE BUSINESS
Страница 1: ...Mitel MiVoice Business RELEASE 7 2 ENGINEERING GUIDELINES ...
Страница 15: ...Chapter 1 ABOUT THIS DOCUMENT ...
Страница 16: ......
Страница 22: ...Engineering Guidelines 8 ...
Страница 23: ...Chapter 2 SYSTEM OVERVIEW ...
Страница 24: ......
Страница 28: ...Engineering Guidelines 14 ...
Страница 29: ...Chapter 3 TYPICAL CONFIGURATIONS ...
Страница 30: ......
Страница 73: ...Chapter 4 PHONES AND VOICE APPLICATIONS ...
Страница 74: ......
Страница 95: ...Phones and Voice Applications 81 Figure 9 ICP Connection Paths and Limitations ...
Страница 100: ...Engineering Guidelines 86 ...
Страница 101: ...Chapter 5 POWER ...
Страница 102: ......
Страница 128: ...Engineering Guidelines 114 ...
Страница 129: ...Chapter 6 PERFORMANCE ...
Страница 130: ......
Страница 135: ...Chapter 7 APPLICATIONS ...
Страница 136: ......
Страница 142: ...Engineering Guidelines 128 ...
Страница 143: ...Chapter 8 EMERGENCY SERVICES ...
Страница 144: ......
Страница 151: ...Chapter 9 IP NETWORKING ...
Страница 152: ......
Страница 167: ...Chapter 10 LICENSING ...
Страница 168: ......
Страница 183: ...Chapter 11 BANDWIDTH CODECS AND COMPRESSION ...
Страница 184: ......
Страница 209: ...Chapter 12 NETWORK CONFIGURATION CONCEPTS ...
Страница 210: ......
Страница 244: ...Engineering Guidelines 230 ...
Страница 245: ...Chapter 13 NETWORK CONFIGURATION SPECIFICS ...
Страница 246: ......
Страница 309: ...Appendix A CAT 3 WIRING ...
Страница 310: ......
Страница 315: ...CAT 3 Wiring 301 Figure 55 CX MX MXe AX and LX Minimum Cable Standard ...
Страница 316: ...Engineering Guidelines 302 ...
Страница 317: ...Appendix B INSTALLATION EXAMPLES ...
Страница 318: ......
Страница 335: ...Appendix C LLDP AND LLDP MED CONFIGURATION EXAMPLES ...
Страница 336: ......
Страница 347: ...Appendix D VOIP AND VLANS ...
Страница 348: ......
Страница 353: ...Appendix E VOIP SECURITY ...
Страница 354: ......
Страница 381: ... ...