FREQUENTLY ASKED QUESTIONS ETERNITY PE/GE/ME/LE Date: 31 st January 2015 Version: V1R1 Author: Vishal Govindiya
Security options available in ETERNITY on VoIP Network Security on VoIP in Site to Site Connectivity 1. Digest Authentication
Programming Required in ETERNITY Enable Digest Authentication in SIP Trunk Parameters Advance option Digest Authentication Enabled Program Digest Authentication table with credentials in ETERNITY Enter Credentials to be used for Digest Authentication for IP PBX ETERNITY Call Traffic
Programming Required in IP-PBX Program same Digest Credentials in IP-PBX 2. White List IP Address
Program White list IP Address with the static IP of IP-PBX (i.e. 203.116.97.51 in this case) to allow incoming call traffic only from IP PBX If Enable IP Address based Call traffic restriction is enabled, but the White List IP Address table is blank, all the Incoming call traffic will be rejected Keep the subnet mask to 255.255.255.255 for each entry. It will block all the IP Addresses other than the programmed IP Address
3. TLS Enable SIP Over TLS in VoIP Port Parameters (Default: Enabled)
Select Default Transport for Outgoing Message as TLS in Peer to Peer Table (Default: UDP) 4. SRTP
Set SRTP Mode to Forced/Optional in SIP Trunk Parameters Advance option (Default: Disable) Don t Allow Logical Partition for Peer to Peer calling
Security on VoIP when ITSP SIP Trunk is registered with ETERNITY Security Recommendations Request the Service provider to allocate strong Authentication ID and password for the SIP Account provided to you by ITSP Ask the ITSP to Enable TLS and SRTP for the SIP Account provided to you and Enable the same in ETERNITY
Security on VoIP when ETERNITY is configured for Gateway Application When ETERNITY is used for Gateway Application make sure that you allow only specific trunk routing (In above diagram we want to allow only VoIP GSM Routing Mobile Trunk has Category 2 applied Allow/Restrict call routing between different trunks
Security on VoIP when ETERNITY is used as SIP Server (SIP Extensions are registered over LAN and WAN) Keep Authentication Password as long as possible (up to 24 alphanumeric characters)
For Extended IP Phones, set Transport mode as TLS under location Settings Set SRTP for SIP clients (Standard & Extended) under SIP Extension settings
Set SRTP for Extended SIP client under SIP Extension settings Advance Location 1,2 or 3 (Default: Disabled) Enable SRTP for Matrix Extended IP Phone
Feature Availability chart: Security Feature White List IP address Peer to Peer SIP Trunk Proxy SIP Trunk Standard SIP SIP Extension Extended SIP Logical Partition Digest Authentication TLS * SRTP * *TLS and SRTP are not available in SPARSH VP248 Important Security Recommendations to Prevent outside intruders attacking system Never disclose SIP/System log-in credentials to anyone. Remember to make your password unique, so it is hard for someone to guess. Update your password on a regular basis Never use default login passwords for SIP Extensions. It is recommended to use a long (up to 24 alphanumeric characters) password The user should restrict port scanning and ping of Public static IP used in VoIP Communication Change the System Engineer (SE) and System Administrator (SA) password and make sure no one can access ETERNITY GUI except concern person Change the default WEB GUI port of ETERNITY Change the default SIP and RTP ports on VoIP card
For more information, contact Matrix Technical Training Team Training@MatrixComSec.com Disclaimer: The information contained in this e-mail and/or attachment may contain confidential or privileged information. Unauthorized use, disclosure or copying is strictly prohibited and may constitute unlawful act and can possibly attract legal action, civil and/or criminal. The contents of this message need not necessarily reflect or endorse the views of Matrix ComSec Pvt Ltd on any subject matter. Any action taken or omitted on this message is not entirely at your risk and the originator of this message nor does Matrix ComSec Pvt Ltd take any responsibility or liability towards the same. If you are not the intended recipient, please notify us immediately and permanently delete the message.