Download Product Reference Manual - NFS Professional Services

Transcript
Product Reference Manual
6
6. Security
Security
This section describes the security mechanisms and protocols implemented on the device.
The following list specifies the available security protocols and their objectives:
6.1
„
IPSec and IKE protocols are part of the IETF standards for establishing a secured IP
connection between two applications. IPSec and IKE are used in conjunction to
provide security for control and management protocols but not for media (refer to
''IPSec and IKE'' on page 101).
„
SSL (Secure Socket Layer) / TLS (Transport Layer Security). The SSL / TLS protocols
are used to provide privacy and data integrity between two communicating applications
over TCP/IP. They are used to secure the following applications: SIP Signaling (SIPS),
Web access (HTTPS) and Telnet access (refer to ''SSL/TLS'' on page 107).
„
Secured RTP (SRTP) according to RFC 3711 - used to encrypt RTP and RTCP
transport (refer to ''SRTP'' on page 109).
„
RADIUS (Remote Authentication Dial-In User Service) - RADIUS server is used to
enable multiple-user management on a centralized platform (refer to ''RADIUS Login
Authentication'' on page 110).
„
Internal Firewall for filtering unwanted inbound traffic (refer to ''Internal Firewall'' on
page 114).
IPSec and IKE
IPSec and Internet Key Exchange (IKE) protocols are part of the IETF standards for
establishing a secured IP connection between two applications (also referred to as peers).
Providing security services at the IP layer, IPSec and IKE are transparent to IP applications.
IPSec and IKE are used in conjunction to provide security for control and management
(e.g., SNMP and Web) protocols, but not for media (i.e., RTP, RTCP and T.38).
IPSec is responsible for securing the IP traffic. This is accomplished by using the
Encapsulation Security Payload (ESP) protocol to encrypt the IP payload (illustrated in the
following figure). The IKE protocol is responsible for obtaining the IPSec encryption keys
and encryption profile (known as IPSec Security Association - SA).
Figure 6-1: IPSec Encryption
Note: IPSec doesn’t function fully if the device's IP address is changed on-the-fly
due to the fact that the crypto hardware can only be configured on reset.
Therefore, reset the device after you change its IP address.
Version 5.6
101
November 2008