Download Product Reference Manual - NFS Professional Services
Transcript
Product Reference Manual 6 6. Security Security This section describes the security mechanisms and protocols implemented on the device. The following list specifies the available security protocols and their objectives: 6.1 IPSec and IKE protocols are part of the IETF standards for establishing a secured IP connection between two applications. IPSec and IKE are used in conjunction to provide security for control and management protocols but not for media (refer to ''IPSec and IKE'' on page 101). SSL (Secure Socket Layer) / TLS (Transport Layer Security). The SSL / TLS protocols are used to provide privacy and data integrity between two communicating applications over TCP/IP. They are used to secure the following applications: SIP Signaling (SIPS), Web access (HTTPS) and Telnet access (refer to ''SSL/TLS'' on page 107). Secured RTP (SRTP) according to RFC 3711 - used to encrypt RTP and RTCP transport (refer to ''SRTP'' on page 109). RADIUS (Remote Authentication Dial-In User Service) - RADIUS server is used to enable multiple-user management on a centralized platform (refer to ''RADIUS Login Authentication'' on page 110). Internal Firewall for filtering unwanted inbound traffic (refer to ''Internal Firewall'' on page 114). IPSec and IKE IPSec and Internet Key Exchange (IKE) protocols are part of the IETF standards for establishing a secured IP connection between two applications (also referred to as peers). Providing security services at the IP layer, IPSec and IKE are transparent to IP applications. IPSec and IKE are used in conjunction to provide security for control and management (e.g., SNMP and Web) protocols, but not for media (i.e., RTP, RTCP and T.38). IPSec is responsible for securing the IP traffic. This is accomplished by using the Encapsulation Security Payload (ESP) protocol to encrypt the IP payload (illustrated in the following figure). The IKE protocol is responsible for obtaining the IPSec encryption keys and encryption profile (known as IPSec Security Association - SA). Figure 6-1: IPSec Encryption Note: IPSec doesn’t function fully if the device's IP address is changed on-the-fly due to the fact that the crypto hardware can only be configured on reset. Therefore, reset the device after you change its IP address. Version 5.6 101 November 2008