This document covers the configuration procedure to implement endpoint hardening for securing Cisco Unified Communications Manager devices against various forms of attacks and vulnerabilities. Deploying a VoIP infrastructure introduces a new set of challenges and Securing Unified Communications allows the phones to communicate over the secure real time protocol and prevent access from allowing unsecured devices.
Implementing endpoint hardening on CUCM
Endpoint hardening can provide greater protection from various forms of attacks.
To harden an endpoint from various forms of attacks and vulnerabilities, perform the following:
1. Navigate to the endpoint to be hardened on the Cisco Unified Communications Administration page: Device --> Phone
2. Under the Product Specific Configuration Layout section, enable or disable the following fields as required:
Based on your requirement you can disable the fields which are not required. Those that are not required can be disabled as part of endpoint hardening.
PC Port - Disabled
This prevents the users from connecting a computer to the network by way of this port, useful for disabling the phones connected in lobby/reception area.
Settings Access - Disabled
Disabling access to the settings menu prevents a user from gathering information about the networking, including relevant IP addresses and VLAN information
Gratuitous ARP - Disabled
PC Voice VLAN Access – Disabled
Disabling the PC Port VLAN access, prevent users connected to the phone from sniffing voice traffic. This feature can be useful for administrators when troubleshooting, but in general should be disabled and enabled on an as-needed basis.
Video capabilities – Disable
Auto Line select - Disabled
Web Access - Disabled
3. Click --> Save.
4. Click --> Reset.
5. Repeat these steps for each endpoint that requires hardening.
By doing this we can increase the security of our setup and prevent our phones from attacks such as Gratuitous ARP poisoning.
Hello there, I been reading that when ordering a new BE server, it comes with pre loaded apps, does these pre loaded apps also include the CER app in the same physical server? I see CER licenses are included in the top level sku (R-CBE6-K9).&nbs...
I am unable to update my Windows 10 computer to any version past 1803. If I do, I get an 'invalid extension' when trying to log into my CUACS application.I am currently running 126.96.36.19904 version... is there a fix for this problem?? I can't h...
Hi,When I applied the call forwarding rule, the destination number only rang about 2 rings. Is there a setting on either the Cisco Call Manager or on the host's Cisco desk phone that I can apply to increase the number of rings?