11-26-2019 07:41 AM
We are using sip trunk from service provider Telekom germany over the internet. To secure the connection we want to configure TLS and SRTP with service provider. Please help how to do it.
Solved! Go to Solution.
12-10-2019 09:01 PM
Marc,
After the secure trans-coder configuration all are working fine. Thank you very much for your support.
11-26-2019 08:25 AM
You have to ask the provider if they support this
Normally providers don't do this
JH
11-26-2019 08:49 AM
There are a few Cisco Live sessions on UC/CUBE security that cover the whole procedure, you can refer to those.
But as Jan mentioned, verify your telco does support this in first place.
11-26-2019 09:04 PM
Guys,
Yes they support TLS. I am looking for document i am not able to get it please help
11-27-2019 03:24 AM
You can search all the Cisco Live Presentations through the On-Demand Library:
https://www.ciscolive.com/global/on-demand-library.html?search=cube%20security#/
The LRTCOL-2310 or BRKUCC-2006 are essential presentations.
George
11-27-2019 05:25 AM
Thank you i got it.
I want to know is it possible to configure the TLS SRTP only towards service provider not towards CUCM.
If that is not possible do we need to enable mixed mode on CUCM. Even do we need to enable unity also secure connection? Because i am cluster i want to enable TLS for one remote location SIP trunk with service provider.
11-28-2019 12:55 AM
Moin,
I think this document helps:
I think they used Deutsche Telekom in this document
Hope it helps
Marc
11-28-2019 01:48 AM
Guys,
Thanks for the link i am doing for first time. I have below doubt.
1. Is TLS/SRTP possible only between CUBE-->Service provider, not between CUCM--CUBE?
2. CUCM mixed is mandatory?
3. If it is both the leg how about unity. Unity is centralized and will that works?
4. Any CSR need to generate on CUBE and get it sign by public CA?
5. Or is it directly get the public certificate and install on CUBE?
6. Any certificate need to install on CUCM and CUBE?
12-02-2019 12:46 AM
Hi,
I am using this on a 2921 ISG G2. Transcoder is required on cube. I can post a working config for the ISR G2.
My problem is the LTI Secure Transcoder. It is not working properly on shared lines . Audio comes in after a few seconds.
1. Yes. TLS/SRTP is only between Cube and Telekom. Local phones, other tenants or other trunks can be used unsecure.
2. No. I am using CME only with 8800 Sip phones
3. See no 1. All other legs can be unsecured.
4. You import the root .cer from telekom (valid until 2033) into cube. No other cert required.
5. To have a secure connection to telekom, there is no other cert required.
If you have a ISR4k my config needs to be changed a little, but you do not need the transcoder. So that would be a huge plus, because it is given me a big problems on ISR G2.
Gruss
Marc
12-02-2019 09:04 PM
Hi Marc,
Thank you for your input it is very helpful. yes i am your ISR4K series router. If possible please share your configuration it will be more helpful.
12-02-2019 11:01 PM - edited 12-03-2019 12:08 AM
Hi,
Download the telekom certificate:
My configuration, changed to ISR4K, is attached. Hope it works for you.
Please remove your uncrypted telekom registrar on port 5060 from you config.
Let us know the result.
Marc
12-03-2019 12:33 AM
Hi Marc,
Thank you.
Sorry for confusion my router is ISR 2911 only. What could be issue my might face and what is the work around for that.
I saw your configuration and there is no registration under SIP-UA. Is it not required or i need to update in 5061 and configure?
Is trans-coder need to configure with secure?
12-03-2019 01:14 AM
Hi,
on the ISR-G2 you need a transcoder for SRTP-RTP and RTP-SRTP.
My problem is that I use CME and on the incoming central line (0) the audio comes in after a few seconds on the phones. The sip-dn for extension zero (0) is a shared dn (sip only, not mixed shared line with SCCP) on 5 sip phones 8851 and a ATA190.
But this is specific to my configuration, and if you use a CUCM this may not be a problem for you.
Workaround is to use the Telekom Sip Trunk unsecure, or make the phones on CME secure (TLS/SRTP) as well.
The sip-ua registration is under "Tenant". With Tenants you can use multiple sip provider.
For the use of TLS/SRTP on Telekom Sip Trunk with ISR G2:
Download the telekom certificate
Please remove your uncrypted telekom registrar on port 5060 from you config.
Let me know how the transcoder works for you.
Marc
12-04-2019 02:42 AM
Hi Marc,
Waiting for change window and let you know once done
12-04-2019 03:45 AM - edited 12-04-2019 06:02 AM
Hi,
you have to check the amount of DSP's installed in your ISR2911 (sh inv). The 2911 voice bundle is equiped with a PVDM3-16 by default. That means you have to set "maximum sessions 6" in the LTI transcoder (if it is the only transcoder configured).
I have a ISR2921 with a PVDM3-32, so I can set "maximum sessions 12".
For ISR G2s/4K series, install the UCK9 package license to access all the voice features including CUBE. For SIP TLS/SRTP, SEC-K9 license is also required.
Hope this helps,
Marc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide