cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
388
Views
0
Helpful
4
Replies

Is it possible to secure E-SRST?

Nadav
Level 7
Level 7

Hi everyone,

 

From what I can tell, E-SRST doesn't support any kind of security (authentication or encryption). Is this correct, and is there anything in the Cisco roadmap for adding a secure E-SRST feature? 

 

Thanks!

4 Replies 4

Akshay Sachdeva
Level 1
Level 1

Hi,

 

Kindly confirm the exact implementation of E-SRST. Are you doing through SRST manager or if you're talking about the mode under voice service voip. 

 

If you're talking about under the voice service voip, E-SRST mode then we can surely secure it. Basically E-SRST provides extra features as compared to the normal SRST mode. So the method of securing E-SRST is same as the SRST mode. I'm attaching a link below which provides a configuration example of securing your SRST/E-SRST environment.

 

http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/admin/sccp_sip_srst/configuration/guide/SCCP_and_SIP_SRST_Admin_Guide/srst_secure_sccp_and_sip.html#pgfId-1565299

 

Regards

Akshay

Hi Akshay,

 

Thanks for the quick response.

I'm referring to E-SRST as a disaster recovery solution which is provisioned by SRST Manager. It allows a certain number of phones to retain their functionality and communicate with all other phones registered to the E-SRST in the case of the branch site being disconnected. Is it possible to ensure that the phone register with the E-SRST via SIPS (the UCM cluster is in Mixed Mode)?

 

In this link: http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cusrst/requirements/guide/srs105spc.html

It states that secure E-srst is not supported. This makes me question whether or not I can authenticate SIP or encrypt RTP under fallback mode.

Does anyone know whether or not you can secure an ESRST (auth/encryption)  for fallback mode?

Hi,

 

If you are referring to enhanced SRST mode, then you can secure it. E-SRST is basically a CME used for failover. It can have the entire security capability of CME