cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
528
Views
0
Helpful
1
Replies

SPA 303 and 504G SRTP issue

tsyganovdmitriy
Level 1
Level 1

Hi,

I have a problem that when SRTP mode is enabled on SPA 303 and 504G answer "488 not acceptable here" on incoming INVITE.

 

SDP of incoming INVITE:

v=0
o=FreeSWITCH 1505106066 1505106067 IN IP4 38.108.164.66
s=FreeSWITCH
c=IN IP4 38.108.164.66
t=0 0
m=audio 18942 RTP/SAVP 102 9 0 8 101
a=rtpmap:102 G7221/16000
a=fmtp:102 bitrate=32000
a=rtpmap:9 G722/8000
a=rtpmap:0 PCMU/8000
a=rtpmap:8 PCMA/8000
a=rtpmap:101 telephone-event/8000
a=fmtp:101 0-16
a=crypto:1 AEAD_AES_256_GCM_8 inline:gQ8RJ38GjfEPxG9EWnwveTLVlN08TY/GAjyBTqNOaJtMpMn85paHTnDFVU4
a=crypto:2 AEAD_AES_128_GCM_8 inline:MQhTXchw2n0qniYY7F63MV3FmmJotUQBhHbpOQ
a=crypto:3 AES_CM_256_HMAC_SHA1_80 inline:7aN+4+f0zuZtLWzu/2EjHA3/nV9veShF3pU2j7G4k6mDaVKzyYshU51tLBofdg
a=crypto:4 AES_CM_192_HMAC_SHA1_80 inline:hJJXx0LBB1/9krgj/3/2Gpp5YCFCSSFo+fCuaZNMG5y03KgVMvc
a=crypto:5 AES_CM_128_HMAC_SHA1_80 inline:bZLGdFEleuOYt4VPbTUbDGlJNWZsdMCpx6h7YWtw
a=crypto:6 AES_CM_256_HMAC_SHA1_32 inline:Fj7S/25ik1/jyrdm2QhoHmYrHsYAJ0qRJ39biU5Zg3ojZ7GBzsUFEdkjyETKsA
a=crypto:7 AES_CM_192_HMAC_SHA1_32 inline:VceVwNWS3UPIW0roZ33TB/KOYXCFAGQOhsPBjtyTD3JUiDFRwU0
a=crypto:8 AES_CM_128_HMAC_SHA1_32 inline:O0IygwJtNzKM2vKbPtVN05D19cAL/92N+8vUegzm
a=crypto:9 AES_CM_128_NULL_AUTH inline:PB46MMF+0VCfv8htKCeOel3OJ8v19ZYxCCZCKfvr
a=silenceSupp:off - - - -
a=ptime:20

 

I did some tests and looks like phones answer 488 when SDP contains crypto suits AEAD_AES_256_GCM_8 and AEAD_AES_128_GCM_8.

Don't this model support these kind of crypto suits?

Or what can i do to setup phones to not reject session since other crypto suits in SDP works fine

Software version is 7.6.1

1 Reply 1

Jaime Valencia
Cisco Employee
Cisco Employee

SPA endpoints are covered in the SMB area, might want to ask there.

HTH

java

if this helps, please rate