cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
526
Views
15
Helpful
4
Replies

Voice Traffic Security

bobby.jacob
Level 1
Level 1

Hello all,

One of our clients planning to have encryption on voice traffic, Does anyone have experiance on the configuration?

Basically customer needs all their voice conversation to be secured.

Any good documents on this will be really helpful.

We have CM 8.5 on one PUB and 2 SUB.

Almost 300 phones distributed in HQ and in 2 remote sites.

tnx

Bobby

4 Replies 4

Jaime Valencia
Cisco Employee
Cisco Employee

All info is here

Cisco Unified Communications Manager Security Guide, Release 8.5(1)

http://www.cisco.com/en/US/partner/docs/voice_ip_comm/cucm/security/8_5_1/secugd/sec-851-cm.html

HTH

java

if this helps, please rate

www.cisco.com/go/pdihelpdesk

HTH

java

if this helps, please rate

William Bell
VIP Alumni
VIP Alumni

One of my colleagues did a blog series on this topic. It was on CUCM 7.1 but a decent portion of the info should still be relevant.

http://www.netcraftsmen.net/resources/blogs/configuring-calling-encryption-between-cisco-ip-phones.html

-Bill

HTH -Bill (b) http://ucguerrilla.com (t) @ucguerrilla

Please remember to rate helpful responses and identify

tnx bill/java,

A small concern By doing encription on phones, will it make any impact on our third party integrations like our billing system,right fax, and tandberg VCS sip trunk?

tnx

Bobby,

I would say that you have to consider all integration points when enabling signaling and media encryption. That isn't to say all integration points will fail or need to be tinkered with. Just that you have to identify your integration points, assess impact, and determine action (if needed).  For the three integration points you listed:

Billing System. In general, billing systems will not be affected by provisioning a secure call processing environment.

Right Fax. If you are TDM integrated (CAS or ISDN trunk) then there is definitely no impact. If you are integrated with SIP trunk (i.e. you are doing T.38) then the answer is "it depends". I am not sure if Right Fax will support encrypted signaling (SIP over TLS) nor do I know if it supports SRTP. A quick google search should answer that question. Keep in mind that CUCM is aware of the security status of all call legs. If an unsecure device is added to a call with one or more secure devices, the call can succeed as an unsecure call.

Tandberg VCS. You know, I have set up encryption on both VCS and UCM but not between. Though, I know that you can provision TLS for secure signaling between the two systems. The VCS deployment guide for CUCM should cover that. I'd suspect you can do secure voice media. On UCM version 8.5 I don't think encrypted/secure video is supported with video endpoints registered to UCM.

HTH.

-Bill (http://ucguerrilla.com)

HTH -Bill (b) http://ucguerrilla.com (t) @ucguerrilla

Please remember to rate helpful responses and identify