01-16-2013 10:51 AM - edited 03-16-2019 03:12 PM
Hello all,
One of our clients planning to have encryption on voice traffic, Does anyone have experiance on the configuration?
Basically customer needs all their voice conversation to be secured.
Any good documents on this will be really helpful.
We have CM 8.5 on one PUB and 2 SUB.
Almost 300 phones distributed in HQ and in 2 remote sites.
tnx
Bobby
01-16-2013 10:57 AM
All info is here
Cisco Unified Communications Manager Security Guide, Release 8.5(1)
http://www.cisco.com/en/US/partner/docs/voice_ip_comm/cucm/security/8_5_1/secugd/sec-851-cm.html
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
01-16-2013 11:01 AM
One of my colleagues did a blog series on this topic. It was on CUCM 7.1 but a decent portion of the info should still be relevant.
-Bill
Please remember to rate helpful responses and identify
01-16-2013 12:15 PM
tnx bill/java,
A small concern By doing encription on phones, will it make any impact on our third party integrations like our billing system,right fax, and tandberg VCS sip trunk?
tnx
01-18-2013 05:30 AM
Bobby,
I would say that you have to consider all integration points when enabling signaling and media encryption. That isn't to say all integration points will fail or need to be tinkered with. Just that you have to identify your integration points, assess impact, and determine action (if needed). For the three integration points you listed:
Billing System. In general, billing systems will not be affected by provisioning a secure call processing environment.
Right Fax. If you are TDM integrated (CAS or ISDN trunk) then there is definitely no impact. If you are integrated with SIP trunk (i.e. you are doing T.38) then the answer is "it depends". I am not sure if Right Fax will support encrypted signaling (SIP over TLS) nor do I know if it supports SRTP. A quick google search should answer that question. Keep in mind that CUCM is aware of the security status of all call legs. If an unsecure device is added to a call with one or more secure devices, the call can succeed as an unsecure call.
Tandberg VCS. You know, I have set up encryption on both VCS and UCM but not between. Though, I know that you can provision TLS for secure signaling between the two systems. The VCS deployment guide for CUCM should cover that. I'd suspect you can do secure voice media. On UCM version 8.5 I don't think encrypted/secure video is supported with video endpoints registered to UCM.
HTH.
-Bill (http://ucguerrilla.com)
Please remember to rate helpful responses and identify
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide