01-23-2023 03:39 AM
Hi
We currently have CUCM/IMP/CUC (SCCP integration ) version 12.5 . Wanted to understand what security features are enabled by default in these versions. What are the benefits of Mixed mode vs Non Secure mode. What is the maximum in terms of Security that we can achieve in CUC( SCCP integration)?
Any documentation explaining the Security Features enabled on CUCM/IMP/CUC would be helpful.
Thanks in Advance
01-23-2023 03:57 AM
01-26-2023 03:47 AM - edited 01-26-2023 03:47 AM
TL;DR- Mixed mode with CAPF gets you up to four things:
Without it all you get are digitally signed TFTP config files to prevent spoofing that could proxy the phone through a malicious call control agent. This is the ITL architecture - and it borrows many concepts from the CTL with CAPF.
Be warned: CAPF requires real work to setup initially and maintain thereafter! The biggest gotcha is that LSCs do not renew automatically; you must initiate the renewal and the phone must be registered for it to work. Phones will unregister and stop working if their LSC expires! There is a BAT job to do this in bulk, usually once every few years per-Device Pool.
Also worth mentioning that CUCM 14 introduced OAuth tokens as an alternative to CAPF LSCs. A huge advantage is that they auto-renew every 60 days if the phone is online. They only accomplish the first two of the four bullets above though.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide