Cisco 521SG Administration Guide - Page 132

Securing Voice Traffic with SRTP, Authorizing Secure Calls with a Mini-certification

Page 132 highlights

Configuring Security, Quality, and Network Features Setting Security Features 5 Securing Voice Traffic with SRTP Secure Real-Time Transport Protocol (SRTP) is a secure protocol for transporting real-time data over networks. It provides media encryption to ensure that media streams between devices are secure and that only the intended devices receive and read the data. Cisco SPA IP phones use SRTP to securely send and receive voice traffic to and from phones and gateways that support SRTP. (Security Description (RFC-4568) is supported.) When a call is secured with SRTP, the voice conversation is encrypted so that others cannot eavesdrop on the conversation. To enable this feature, Cisco SPA IP phones must have a mini-certificate installed. Defaults to prefer to use encrypted media (voice codecs). Audio packets in both directions of outbound calls are encrypted by using SRTP. Authorizing Secure Calls with a Mini-certification The phone can encrypt calls to protect them from eavesdroppers. The dial pad codes for encrypting calls are: • *16-Secures all calls. • *17-Disable the call security the user enabled by dialing *16. • *18-Secures an individual call when dialed before or during a call. Using this star code is redundant if all outbound calls are already secure by default or from having dialed *16. To enable call encryption on the phone web user interface: STEP 1 Obtain the Generate Mini-Cert tool from your service provider. STEP 2 Navigate to Admin Login > advanced > Voice > Ext_n. STEP 3 Under Subscriber Information, enter the Mini Certificate and the SRTP Private Key that provide secure encryption of RTP streams between two endpoints on an extension. STEP 4 To enable the secure call service, navigate to Admin Login > advanced > Voice > Phone. STEP 5 Under Supplementary Services verify that Secure Call Serv is set to yes. (This feature can also be configured in the User tab under Supplementary Services.) Cisco Small Business SPA300 Series, SPA500 Series, and WIP310 IP Phone Administration Guide 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325

Configuring Security, Quality, and Network Features
Setting Security Features
Cisco Small Business SPA300 Series, SPA500 Series, and WIP310 IP Phone Administration Guide
131
5
Securing Voice Traffic with SRTP
Secure Real-Time Transport Protocol (SRTP) is a secure protocol for transporting
real-time data over networks. It provides media encryption to ensure that media
streams between devices are secure and that only the intended devices receive
and read the data. Cisco SPA IP phones use SRTP to securely send and receive
voice traffic to and from phones and gateways that support SRTP. (Security
Description (RFC-4568) is supported.)
When a call is secured with SRTP, the voice conversation is encrypted so that
others cannot eavesdrop on the conversation.
To enable this feature, Cisco SPA IP
phones must have a mini-certificate installed.
Defaults to prefer to use encrypted media (voice codecs). Audio packets in both
directions of outbound calls are encrypted by using SRTP.
Authorizing Secure Calls with a Mini-certification
The phone can encrypt calls to protect them from eavesdroppers. The dial pad
codes for encrypting calls are:
*16—Secures all calls.
*17—Disable the call security the user enabled by dialing *16.
*18—Secures an individual call when dialed before or during a call. Using
this star code is redundant if all outbound calls are already secure by
default or from having dialed *16.
To enable call encryption on the phone web user interface:
STEP 1
Obtain the Generate Mini-Cert tool from your service provider.
STEP
2
Navigate to
Admin Login
>
advanced
>
Voice
>
Ext_n.
STEP
3
Under
Subscriber Information
, enter the
Mini Certificate
and the
SRTP Private
Key
that provide secure encryption of RTP streams between two endpoints on an
extension.
STEP
4
To enable the secure call service, navigate to
Admin Login
>
advanced
>
Voice
>
Phone.
STEP
5
Under
Supplementary Services
verify that
Secure Call Serv
is set to
yes
. (This
feature can also be configured in the
User
tab under
Supplementary Services
.)