Cisco 6941 Administration Guide - Page 30

Understanding Security Profiles, Identifying Encrypted Phone Calls

Page 30 highlights

Understanding Security Features for Cisco Unified IP Phones Chapter Table 1-6 Overview of Security Features (continued) Feature Phone hardening 802.1X Authentication Description Additional security options, which you control from Cisco Unified CM Administration: • Disabling PC port • Disabling PC Voice VLAN access • Disabling access to web pages for a phone Note You can view current settings for the PC Port Disabled, GARP Enabled, and Voice VLAN enabled options by looking at the phone's Security Configuration menu. For more information, see the "Security Configuration Menu" section on page 4-9. The Cisco Unified IP Phone can use 802.1X authentication to request and gain access to the network. See the "Supporting 802.1X Authentication on Cisco Unified IP Phones" section on page 1-21 for more information. Related Topics • Understanding Security Profiles, page 1-18 • Identifying Encrypted Phone Calls, page 1-18 • Security Restrictions, page 1-22 Understanding Security Profiles All Cisco Unified IP Phones that support Cisco Unified CM use a security profile, which defines whether the phone is nonsecure or encrypted. For information about configuring the security profile and applying the profile to the phone, refer to Cisco Unified Communications Manager Security Guide. To view the security mode that is set for the phone, look at the Security Mode setting in the Security Configuration menu. For more information, see the "Security Configuration Menu" section on page 4-9. Related Topics • Identifying Encrypted Phone Calls, page 1-18 • Security Restrictions, page 1-22 Identifying Encrypted Phone Calls When security is implemented for a phone, you can identify encrypted phone calls by icons on the screen on the phone. You can also determine if the connected phone is secure and protected if a security tone plays at the beginning of the call. In a secure call, all call signaling and media streams are encrypted. An encrypted call offers a high level of security, providing integrity and privacy to the call. When a call in progress is being encrypted, the call progress icon to the right of the call duration timer in the phone LCD screen changes to the lock icon: . If the call is routed through non-IP call legs, for example, PSTN, the call may be nonsecure even though it is encrypted within the IP network and has a lock icon associated with it. 1-18 Cisco Unified IP Phone 6921, 6941, 6945, and 6961 Administration Guide for Cisco Unified Communications Manager 8.5 (SCCP and SIP) OL-23769-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196

1-18
Cisco Unified IP Phone 6921, 6941, 6945, and 6961 Administration Guide for Cisco Unified Communications Manager 8.5 (SCCP and SIP)
OL-23769-01
Chapter
Understanding Security Features for Cisco Unified IP Phones
Related Topics
Understanding Security Profiles, page 1-18
Identifying Encrypted Phone Calls, page 1-18
Security Restrictions, page 1-22
Understanding Security Profiles
All Cisco Unified IP Phones that support Cisco Unified CM use a security profile, which defines whether
the phone is nonsecure or encrypted. For information about configuring the security profile and applying
the profile to the phone, refer to
Cisco Unified Communications Manager Security Guide
.
To view the security mode that is set for the phone, look at the Security Mode setting in the Security
Configuration menu. For more information, see the
“Security Configuration Menu” section on page 4-9
.
Related Topics
Identifying Encrypted Phone Calls, page 1-18
Security Restrictions, page 1-22
Identifying Encrypted Phone Calls
When security is implemented for a phone, you can identify encrypted phone calls by icons on the screen
on the phone. You can also determine if the connected phone is secure and protected if a security tone
plays at the beginning of the call.
In a secure call, all call signaling and media streams are encrypted. An encrypted call offers a high level
of security, providing integrity and privacy to the call. When a call in progress is being encrypted, the
call progress icon to the right of the call duration timer in the phone LCD screen changes to the lock
icon:
.
If the call is routed through non-IP call legs, for example, PSTN, the call may be nonsecure even though
it is encrypted within the IP network and has a lock icon associated with it.
Phone hardening
Additional security options, which you control from Cisco Unified CM
Administration:
Disabling PC port
Disabling PC Voice VLAN access
Disabling access to web pages for a phone
Note
You can view current settings for the PC Port Disabled, GARP Enabled,
and Voice VLAN enabled options by looking at the phone’s Security
Configuration menu. For more information, see the
“Security
Configuration Menu” section on page 4-9
.
802.1X Authentication
The Cisco Unified IP Phone can use 802.1X authentication to request and gain
access to the network. See the
“Supporting 802.1X Authentication on Cisco
Unified IP Phones” section on page 1-21
for more information.
Table 1-6
Overview of Security Features (continued)
Feature
Description