Cisco 7971G-GE Administration Guide - Page 26

Understanding Security Profiles

Page 26 highlights

Understanding Security Features for Cisco Unified IP Phones Chapter 1 An Overview of the Cisco Unified IP Phone Table 1-3 Overview of Security Features (continued) Feature Security profiles Encrypted configuration files Optional disabling of the web server functionality for a phone Phone hardening 802.1X Authentication Description Defines whether the phone is nonsecure, authenticated, encrypted, or protected. See the "Understanding Security Profiles" section on page 1-12 for more information. Lets you ensure the privacy of phone configuration files. You can prevent access to a phone's web page, which displays a variety of operational statistics for the phone. Additional security options, which you control from Cisco Unified Communications Manager Administration: • Disabling PC port • Disabling Gratuitous ARP (GARP) • Disabling PC Voice VLAN access • Disabling access to the Setting menus, or providing restricted access that allows access to the User Preferences menu and saving volume changes only • Disabling access to web pages for a phone. Note You can view current settings for the PC Port Disabled, GARP Enabled, and Voice VLAN enabled options by looking at the phone's Security Configuration menu. For more information, see the "Device Configuration Menu" section on page 4-10. The Cisco Unified IP Phone can use 802.1X authentication to request and gain access to the network. See the "Supporting 802.1X Authentication on Cisco Unified IP Phones" section on page 1-16 for more information. Related Topics • Understanding Security Profiles, page 1-12 • Identifying Authenticated, Encrypted, and Protected Phone Calls, page 1-13 • Establishing and Identifying Secure Conference Calls, page 1-14 • Device Configuration Menu, page 4-10 • Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-16 • Security Restrictions, page 1-17 Understanding Security Profiles Cisco Unified IP Phones that support Cisco Unified Communications Manager 7.0 or later use a security profile, which defines whether the phone is nonsecure, authenticated, or encrypted. For information about configuring the security profile and applying the profile to the phone, refer to Cisco Unified Communications Manager Security Guide. To view the security mode that is set for the phone, look at the Security Mode setting in the Security Configuration menu. For more information, see the "Security Configuration Menu" section on page 4-23. 1-12 Cisco Unified IP Phone 7970G/7971G-GE Administration Guide for Cisco Unified Communications Manager 7.0 OL-15299-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219

1-12
Cisco Unified IP Phone 7970G/7971G-GE Administration Guide for Cisco Unified Communications Manager 7.0
OL-15299-01
Chapter 1
An Overview of the Cisco Unified IP Phone
Understanding Security Features for Cisco Unified IP Phones
Related Topics
Understanding Security Profiles, page 1-12
Identifying Authenticated, Encrypted, and Protected Phone Calls, page 1-13
Establishing and Identifying Secure Conference Calls, page 1-14
Device Configuration Menu, page 4-10
Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-16
Security Restrictions, page 1-17
Understanding Security Profiles
Cisco Unified IP Phones that support Cisco Unified Communications Manager 7.0 or later use a security
profile, which defines whether the phone is nonsecure, authenticated, or encrypted. For information
about configuring the security profile and applying the profile to the phone, refer to
Cisco Unified
Communications Manager Security Guide
.
To view the security mode that is set for the phone, look at the Security Mode setting in the Security
Configuration menu. For more information, see the
“Security Configuration Menu” section on
page 4-23
.
Security profiles
Defines whether the phone is nonsecure, authenticated, encrypted, or protected.
See the
“Understanding Security Profiles” section on page 1-12
for more
information.
Encrypted configuration files
Lets you ensure the privacy of phone configuration files.
Optional disabling of the web server
functionality for a phone
You can prevent access to a phone’s web page, which displays a variety of
operational statistics for the phone.
Phone hardening
Additional security options, which you control from
Cisco Unified Communications Manager Administration:
Disabling PC port
Disabling Gratuitous ARP (GARP)
Disabling PC Voice VLAN access
Disabling access to the Setting menus, or providing restricted access that
allows access to the User Preferences menu and saving volume changes only
Disabling access to web pages for a phone.
Note
You can view current settings for the PC Port Disabled, GARP Enabled,
and Voice VLAN enabled options by looking at the phone’s Security
Configuration menu. For more information, see the
“Device Configuration
Menu” section on page 4-10
.
802.1X Authentication
The Cisco Unified IP Phone can use 802.1X authentication to request and gain
access to the network. See the
“Supporting 802.1X Authentication on Cisco
Unified IP Phones” section on page 1-16
for more information.
Table 1-3
Overview of Security Features (continued)
Feature
Description