ZyXEL VMG9823 User Guide - Page 219

Any_WAN, MultiWAN, Start Port, End Port, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32,

Page 219 highlights

Chapter 21 Voice Table 98 VoIP > SIP > SIP Service Provider > Add New Provider/Edit (continued) LABEL DESCRIPTION Don't send reInvite to the remote party when there are multiple codecs answered in the SDP Do not send a re-Invite packet to the remote party when the remote party answers that it can support multiple codecs. Bound Interface Name Bound If you select Any_WAN, the VMG automatically activates the VoIP service when any WAN Interface Name connection is up. If you select MultiWAN, you also need to select two or more pre-configured WAN interfaces. The VoIP service is activated only when one of the selected WAN connections is up. Outbound Proxy Outbound Proxy Address Enter the IP address or domain name of the SIP outbound proxy server if your VoIP service provider has a SIP outbound server to handle voice calls. This allows the VMG to work with any type of NAT router and eliminates the need for STUN or a SIP ALG. Turn off any SIP ALG on a NAT router in front of the VMG to keep it from re-translating the IP address (since this is already handled by the outbound proxy server). Outbound Proxy Port Enter the SIP outbound proxy server's listening port, if your VoIP service provider gave you one. Otherwise, keep the default value. Use DHCP Option 120 First Select this to enable the SIP server via DHCP option 120. RTP Port Range Start Port End Port Enter the listening port number(s) for RTP traffic, if your VoIP service provider gave you this information. Otherwise, keep the default values. To enter one port number, enter the port number in the Start Port and End Port fields. To enter a range of ports, SRTP Support SRTP Support • enter the port number at the beginning of the range in the Start Port field. • enter the port number at the end of the range in the End Port field. When you make a VoIP call using SIP, the Real-time Transport Protocol (RTP) is used to handle voice data transfer. The Secure Real-time Transport Protocol (SRTP) is a security profile of RTP. It is designed to provide encryption and authentication for the RTP data in both unicast and multicast applications. The VMG supports encryption using AES with a 128-bit key. To protect data integrity, SRTP uses a Hash-based Message Authentication Code (HMAC) calculation with Secure Hash Algorithm (SHA)-1 to authenticate data. HMAC SHA-1 produces a 80 or 32-bit authentication tag that is appended to the packet. Crypto Suite Both the caller and callee should use the same algorithms to establish an SRTP session. Select the encryption and authentication algorithm set used by the VMG to set up an SRTP media session with the peer device. Select AES_CM_128_HMAC_SHA1_80 or AES_CM_128_HMAC_SHA1_32 to enable both data encryption and authentication for voice data. Select AES_CM_128_NULL to use 128-bit data encryption but disable data authentication. DTMF Mode Select NULL_CIPHER_HMAC_SHA1_80 to disable encryption but require authentication using the default 80-bit tag. VMG9823-B10A User's Guide 219

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333

Chapter 21 Voice
VMG9823-B10A User’s Guide
219
Don't send re-
Invite to the
remote party
when there are
multiple codecs
answered in the
SDP
Do not send a re-Invite packet to the remote party when the remote party answers that it
can support multiple codecs.
Bound Interface Name
Bound
Interface Name
If you select
Any_WAN
, the VMG automatically activates the VoIP service when any WAN
connection is up.
If you select
MultiWAN
, you also need to select two or more pre-configured WAN
interfaces. The VoIP service is activated only when one of the selected WAN connections is
up.
Outbound Proxy
Outbound
Proxy Address
Enter the IP address or domain name of the SIP outbound proxy server if your VoIP service
provider has a SIP outbound server to handle voice calls. This allows the VMG to work with
any type of NAT router and eliminates the need for STUN or a SIP ALG. Turn off any SIP ALG
on a NAT router in front of the VMG to keep it from re-translating the IP address (since this
is already handled by the outbound proxy server).
Outbound
Proxy Port
Enter the SIP outbound proxy server’s listening port, if your VoIP service provider gave you
one. Otherwise, keep the default value.
Use DHCP
Option 120
First
Select this to enable the SIP server via DHCP option 120.
RTP Port Range
Start Port
End Port
Enter the listening port number(s) for RTP traffic, if your VoIP service provider gave you this
information. Otherwise, keep the default values.
To enter one port number, enter the port number in the
Start Port
and
End Port
fields.
To enter a range of ports,
enter the port number at the beginning of the range in the
Start Port
field.
enter the port number at the end of the range in the
End Port
field.
SRTP Support
SRTP Support
When you make a VoIP call using SIP, the Real-time Transport Protocol (RTP) is used to
handle voice data transfer. The Secure Real-time Transport Protocol (SRTP) is a security
profile of RTP. It is designed to provide encryption and authentication for the RTP data in
both unicast and multicast applications.
The VMG supports encryption using AES with a 128-bit key. To protect data integrity, SRTP
uses a Hash-based Message Authentication Code (HMAC) calculation with Secure Hash
Algorithm (SHA)-1 to authenticate data. HMAC SHA-1 produces a 80 or 32-bit
authentication tag that is appended to the packet.
Both the caller and callee should use the same algorithms to establish an SRTP session.
Crypto Suite
Select the encryption and authentication algorithm set used by the VMG to set up an SRTP
media session with the peer device.
Select
AES_CM_128_HMAC_SHA1_80
or
AES_CM_128_HMAC_SHA1_32
to enable
both data encryption and authentication for voice data.
Select
AES_CM_128_NULL
to use 128-bit data encryption but disable data authentication.
Select
NULL_CIPHER_HMAC_SHA1_80
to disable encryption but require authentication
using the default 80-bit tag.
DTMF Mode
Table 98
VoIP > SIP > SIP Service Provider > Add New Provider/Edit (continued)
LABEL
DESCRIPTION