RedMax EXtreme EX-LRT Anleitung zur Fehlerbehebung Seite 116

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 142
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 115
Oracle SBC Security Guide
Where “sdes1” is the configured sdes-profile used for this implementation. In the same way, mikey-
profile could be used if the desired implementation uses MIKEY instead. Here are the default sdes-profile
and mikey-profile suggested, to be superseded only by specific customer requirements.
# show running-config sdes-profile
sdes-profile
name sdes1
crypto-list AES_CM_128_HMAC_SHA1_80
AES_CM_128_HMAC_SHA1_32
srtp-auth enabled
srtp-encrypt enabled
srtcp-encrypt enabled
egress-offer-format same-as-ingress
use-ingress-session-params srtcp-encrypt
srtp-auth
srtp-encrypt
mki disabled
key
salt
(mikey-profile)# show
mikey-profile
name mikey1
key-exchange-method pre-shared
encr-algorithm AES-CM
auth-algorithm HMAC-SHA1-80 HMAC-SHA1-32
shared-secret
mki disabled
egress-offer-format same-as-ingress
use-ingress-session-params
(mikey-profile)#
The media-sec-profile configured for SRTP should be applied under the desired realm.
realm-config
identifier access1
description
addr-prefix 0.0.0.0
network-interfaces
M00:0
media-sec-policy SRTP1
Finally, a security-policy should be applied to perform the RTP/SRTP or SRTP/SRTP conversion at the
flow level. One security-policy is needed for the media traffic.
The local-port-match is set to 0 for an SRTP security-policy, meaning all ports on the IP address
configured in local-ip-match are subject to this security-policy. Hence, to avoid a clash with the SIP
signaling port (typically 5060) when signaling and media are managed on the same IP address, a second
security-policy with a higher priority is required to exempt the SIP signaling port from the media security-
policy.
Seitenansicht 115
1 2 ... 111 112 113 114 115 116 117 118 119 120 121 ... 141 142

Kommentare zu diesen Handbüchern

Keine Kommentare