Avaya Administering Aura Session Manager Release 6.1 Manual de usuario Pagina 277

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 532
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 276
Authentication of trusted SIP entities
Routing uses the following information for the authentication of SIP entities by performing
validation on IP/Transport Layer and TLS Layer:
• FQDN or IP Address of the SIP entity
• Credential name of the SIP entity
• Protocol of the Entity Links. This is a SIP connection transport type (TCP/TLS/UDP)
• Trust State of the Entity Link (This defines whether the entity link is Trusted or not)
For information about administering these fields, refer to Creating SIP entities.
IP and transport layer validation
When a SIP entity connects to Session Manager over a TCP or TLS port, Session Manager
validates that:
• The IP address matches one of the SIP entities configured in routing that have trusted
entity links with the Session Manager. If the SIP entities are configured as FQDN, Session
Manager performs a DNS resolution before doing the verification.
Transport for the incoming SIP connection matches with one of the entity links associated
with this SIP entity and the Session Manager. Also, the Trust State of the entity link must
be configured as trusted. Session Manager does not accept connections matching
untrusted entity links.
For SIP packets over UDP, above validation is performed for each packet. For SIP TLS
connections, further validation is performed as described in the next section.
TLS layer validation
Session Manager applies the following additional validations for SIP TLS connections:
1. During a TLS handshake, mutual TLS authentication is performed, that is, Identity
certificate of the SIP entity is validated against the trusted CA certificate repository
in the Session Manager for SIP TLS. If this verification fails, Session Manager does
not accept the connection.
2. If the mutual TLS authentication is successful, further validation is performed on the
SIP entity Identity Certificate as per the Credential Name or the far-end IP
address.
• If the Credential Name string is empty, the connection is accepted.
SIP Entities
Administering Avaya Aura
®
Session Manager November 2010 277
Vista de pagina 276
1 2 ... 272 273 274 275 276 277 278 279 280 281 282 ... 531 532

Comentarios a estos manuales

Sin comentarios