RedMax EXtreme EX-LRT Guía para resolver problemas Pagina 109

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 142
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 108
Oracle SBC Security Guide
If SRTP is enabled for the inbound realm/interface, the SBC will handle the request according to the
capabilities defined in the SRTP configuration. If there is a crypto attribute in the offer, the SBC will
attempt to parse the crypto attributes and parameters in the SDP. It accepts exactly one of the offered
crypto attributes for a given media stream, if this is configured as a valid crypto-suite on the SD. If there
is no crypto-suite configured on the SBC in the list of crypto-suites received, the SBC will reject the call
with a “488 Not Acceptable Here” response.
Before the request is forwarded to the callee, the SBC allocates resources, updates the SDP with proper
media addresses and ports, and the original crypto attribute is removed from the SDP.
Once the reply from the callee is received, SBC inserts the appropriate crypto attribute to form a new
SDP, and forwards the response back to the caller. At this point, SRTP traffic is allowed between the
caller and the SD.
Back-to-back SRTP Termination
SRTP enabled on inbound interface, enabled on outbound interface. Separate crypto keys on
either side.
Similarly to the “Single End SRTP Termination” case above, before the request is forwarded to the callee,
the SBC allocates resources and updates the SDP with proper media addresses and ports, however, at this
point, the original crypto attribute is replaced with one generated by the SD.
The construction of the crypto attribute in the SDP will be based on the configuration for the outbound
realm/interface. Once the reply from the callee is received, the SBC could also accept or reject the
“answer” from the callee according to the configuration and the list of crypto-suites supported. If
accepted, the SBC will replace the original crypto attribute from the callee with its own to form a new
SDP. The new SDP is forwarded back to the caller. At this point, SRTP media sessions are established on
both sides.
Pass-through SRTP
Crypto attribute is not intercepted, just forwarded, and the key negotiation is done end-to-end.
Vista de pagina 108
1 2 ... 104 105 106 107 108 109 110 111 112 113 114 ... 141 142

Comentarios a estos manuales

Sin comentarios