RedMax EXtreme EX-LRT Guía para resolver problemas Pagina 122

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 142
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 121
Oracle SBC Security Guide
Secured-network parameter is set to ENABLED under the access sip-interface and ENABLED on the
core sip-interface. Only one security-policy is configured for SRTP under 172.181.72. Two media-sec-
policies are created, one in the access network with mode=any and one in the core with mode=RTP. As in
the access network both RTP and SRTP endpoints could be present, the egress-offer-format is set to
simultaneous-best-effort.
Back-to-back SRTP Termination
Normally deployed in peering scenarios where SRTP is needed in both networks that the SBC is
interconnecting. In that case, the Session Border Controller is doing SRTP termination so the SRTP key
exchange is different in the two connected networks.
In the SBC, 172.18.1.71 will be used for SIP (TLS) and SRTP in the peer1A network, while 172.18.2.71
will be used in the 172.18.2.71.
The peer element sending traffic in the peer1A network will be in 172.18.1.200, while the peer element in
the peer1B will be 172.18.2.100.
Secured-network is set to DISABLED under both sip-interfaces. Two security-policies are configured per
peer1 realm, one for SRTP and one that creates the exception for SIP signaling, so four security-policies
are configured in total. Also, two media-sec-policies are created, one in the peer1A network with
mode=SRTP and one in the peer1B with mode=SRTP, where each one is linked with a different SDES
profile, to allow different cryptos between networks. Note that this is not required, and the same SDES
profile could be used for both networks, the key exchange would keep different as the SBC would
terminate the SRTP anyway, so configuring different SDES profiles would be only needed in the case
where the crypto-suites supported in each network are different or have different characteristics.
Troubleshooting
A network capture taken on both access and core network should show RTP packets with the same
sequence number, however, if SRTP termination is done in the SBC, the payload contained in RTP
packets with the same sequence number will be different because of the encryption/unencryption done by
the SD.
Vista de pagina 121
1 2 ... 117 118 119 120 121 122 123 124 125 126 127 ... 141 142

Comentarios a estos manuales

Sin comentarios