Cisco 7800 Series Administration Manual page 89

Hide thumbs Also See for 7800 Series:
Table of Contents

Advertisement

Cisco IP Phone Administration
Feature
Secure SRST reference
Media encryption
CAPF (Certificate Authority Proxy Function)
Security profiles
Encrypted configuration files
Optional disabling of the web server functionality for
a phone
Phone hardening
802.1X Authentication
Cisco IP Phone 7800 Series Administration Guide for Cisco Unified Communications Manager
Supported Security Features
Description
After you configure a SRST reference for security
and then reset the dependent devices in Cisco Unified
Communications Manager Administration, the TFTP
server adds the SRST certificate to the phone cnf.xml
file and sends the file to the phone. A secure phone
then uses a TLS connection to interact with the
SRST-enabled router.
Uses SRTP to ensure that the media streams between
supported devices proves secure and that only the
intended device receives and reads the data. Includes
creating a media master key pair for the devices,
delivering the keys to the devices, and securing the
delivery of the keys while the keys are in transport.
Implements parts of the certificate generation
procedure that are too processing-intensive for the
phone, and interacts with the phone for key generation
and certificate installation. The CAPF can be
configured to request certificates from
customer-specified certificate authorities on behalf of
the phone, or it can be configured to generate
certificates locally.
Defines whether the phone is nonsecure or encrypted.
Lets you ensure the privacy of phone configuration
files.
You can prevent access to a phone web page, which
displays a variety of operational statistics for the
phone.
Additional security options, which you control from
Cisco Unified Communications Manager
Administration:
• Disable PC port
• Disable PC Voice VLAN access
• Disable access to web pages for a phone
Note
You can view current settings for the PC
Port Disabled, GARP Enabled, and Voice
VLAN enabled options by looking at the
phone Configuration menu.
The Cisco IP Phone can use 802.1X authentication to
request and gain access to the network.
75

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7821781178617841

Table of Contents