RedMax EXtreme EX-LRT Průvodce řešením problémů Strana 119

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 142
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 118
Oracle SBC Security Guide
name SRTP1
pass-through disabled
inbound
profile sdes1
mode any
protocol SDES
outbound
profile sdes1
mode any
protocol SDES
(media-sec-policy)#
And this media-sec-policy should be applied under the realm where RTP+SRTP are desired:
realm-config
identifier access1
description
addr-prefix 0.0.0.0
network-interfaces
M00:0
media-sec-policy SRTP1
Finally, we need to configure the security-policy for SRTP. Since in this case both RTP and SRTP can be
present under the same realm, the recommendation is to use different IPs for RTP and for SRTP.
The SRTP IP must be in the same subnet (network-interface) as the IP used for RTP. For its definition,
the IP used for RTP will continue being defined under the steering-pool, while the IP for SRTP needs to
be defined under the security-policy. When RTP needs to be used, the SBC will use the IP configured in
the steering-pool, whereas when SRTP needs to be inserted into the SDP, the SBC will choose the IP
from the security-policy AND an available port from the steering-pool configured for RTP, so the
dimensioning of the port range of the steering-pool should consider both RTP and SRTP estimated traffic.
If SIP traffic runs over the same subnet (network-interface), it is recommended not to use the IP used for
SRTP traffic. That way, it is not necessary to configure a second security-policy for SIP traffic.
In the example below, 11.0.0.10 is used for RTP and 11.0.0.11 is used for SRTP. In the case that SIP
traffic is desired under the same network, it would be recommended not to use 11.0.0.11, as this is
reserved for SRTP use and the security-policy configured for it would apply.
steering-pool
ip-address 11.0.0.10
start-port 20000
end-port 49999
realm-id access
security-policy
name media
network-interface M00:0
priority 1
local-ip-addr-match 11.0.0.11
remote-ip-addr-match 0.0.0.0
local-port-match 0
remote-port-match 0
Zobrazit stránku 118
1 2 ... 114 115 116 117 118 119 120 121 122 123 124 ... 141 142

Komentáře k této Příručce

Žádné komentáře