Secure TLS and SRTP signalling
When the Branch solution is deployed in a centralized, mixed, or distributed environment connected to the Avaya Aura® infrastructure, you can use secure transport methods and media encryption to maintain the confidentiality of media communications. You can select the secure TLS, instead of TCP, as the transport method for SIP phones deployed as Centralized users and for many types of SIP endpoints that are deployed as IP Office users. You can also configure TLS as the SIP connection between Session Manager and IP Office.
When TLS is activated, you can enable Secure Real-time Transport Protocol (SRTP) for media encryption. SRTP is supported by IP Office with many types of endpoints deployed as IP Office users and with all phones that are deployed as Centralized users. SRTP interoperability is also supported between IP Office and other components in the solution on calls through the SM Line.
In cases where there is no SRTP compatibility between one call leg and the other, IP Office does not set up direct media for the call. Instead, IP Office relays the media and converts it as required. An example for such an SRTP call flow is described in Appendix A.
IP Office supports SRTP interoperability with the following products:
-
The following endpoints deployed as IP Office users:
-
9608, 9611, 9621 and 9641 H323 phones (also known as 96x1 H.323 phones)
-
Avaya Communicator for iOS and Avaya Communicator for Windows
-
one-X Mobile Preferred iOS and one-X Mobile Preferred Android
-
Avaya H175 Video Collaboration Station
-
11xx/ 12xx series phones
-
B179 phone
-
Radvision XT series
-
J100 series for J129, J139, J159, J169/J179, J189 phones (Supported only as Standard SIP Phone)
-
Avaya Aura® Session Border Controller
-
The following endpoints deployed as Centralized users, both in Sunny day and in Rainy day:
-
9600 series SIP phones (both 96x1 and 96x0)
-
Avaya H175 Video Collaboration Station
-
Avaya Communicator for Windows
-
Avaya one-X® Communicator
-
11xx/ 12xx series phones
-
B179 phone
-
J100 series for J129, J139, J159, J169/J179, J189 phones (Supported only as Standard SIP Phone)
-
Communication Manager and its endpoints in other sites with signaling through Session Manager that includes the following phones:
-
G450 Branch Gateway used by the central Communication Manager to handle any calls that are not shuffled.
-
Phones, such as, 9600, J100 series phones, and Avaya H175 Video Collaboration Station, which are registered to Communication Manager. IP Office exchanges media directly when Communication Manager sets up direct media or shuffles the call.
-
The following other applications and products are behind Session Manager:
Certificate configuration
Establishment of TLS connections depends on the successful exchange and verification of certificates. Certificates must be set up appropriately on the different products involved. In branch deployments, when
IP Office is managed by
System Manager, each
IP Office must obtain an identity certificate that is generated and signed by
System Manager. Each
IP Office must be added to the
System Manager Certificate Authority and the Simple Certificate Enrollment Protocol (SCEP) must be configured to enable
IP Office to obtain required certificates from
System Manager. For more information, see
Deploying Avaya IP Office™ Platform as an Enterprise Branch with Avaya Aura® Session Manager.
If the phones register using the TLS protocol, in order to register to IP Office in Rainy day, the System Manager CA root certificate must be included in the list of files installed on the file server. This is required because the phones must trust the System Manager CA root certificate so that they can verify the IP Office Identity Certificate that is signed by the System Manager CA.