Configuring Security Settings

Last Updated : Feb 07, 2025 |

About this task

The provisioning connection between the IP Office control unit and the master base station uses the HTTP/HTTPS service configured in the IP Office system security settings.
  • Important It is important to note that for new systems and system where the security settings have been defaulted:

  • The IPDECTService service user used for provisioning is disabled by default.

  • The TFTP Directory Read function used by handsets to display the IP Office system directory is off by default.

Procedure

  1. In the IP Office Manager View menu, select Advanced .
  2. Select File | Advanced | Security Settings.
  3. From the discovery menu select the IP Office and click OK.
  4. Enter the systems user name and password for the security service user login. They will be different from the name and password used for IP Office configuration access.
  5. Select Services.




  6. Select the HTTP service. The HTTP service affects all HTTP connections provided by the IP Office system. Changing its setting will affect applications other than just the Avaya Wireless DECT. The only option that can be changed is the Service Security Level. The default is Secure + Unsecure, meaning both http and https can be used between the base station and IP Office.

    Value

    Description

    Unsecure Only

    HTTP port 80 available and used for phone files, embedded file manager, system file upgrade, one-X Portal directory services, Avaya Wireless DECT provisioning.

    Secure + Unsecure

    This mode (the default) allows both unsecure HTTP (see above) and secure HTTPS (see below) connections.

    Secure, Low

    HTTPS port 443 available and used for Avaya Wireless DECT provisioning, IP Office Video Softphone provisioning. This option allows secure access to that service using TLS, and demands weak (for example DES_40 + MD5)  encryption and authentication or higher.  The service's unsecured TCP port is disabled.

    Secure, Medium

    This option allows secure access to that service using TLS, and demands moderate (for example DES_56 + SHA-1) encryption and authentication or higher.  The service's unsecured TCP port is disabled.

    Secure, High

    This option allows secure access to that service using TLS and demands strong (for example 3DES + SHA-1) encryption and authentication, or higher.  In addition, a certificate is required from the client (usuallyIP Office Manager).

  7. Select Rights Groups. The list of groups should contain one called IPDECT Group. Select that group. If the group is not present in the list, click on the new entry icon to create the group.
  8. Select the HTTP tab. Check that the option DECT R4 Provisioning and Directory Read are selected. Check that no other options are selected on any other tab.




  9. Select Service Users.
    1. Select the Service User IPDectService.




    2. In the Rights Group Membership list check that the user is set as a member of the IPDECT Group.
    3. Leave the Account Status as Enabled and the Account Expiry as <None>.
    4. Click on the icon to save any changes you have made to the security settings.
      Note:

      Avaya recommends changing the default password.