Disable Unused Services/Interfaces

Last Updated : Apr 27, 2022 |

All interfaces and services not required must be disabled. Additionally, consider enabling interfaces and services only when required.

  1. In IP Office Manager security settings System > Unsecured Interfaces tab: Uncheck all Application controls and enable only the minimum according to the following table:

Application Control

Affected Application(s)

Notes

TFTP Server

IP Office Manager Upgrade

Phone Manager

DECT R4*

LegacyVoicemail Pro

UDP whois**

Network Viewer

Disables all TFTP access, including TFTP Directory Read, TFTP Voicemail and Program Code.

* When inactive, DECT will continue operating but without the system directory feature.

** TCP whois discovery should be used in IP Office Manager.

TFTP Directory Read

Phone Manager

DECT R4*

TAPI Install**

Also used for legacy applications: IP DECT*, Analog DECT.

* When inactive, DECT will continue operating but without the system directory feature

** TAPI installation will generate a warning, but it can be ignored

Also controlled by the general TFTP Server setting above.

TFTP Voicemail

Legacy Voicemail Pro

Enable only when Voicemail Pro R9.0 and prior used

Not applicable to embedded voicemail

Also controlled by the general TFTP Server setting above.

Program Code

IP Office Manager Upgrade

Used for upgrades from IP Office Manager, must be disabled when not required

Also controlled by the general TFTP Server setting above.

DevLink

DevLink

System Monitor*

Must be disabled when not required

* When inactive, SysMonitor can still use the HTTP/S access method.

TAPI

TAPI Link Lite (1st party TAPI)

TAPI Link Pro (3rd party TAPI)

Avaya Contact Center Select

Enable only when TAPI required; note that TAPI driver installation will fail if the TAPI interface is not active.

This setting will affect the ACCS CTI Link; when inactive, any ACCS sessions will require TLS and a trusted certificate from ACCS.

This setting will not affect the Avaya one-X® Portal for IP Office CTI Link.

HTTP Directory Read

IP Office Centralized Directory

J129*

Enable only when J129 or IP Office Centralized Directory used. Access only via HTTPS. HTTP port 80 must be disable.

* When inactive, any J129s operate but without the directory feature

HTTP Directory Write

J129*

Enable only when J129. Access only via HTTPS. HTTP port 80 must be disabled.

* When inactive, any J129s operate but without the directory feature