All interfaces and services not required must be disabled. Additionally, consider enabling interfaces and services only when required.
In IP Office Manager security settings tab: Uncheck all Application controls and enable only the minimum according to the following table:
Application Control |
Affected Application(s) |
Notes |
TFTP Server |
IP Office Manager Upgrade Phone Manager DECT R4* LegacyVoicemail Pro UDP whois** Network Viewer |
Disables all TFTP access, including TFTP Directory Read, TFTP Voicemail and Program Code. * When inactive, DECT will continue operating but without the system directory feature. ** TCP whois discovery should be used in IP Office Manager. |
TFTP Directory Read |
Phone Manager DECT R4* TAPI Install** |
Also used for legacy applications: IP DECT*, Analog DECT. * When inactive, DECT will continue operating but without the system directory feature ** TAPI installation will generate a warning, but it can be ignored Also controlled by the general TFTP Server setting above. |
TFTP Voicemail |
Legacy Voicemail Pro |
Enable only when Voicemail Pro R9.0 and prior used Not applicable to embedded voicemail Also controlled by the general TFTP Server setting above. |
Program Code |
IP Office Manager Upgrade |
Used for upgrades from IP Office Manager, must be disabled when not required Also controlled by the general TFTP Server setting above. |
DevLink |
DevLink System Monitor* |
Must be disabled when not required * When inactive, SysMonitor can still use the HTTP/S access method. |
TAPI |
TAPI Link Lite (1st party TAPI) TAPI Link Pro (3rd party TAPI) Avaya Contact Center Select |
Enable only when TAPI required; note that TAPI driver installation will fail if the TAPI interface is not active. This setting will affect the ACCS CTI Link; when inactive, any ACCS sessions will require TLS and a trusted certificate from ACCS. This setting will not affect the Avaya one-X® Portal for IP Office CTI Link. |
HTTP Directory Read |
IP Office Centralized Directory J129* |
Enable only when J129 or IP Office Centralized Directory used. Access only via HTTPS. HTTP port 80 must be disable. * When inactive, any J129s operate but without the directory feature |
HTTP Directory Write |
J129* |
Enable only when J129. Access only via HTTPS. HTTP port 80 must be disabled. * When inactive, any J129s operate but without the directory feature |