The following configurable SRTP options are supported by IP Office:
SRTP feature |
Options |
Support |
Default |
Notes |
SRTP Operation |
Disabled |
✓ |
✓ |
All SRTP settings are per system with a per line and per extension override |
On: Best Effort |
✓ |
– |
On: Enforce |
✓ |
– |
RTP Encryption |
Off |
✓ |
– |
|
On: AES128-CTR |
✓ |
✓ |
|
On: AES128-F8 |
– |
– |
|
RTP Authentication |
Off |
✓ |
– |
RTP Authentication should not be disabled |
On: SHA-1/32 |
✓ |
– |
|
On: SHA-1/80 |
✓ |
✓ |
SHA-1/80 provides stronger authentication for a small bandwidth increase |
RTCP Encryption |
Off |
✓ |
✓ |
|
On: AES128-CTR |
✓ |
– |
Some Avaya and 3rd party endpoints do not support encrypted RTCP |
On: AES128-F8 |
– |
– |
|
RTCP Authentication |
On: SHA-1/32 |
✓ |
– |
RTCP Authentication always active |
On: SHA-1/80 |
✓ |
✓ |
SHA-1/80 provides stronger authentication for a small bandwidth increase. |
IP Office supports a per-system SRTP set of controls, with a per-line and extension overrides, including encryption and authentication settings. The SRTP operation control has the following values:
Option |
Description |
Disabled |
SRTP is not available |
Preferred |
Always offer both SRTP and RTP and given a choice, choose SRTP. |
Enforced |
RTP is not available on that call leg. Note: This doesn't enforce end-to-end SRTP, only SRTP on the call leg configured as Enforce. |