Services

Last Updated : Aug 18, 2021 |

Navigation: Security > Security Settings > System Services

This tab shows details of the services that the system runs to which service users can communicate.

Field

Description

Name

The name of the service. This is a fixed value for information only.

Host System

The IP Office system name.

Service Port

This is the port on which the IP Office system listens for attempts to access the service. The routing of traffic to this port must be enabled on firewalls and network devices between the service users and the IP Office system.

The base port (TCP or HTTP) for each service is offset by a fixed amount from the ports set in System Settings. For information on port usage, see the IP Office Port Matrix document on the Avaya support site.

Service Security Level

Sets the minimum security level the service supports.

  • If the IP Office system does not already have an X509 security certificate, selecting a setting other than Unsecure Only will cause the IP Office system to stop responding for up to a minute whilst it generates a self-signed security certificate.

The options are:

  • Unsecure Only - This option allows only unsecured access to the service. The service's secure TCP port, if any, is disabled. This or disabled are the only options supported for the System Status Interface and Enhanced TSPI services.

  • Unsecure + Secure This option allows both unsecured and secure (Low) access. In addition, TLS connections are accepted without encryption, just authentication.

  • Secure Low - This option allows secure access to the service using TLS and weak (for example DES_40+MD5) encryption and authentication or higher.

  • Secure Medium - This option allows secure access to the service using TLS and moderate (for example SHA-256) encryption and authentication or higher.

  • Secure High - This option allows secure access to the service using TLS and strong encryption (for example SHA-256) and authentication, or higher.

    • Only supported by Linux-based IP Office systems.

    • A certificate is required from the client. For IP Office Manager, the Certificates > Received certificate checks (Management interfaces) setting sets the certificate checks it uses.

  • Disabled - This option is only available for the System Status Interface and Enhanced TSPI services. If selected, access to the service is disabled.

For details of the ciphers supported by Secure Medium and Secure High, see the Avaya IP Office™ Platform Security Guidelines manual.

Service Access Source

Used for the Configuration service. Sets the supported modes for IP Office Manager access to the IP Officesystem:

  • Server Edition Manager - If selected, the IP Office system can only be configured using IP Office Manager in its Server Edition mode. This is the default for Server Edition systems.

    • Opening the configuration of a Server Edition system in IP Office Manager running in any mode other than Server Edition mode should be avoided unless absolutely necessary for system recovery. Even in that case, IP Office Manager will not allow renumbering, changes to the voicemail type, and changes to H.323 lines.

  • Avaya Aura System Manager - If selected, the IP Office system can only be configured using SMGR in Branch Mode. This is the default for centrally managed systems.

  • Unrestricted - The IP Office system can be configured using IP Office Manager in its normal simplified and advanced view modes.

Default Settings

Name

Service Port

Service Security Level

Service Access Source

Configuration

50805

Secure Medium

Unrestricted

Security Admin

50813

Secure Medium

System Status Interface

50809

Secure Medium

Enhanced TSPI Access

50814

Secure Medium

HTTP

80, 443

Secure Medium

Web Services

8443

Secure Medium

External

50821

Disabled