Checks and Tests

Last Updated : Apr 17, 2024 |
Prolog information
Thorough checks and tests should be carried out to ensure the deployment is secure and no previous attacks have compromised the system:
  • Care must be taken not to inadvertently expose sensitive data as a by-product of testing activities.
  • Check LAN1/LAN2 do not have public IP addresses, that is, directly accessible from the internet.
  • Check the IP Office for unsecure internet or inbound IP access by identifying the public IP address of the Firewall (for example, by using http://whatismyipaddress.com), then attempting access to the IP Office ports defined by the Port Matrix document. The following table contains some example ports that should be tested.
Note: This port list is not exhaustive and can vary from release to release. A link to the port matrix document is located athttps://ipofficekb.avaya.com/businesspartner/ipoffice/mergedProjects/general/port_matrix/index.htm.
Port
Protocol
Use
Possible Test Tool/Notes
22
TCP
SSH
SSH, port scanner. Linux servers only
69
UDP
TFTP
Port scanner. A TFTP RRQ of 'nasystem/who_is' can be used
80
TCP
HTTP
Browser, port scanner. http://[ IP Address] can be used
143
TCP
IMAP
Port scanner. Voicemail Pro only
161
UDP
SNMP
SNMP test tool, port scanner
411
TCP
HTTP
Port scanner
443
TCP
HTTPS
Browser, port scanner. https://[ IP Address] can be used
993
TCP
IMAP-TLS
Port scanner. Voicemail Pro only
1300
TCP
H323-TLS
Port scanner
1720
TCP
H323
Port scanner.
5060
UDP
SIP
Port scanner.
5061
TCP
SIP
Port scanner.
5443
TCP
HTTPS
Port scanner. Linux servers only
7070
TCP
HTTPS
Browser, port scanner. Linux servers only. https://[IP Address]:7070 can be used
7071
TCP
HTTPS
Browser, port scanner. Linux servers only. https://[IP Address]:7071 can be used
8000
TCP
HTTP
Port scanner. Linux servers only
8069
TCP
HTTP
Port scanner. Avaya one-X® Portal for IP Office only
8080
TCP
HTTP
Browser, port scanner. https://[IP Address]:8080/onexportal-admin.html can be used
8086
TCP
HTTP
Port scanner. Avaya one-X® Portal for IP Office only
8411
TCP
HTTPS
Port scanner.
8443
TCP
HTTPS
Port scanner.
9443
TCP
HTTPS
Port scanner. Avaya one-X® Portal for IP Office only
50791
TCP
Voicemail Pro Client, port scanner
50792
UDP
Port scanner.
50793
TCP
Port scanner. IP500 V2 only
50794
UDP + TCP
SysMonitor
SysMonitor, port scanner.
50796
TCP
TLS
Port scanner.
50804
TCP
IP Office Manager, port scanner.
50805
TCP
TLS
IP Office Manager, port scanner.
50808
TCP
SSA, port scanner.
50809
TCP
TLS
SSA, port scanner.
50812
TCP
IP Office Manager, port scanner.
50813
TCP
TLS
IP Office Manager, port scanner.
50814
TCP
Port scanner
If access is successful, it can indicate a misconfigured Firewall or other network protection system.
  • Attempt to log into the servers using the set of default administrator accounts and passwords in the following table.
    • Note: Default accounts from previous releases are not removed on upgrade.
Default Account Name
Domain
Possible Test Tool
Notes
security
Administrator
Manager
Operator
BusinessPartner
Maintainer
IPDECTService
SMGRB5800Admin
BranchAdmin
IP Office
IP Office Web Manager
IP Office Manager
All servers, includingIP500 V2.
Administrator
Voicemail Pro
Voicemail Pro client
Voicemail Pro only.
Administrator
Avaya one-X® Portal for IP Office
Browser
Avaya one-X® Portal for IP Office only.
Administrator
Web Control
Browser
Linux servers only.
root
Linux
Console interface
Linux servers only.
If access is successful, the account credentials should be changed or the account removed. See Remove Unnecessary Accounts for more information on account removal
  • Use IP Office Manager to load the configuration and review all errors and warnings with particular reference to passwords. None should be present.
  • Check for unexpected Extensions and Users
  • Check all users' settings for unusual forwarding destinations
  • Ensure all SIP extensions' ExtensionExtnForce Authorization setting has not been disabled.
  • Check the special IP Office user 'NoUser' Source Numbers field; any unexpected entries should be clarified with support personnel. NoUser source numbers are sometimes used to enable specific features or behavior.
  • Check that the padlock symbol is displayed on the bottom right of the screen, indicating a secure connection to IP Office.
  • Use IP Office Manager to load the security settings and review all warnings; none should be present.
  • Again, check that the padlock symbol is displayed on the bottom right of the screen, indicating a secure connection to IP Office.
  • Log on to Avaya one-X® Portal for IP Office administration page, if a warning is displayed 'Change Administrator Default Password' the administrator account is at default.
  • If login to Web Control, Avaya one-X® Portal for IP Office or Voicemail Pro fails unexpectedly, check the IP Office security settings for the account being used; it must have a rights group assigned which contains the correct 'External' rights.
  • Check successful and failed logins produce the expected reports and results.
  • Test the call barring, emergency calls, authorization codes, Voicemail Pro outcalling and call flows. Testing of Emergency Calls must be arranged in advance with the PCSP/Emergency Services to avoid prejudicing genuine emergency response.
  • Review Firewall, SBC and call logger reporting.