All interfaces and services not required must be disabled. Additionally, consider enabling interfaces and services only when required.
-
In IP Office Manager security settings tab: Uncheck all Application controls and enable only the minimum according to the following table:
|
Application Control
|
Affected Application(s)
|
Notes
|
|
TFTP Server
|
IP Office Manager Upgrade
Phone Manager
DECT R4*
LegacyVoicemail Pro
UDP whois**
Network Viewer
|
Disables all TFTP access, including TFTP Directory Read, TFTP Voicemail and Program Code.
* When inactive, DECT will continue operating but without the system directory feature.
** TCP whois discovery should be used in IP Office Manager.
|
|
TFTP Directory Read
|
Phone Manager
DECT R4*
TAPI Install**
|
Also used for legacy applications: IP DECT*, Analog DECT.
* When inactive, DECT will continue operating but without the system directory feature
** TAPI installation will generate a warning, but it can be ignored
Also controlled by the general TFTP Server setting above.
|
|
TFTP Voicemail
|
Legacy Voicemail Pro
|
Enable only when Voicemail Pro R9.0 and prior used
Not applicable to embedded voicemail
Also controlled by the general TFTP Server setting above.
|
|
Program Code
|
IP Office Manager Upgrade
|
Used for upgrades from IP Office Manager, must be disabled when not required
Also controlled by the general TFTP Server setting above.
|
|
DevLink
|
DevLink
System Monitor*
|
Must be disabled when not required
* When inactive, SysMonitor can still use the HTTP/S access method.
|
|
TAPI
|
TAPI Link Lite (1st party TAPI)
TAPI Link Pro (3rd party TAPI)
Avaya Contact Center Select
|
Enable only when TAPI required; note that TAPI driver installation will fail if the TAPI interface is not active.
This setting will affect the ACCS CTI Link; when inactive, any ACCS sessions will require TLS and a trusted certificate from ACCS.
This setting will not affect the Avaya one-X® Portal for IP Office CTI Link.
|
|
HTTP Directory Read
|
IP Office Centralized Directory
J129*
|
Enable only when J129 or IP Office Centralized Directory used. Access only via HTTPS. HTTP port 80 must be disable.
* When inactive, any J129s operate but without the directory feature
|
|
HTTP Directory Write
|
J129*
|
Enable only when J129. Access only via HTTPS. HTTP port 80 must be disabled.
* When inactive, any J129s operate but without the directory feature
|