Hardening for Remote Workers

Last Updated : Jan 21, 2025 |
Prolog information
Whenever SIP or H323 remote worker operation is supported, or if any SIP registrar or H323 gatekeeper is exposed directly or indirectly to an unsecure network even via an SBC, extra considerations are required to ensure that the external access does not compromise IP Office security.
Important:
  • You must never connect an IP Office directly to the external Internet. IP Office must only be connected externally via a properly configured firewall.
  1. The RTP port range on the LAN interface must be set to no more than 50750. If more RTP ports are required, the minimum value may be changed.
    ADDITIONAL INFORMATION:
    • LAN1/2VoIPPort Number RangeMaximum
    • LAN1/2VoIPPort Number Range (NAT)Maximum
  2. Any exposed SIP Registrar or H323 Gatekeeper should have the TLS option enforced and any unsecure options disabled. See VoIP Security. To reduce the overhead of security and certificate management, one LAN's registrar can be used for the external interface, the other LAN for internal extensions.
  3. The SIP registrar ports should be changed from the default 5060/5061.
  4. Any settings file supplied by IP Office must be conveyed via HTTPS not HTTP. This will additionally require certificate administration; see Certificates and Trust.
  5. SRTP for media security should be considered, see VoIP Security.
  6. If any H323 Gatekeeper or SIP registrar is exposed directly or indirectly to an unsecure network, all remote worker's ExtensionExtnPhone Password must be set. The code must not be a sequence, repeated digits, or same as the extension number. It must not be less than 9 digits, preferably 13 digits.
  7. Each H323 or SIP remote worker extension's ExtensionVoIPIP Address should be set to the public IP Address of the phone.
    ADDITIONAL INFORMATION:
    • Note: This cannot be used if more than one phone is behind the same firewall/NAT, or the remote IP address changes.
  8. Follow the steps for Securing Telephony Users & Extensions.
  9. Follow the steps for Preventing Unwanted Calls.
  10. A Session Border Controller (SBC) must be considered for enhanced SIP remote worker security.
    ADDITIONAL INFORMATION:
    • The Avaya SBC for Enterprise (ASBCE) is a solution specifically tailored for IP Office SIP remote workers and SIP trunks. See the Deploying Remote IP Office SIP Phones with an ASBCE manual.
    • If an SBC or SIP Application Level Gateway (ALG) is deployed, you must move some security measures from the IP Office to the SBC/ALG. The IP Office source IP address blacklisting should be disabled with the No User Source Number 'B_DISABLE_SIP_IPADDR'. The SBC/ALG black/white listing must be activated to compensate.