Users and extensions should be configured to restrict access to necessary features, default login codes changed and auto-create disabled.
All unused users should be deleted – except NoUser.
The following auto-create settings must be disabled when not required:
ADDITIONAL INFORMATION:
LAN1/LAN2VoIPH323 GatekeeperAuto-create Extn
LAN1/LAN2VoIPH323 GatekeeperAuto-create User
LAN1/LAN2VoIPSIP RegistrarAuto-create Extn/User
LineIP DECTGatewayAuto-Create Extension
LineIP DECTGatewayAuto-Create User
If any auto-create feature is used to assist installation, the settings must be deactivated as soon as possible. Note that these settings are automatically deactivated 24 hours after being set to avoid inadvertent exposure.
If no H.323 extensions are supported, the SystemLAN1/2VoIPH.323 Gatekeeper Enabled must be disabled. If H.323 extensions are supported, only the relevant LAN's gatekeeper should be enabled.
If no H.323 remote workers are supported, the SystemLAN1/2VoIPH.323 GatekeeperH.323 Remote Extn Enabled must be set disabled. If H.323 remote workers are supported, only the relevant LAN's Remote Extn should be enabled.
If no SIP extensions are supported, the SystemLAN1/2VoIPSIP Registrar Enabled must be set disabled. If SIP extensions are supported, only the relevant LAN's registrar should be enabled.
If no SIP remote workers are supported, the SystemLAN1/2VoIPSIP RegistrarSIP Remote Extn Enabled must be set disabled. If SIP remote workers are supported, only the relevant LAN's SIP Remote Extn should be enabled.
Enforce a Login Code (PIN) policy for all users and extensions by setting SystemTelephonyLogin Code ComplexityMinimum Length to the minimum acceptable length, and activating Complexity Test. For more information, see Password and PIN Management.
All VoIP (SIP, H323, DECT) users' UserTelephonySupervisor SettingsLogin Code or ExtensionExtnPhone Password must be set.
If any SIP registrar or H323 gatekeeper is exposed directly or indirectly to an unsecure network, follow the steps for Hardening for Remote Workers.
All SIP extensions' ExtensionExtnForce Authorization setting must be enabled.
All auto-created VoIP users must have their UserTelephonySupervisor SettingsLogin Code changed from the default. All auto-created non-VoIP (Digital, Analog) users should have their name and extension changed from the default.
Each user should have only the necessary UserUserProfile features enabled, all others disabled.
Each user should have only the minimum necessary UserUser Portal interface features enabled, all others disabled:
If different from the system-wide setting, change the ExtnVoIPMedia Security setting. See VoIP Security.
If the VoIP extension is to be configured for secure media (SRTP) or operates in an unsecure environment, any settings file supplied by IP Office should be conveyed via HTTPS not HTTP. To force settings file provision to be HTTPS, change the security settings ServicesHTTP setting, see Ensure Minimum Rights of Access. This will require certificate administration, see Certificates and Trust.