First step in troubleshooting is to check whether the system and all participating devices are correctly configured. Some endpoints need to be registered using TLS to have SRTP available.
-
Ensure that the system is using the default settings for advanced options. If that is not the case, check that it is intentional.
-
If SIP devices are used and Best Effort is configured, check with System Status Application/SysMonitor how SRTP is negotiated and whether the device supports cap neg (can be checked by placing a call to device with both SRTP and RTP and then checking whether it responds with SRTP or RTP – if it is SRTP, cap neg is supported). If not, override device media security settings and configure Enforce or Disabled, as appropriate.
-
IP Office lines with Best Effort configured and both crypto suites are enabled can result in large call initiation messages on IP Office lines, ~ 5000 bytes. If the link is slow and/or the call rate is high it can have a negative impact. Consider using only one crypto suite or the lines' setting to Enforce or Disabled.
-
Some phones do not support RTCP (SRTCP); verify operation with SRTCP disabled.