Page History
...
Click the Create TLS Profile ( ) icon at the top of the TLS Profile page.
Create TLS - SBC SWe Edge and SBC 1000/2000
Create TLS Profile - SBC CNe Edge
Anchor | ||||
---|---|---|---|---|
|
TLS Profile - Field Definitions
TLS Protocol
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
Specifies the TLS Protocol. Valid entries: TLS 1.0 Only, TLS 1.2 Only, or TLS 1.0 - 1.2. Once the TLS is option is selected, the Client Cipher List is automatically updated to display only the ciphers supported for the selected TLS version.
Note | ||||||||
---|---|---|---|---|---|---|---|---|
The TLS version you choose for the SBC TLS Profile must match the TLS version configured in the SBA security for the associated SIP Server.
|
Pagebreak
Mutual Authentication
...
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
Enables the Mutual authentication request and verifications of the SIP peer client certificate.
Note |
---|
This setting is part of the standard level of Mutual TLS security. Mutual Authentication includes a check on the certificate dates for certificate validity and whether the certificate is signed by a local trusted root CA. |
Handshake Inactivity Timeout
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
Specifies the SIP TLS client and server handshake inactivity timeout interval.
The Inactivity Timeout terminates the TLS session if there have been no handshakes in the specified period of time.
The handshake inactivity timeout should be adjusted to 30 seconds if there are network delays and/or timeouts.
Client Cipher List
...
...
Specifies the cipher suite parameter exchanged and negotiated in the SIP TLS client handshake message. The list is automatically populated with the ciphers supported for the selected TLS Protocol
...
For
and SBC 1000/2000: Spacevars 0 series3
...
.
...
The
Spacevars | ||
---|---|---|
|
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
- TLS_RSA_WITH_3DES_EDE_CBC_SHA
- TLS_RSA_WITH_AES_256_CBC_SHA256
- TLS_RSA_WITH_AES_128_CBC_SHA256
- TLS_RSA_WITH_AES256_CBC_SHA
- TLS_RSA_WITH_AES128_CBC_SHA
- TLS_RSA_WITH_DES_CBC_SHA
Note | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
The TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA is incompatible with Lync servers. For The
|
Info | ||||
---|---|---|---|---|
The cipher list must be provided while configuring SBC using REST. The SBC will try to use the existing cipher list configured when setting the TLS Protocol; if this matches the TLS Protocol being configured it will be successful. If it does not match or the Client Cipher List is empty then the REST command will be rejectedOnly 3 ciphers are allowed per profile in the
|
Verify Peer Server Certificate
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
...
Specifies whether or not to verify the identity of a peer server. Available when Mutual Authentication is disabled.
Note |
---|
This setting is part of the standard level of Mutual TLS security. Verify Peer Server Certificate implies that Mutual Authentication is enabled first. Verify Peer Server Certificate includes a check on the certificate dates for certificate validity and whether the certificate is signed by a local trusted root CA. |
Validate Server FQDN
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
...
...
The Validate Server FQDN is an enhanced security feature of the
Spacevars | ||
---|---|---|
|
Validate Server FQDN (enabled) option allows the
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
Note | ||||
---|---|---|---|---|
|
Certificate (Client Attributes)
...
Specifies the certificate (primary or supplementary) that is in use and that the
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
Validate Client FQDN
...
bgColor | #FAFAFA |
---|---|
borderStyle | none |
...
...
Specifies the reverse DNS lookup of a peer's FQDN. Used to verify the identity of the SIP peer client certificate.
This action takes place when both, Mutual Authentication and Validate Client FQDN are enabled. If Mutual Authentication is disabled, the Validate Client FQDN is also disabled. Validate Client FQDN is an enhanced security feature of
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
Note | ||||
---|---|---|---|---|
|
Certificate (Server Attributes)
...
Specifies the certificate (primary or supplementary) that is in use and that the
Spacevars | ||
---|---|---|
|