Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Panel

In this section:

Table of Contents
maxLevel2



Info
iconfalse

Related articles:

Children Display



Excerpt

This profile specifies the type and behavior of security mechanism to apply to the Access Solution acting as a P-CSCF.

Note
iconfalse
titleNote

When configuring

Sip

SIP Security Profile on a particular SIP Trunk Group, ensure Authcode Headers transparency flag

(see

is not enabled on the same Trunk Group (see Common IP Attributes - Transparency Flags)

is not enabled on the same Trunk Group

.

Excerpt Include
SIP Security Profile - CLI
SIP Security Profile - CLI
nopaneltrue

Include Page
_Transparency_Profile_Note
_Transparency_Profile_Note

To View

Sip

SIP Security Profile

On the SBC main screen, go to Configuration

>

 > Profile Management

> Category

 > Category: Service

Profiles

Profiles >

Sip

 SIP Security Profile.

The Sip Security Profile window is displayed.

Figure 1: Profile Management - Service Profiles - Sip Security Profile

Image Modified


To Edit

Sip

SIP Security Profile

To edit any of the

Sip

SIP Security Profile in the list, click the radio button next to the

specific Sip

specific SIP Security Profile name.

The

The Edit

Selected Sip

Selected SIP Security Profile window is displayed below.

Figure 2: Profile Management - Service Profiles - Sip Security Profile Edit Window

Image Modified

Make the required changes and

click Save at the right hand bottom of the panel to save the changes made

click Save.

To Create

Sip

SIP Security Profile

To create a new

Sip

SIP Security Profile,

click

click New

Sip

SIP Security Profile

tab

 tab on

the Sip

the SIP Security Profile List panel.

Figure 3: Profile Management - Service Profiles - Sip Security Profile Fields

Image Removed

The Create New Sip

The Create New SIP Security Profile window is displayed.

Figure 4: Profile Management - Service Profiles - Sip Security Profile Create Window

Image Modified

The following fields are displayed:

Table 1:


SIP Security Profile Parameters:

Parameter

Description

Name

Specifies the

The user name of this SIP Security Profile.

Sbx Sec Mode

Use this parameter to define the SBC security mode for this SIP Security Profile.

 The options are:

 

  • Sbc-pcscf
: SBC acts
  • (default) – SBC acts as integrated SBC+PCSCF mode.
  • Sbc-only: SBC-only mode. The SBC disregards the configured security mechanism (ipsec-3gpp or tls) in the profile, if any.

When you configure Sbx Sec Mode

is configured

as

sbc

"Sbc-only", you must configure a Transparency Profile

for following headers

in an egress trunk group.

  • Refer
to
section
  • " section to know more on how to configure a Transparency Profile.
  • Refer
to
know
  • learn the functionality of this feature.

Force Client
Security

If Enabled, while selecting the Security Mechanism, the precedence is given to the order of occurrence

of mechanism

of mechanism-

name values

name values in

the SecurityDisabled

the Security-Client header.

The options are:

  • Disabled (default)
  • Enabled

Reject Sec Unsupported Request

Enable this flag to reject the incoming REGISTER when it does not contain "sec-agree" header value (in Require or Proxy-Require headers) or does not contain any supported mechanism-name (ipsec-3gpp) in "Security-Client" header.
Use default setting "Disabled" to process messages using "Digest without TLS" security mechanism.

Disabled
  • Disabled (default)
  • Enabled

Encryption

Preference

Provides encryption preference for

Specify the SIP Security Profile encryption preference.

The available options are:

  • Always-encrypt
—Use
  • – Use this option to reject REGISTER requests if the UE offers a NULL encryption algorithm. 
None
  • None (default)
—If
  • – If this option is configured the SBC compares the UE's offer of encryption algorithms with the list of supported encryption algorithms, and selects the first matched entry in the 401 response for the REGISTER request. The SBC accepts the NULL encryption algorithm if it is the first one in the UE's offer.
  • Null-forced
 
  • –  Use this option to enforce NULL encryption irrespective of what encryption
algorithm offered
  • algorithm offered by the UE.
The 
  • The SBC acting as a Proxy For Call Session Control Function (P-CSCF) always disables encryption. 


To Delete

Sip

SIP Security Profile

To delete any of the created

Sip

SIP Security Profile, click the radio button next to the

specific Sip

specific SIP Security Profile

which you want to delete

.

Click

Click Delete

at

 at the end of the highlighted row. A delete confirmation message appears seeking your decision.

Click Yes

Click Yes to remove the specific

Sip

SIP Security Profile

from the

.