AudioCodes MediaPack 114 Manual de usuario Pagina 94

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 390
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 93
SIP User's Manual 94 Document #: LTRT-65411
MediaPack Series
Parameter Description
server or client for the TLS connection.
When a remote certificate is received and this parameter is not
disabled, the SubjectAltName value is compared with the list of
available Proxies. If a match is found for any of the configured
Proxies, the TLS connection is established.
The comparison is performed if the SubjectAltName is either a
DNS name (DNSName) or an IP address. If no match is found
and the SubjectAltName is marked as ‘critical’, the TLS
connection is not established. If DNSName is used, the
certificate can also use wildcards (‘*’) to replace parts of the
domain name.
If the SubjectAltName is not marked as ‘critical’ and there is no
match, the CN value of the SubjectName field is compared with
the parameter TLSRemoteSubjectName. If a match is found,
the connection is established. Otherwise, the connection is
terminated.
TLS Client Verify Server Certificate
[VerifyServerCertificate]
Determines whether the device, when acting as client for TLS
connections, verifies the Server certificate. The certificate is
verified with the Root CA information.
[0] Disable (default).
[1] Enable.
Note: If Subject Name verification is necessary, the parameter
PeerHostNameVerificationMode must be used as well.
TLS Remote Subject Name
[TLSRemoteSubjectName]
Defines the Subject Name that is compared with the name
defined in the remote side certificate when establishing TLS
connections.
If the SubjectAltName of the received certificate is not equal to
any of the defined Proxies Host names/IP addresses and is not
marked as 'critical', the Common Name (CN) of the Subject
field is compared with this value. If not equal, the TLS
connection is not established. If the CN uses a domain name,
the certificate can also use wildcards (‘*’) to replace parts of the
domain name.
The valid range is a string of up to 49 characters.
Note: This parameter is applicable only if the parameter
PeerHostNameVerificationMode is set to 1 or 2.
3.4.3.6 Configuring the IPSec Table
The 'IPSec Table' page allows you to configure the Security Policy Database (SPD)
parameters for IP security (IPSec).
Note:
You can also configure the IPSec table using the ini file table parameter
IPSEC_SPD_TABLE (refer to ''Security Parameters'' on page 252).
Vista de pagina 93
1 2 ... 89 90 91 92 93 94 95 96 97 98 99 ... 389 390

Comentarios a estos manuales

Sin comentarios