Description
Feature
Defines whether the phone is nonsecure, authenticated, encrypted, or protected. Other entries
in this table describe security features. For more information about these features, about
Cisco Unified Communications Manager, and about Cisco Unified IP Phone security, see
the
Cisco Unified Communications Manager Security Guide
.
Security profile
Lets you ensure the privacy of phone configuration files.
Encrypted configuration files
For security purposes, you can prevent access to the web pages for a phone (which display
a variety of operational statistics for the phone) and User Options web pages. For more
information, see
Control web page access, on page 249
.
Optional web server disabling for a
phone
Additional security options, which you control from Cisco Unified Communications Manager
Administration:
•
Disabling PC port
•
Disabling Gratuitous ARP (GARP)
•
Disabling PC Voice VLAN access
•
Disabling access to the Setting menus, or providing restricted access that allows access
to the Preferences menu and saving volume changes only
•
Disabling access to web pages for a phone
•
Disabling Bluetooth Accessory Port
Phone hardening
The Cisco Unified IP Phone can use 802.1X authentication to request and gain access to the
network. See
802.1X Authentication, on page 33
for more information.
802.1X Authentication
After you configure a Survivable Remote Site Telephony (SRST) reference for security and
then reset the dependent devices in Cisco Unified Communications Manager Administration,
the TFTP server adds the SRST certificate to the phone cnf.xml file and sends the file to the
phone. A secure phone then uses a TLS connection to interact with the SRST-enabled router.
Secure SIP Failover for SRST
Ensures that all SCCP and SIP signaling messages that are sent between the device and the
Cisco Unified Communications Manager server are encrypted.
Signaling encryption
Security Profiles
All Cisco Unified IP Phones that support Cisco Unified Communications Manager use a security profile,
which defines whether the phone is nonsecure, authenticated, or encrypted. For information about configuring
the security profile and applying the profile to the phone, see
Cisco Unified Communications Manager Security
Guide
.
To view the security mode that is set for the phone, look at the Security Mode setting in the Security
Configuration menu.
Cisco Unified IP Phone 8961, 9951, and 9971 Administration Guide for Cisco Unified Communications Manager
10.0 (SIP)
30
Cisco Unified IP Phone
Security Profiles
REVIEW DRAFT - CISCO CONFIDENTIAL