background image

Encrypting the Media:

For encrypting the media, 256-bit Advanced Encryption Standard (AES-256) is used. 
AES-256 specifies a cryptographic algorithm using a symmetrical block cipher that can 
process data blocks of 128 bits with 256bit chipper key (crypto key)  which is agreed by 
Diffie-Hellman   procedure.  Audio   samples   are   collected   from   the   codec,   they   are 
encrypted, and inserted into the RTP payloads. 

When the receiving side gets RTP payloads, the decrypting occurs.

A secure contact would be by generating and exchanging shared Diffie-Hellman half-
keys. Diffie-Hellman master key for the AES-256 encryption is generated from the 
combination of the two shared half keys exchanged by two Telesis systems involved in 
a call.

Diffie-Hellman key exchange:

Telesis   systems   exchange   Diffie-Hellman   half   keys   using   authentication   based   on 
H.235 Baseline Security Profile with or without integrity check. This prevents Man-in-
the-Middle (MIM) attacks and communicating systems can be sure with whom they 
share the Diffie-Hellman half keys. Hash algorithm for H.235 Baseline Security Profile 
or H.235 Baseline Security Profile with integrity check is HMAC-SHA1-96. Exchange 
of HMAC-SHA1-96 hashed Diffie-Hellman halfs keys provides additional security.

Key   exchange   occurs   during   H323   call   signaling   (H.225)   messaging   between   two 
systems for end-to-end communication. First call signaling message in both direction 
are   used   in   key   exchange.   Setup   message   is   used   in   forward   direction.   Setup 
Acknowledge, Call proceeding, Alerting or Connect message can be used in reverse 
direction. Since, the authentication keyed by the password, which is a secret in two 
systems,   it   may   be   open   to   MIM   attacks   if   simple   passwords   are   chosen.   Telesis 
systems   allow   Diffie-Hellman   half   key   exchange   provided   that   a   sufficiently   long 
password is selected. In the following cases, the call fails before connect.

Authentication failure 

Authentication but missing half key in Setup message 

Authentication   but   missing   half   key   in   one   of   Setup   Acknowledge,   Call 
proceeding, Alerting or Connect messages

Summary:

Security of VoIP communication between two Telesis systems is ensured with:

A sufficiently long password 

Baseline Security Profile for RAS messaging for H.323 endpoint-to-gatekeeper 
registration 

Baseline   Security   Profile   for   Call   Signaling   for   secure   Diffie-Hellman   key 
exchange.  

Exchange of HMAC-SHA1-96 hashed Diffie-Hellman half keys 

Cipher AES-256

H.323 AND SIP INTEGRATION

Description:

Telesis PX24U/PX24M Hybrid IP PBX systems support for SIP and H.323 protocols. 
Both protocols coexist on the same Telesis PX24U/PX24M Hybrid IP PBX system. SIP 
and H.323 calls may originate and terminate in the same system. Furthermore, Telesis 
PX24U/PX24M Hybrid IP PBX systems allow calls from SIP based devices to be 
routed to H.323 based devices and vice versa. With this interoperability, enterprises 
may have the ability to use both protocols in the same network. 

General Capabilities:

Telesis PX24U/PX24M Hybrid IP PBX systems can register to both SIP registrar and 
H.323 gatekeeper at the same time. This allows address resolution of a Telesis PX24U/
PX24M Hybrid IP PBX system from either side and results in flexibility for multi-path 
VoIP access applications. Furthermore, Telesis PX24U/PX24M Hybrid IP PBX systems 
may   have   both   integrated   H.323   gatekeeper   and   external   gatekeeper   registration 
capability at the same time. Similarly, they may have both integrated SIP registrar and 
external   registrar  registration  capability  at   the   same   time.   Coexistence  of   all  these 
capabilities allows:

SIP users to call SIP users in private address space 

SIP users to call H.323 users in private address space 

SIP users to call SIP entities in public network 

SIP users to call H.323 entities in public network 

25

Summary of Contents for PX24M

Page 1: ...PX24U PX24M HYBRID IP PBXs...

Page 2: ...RID IP PBX BUSINESS TELEPHONE SYSTEMS Designer and Manufacturer Telesis CZ Ltd U Jesl 1851 47 193 00 Praha 9 tel 420261090171 info telesis cz http www telesis cz Doc No IH 1037 eng ver1 03 January 200...

Page 3: ...PBX systems while keeping traditional TDM interfaces There are analog subscribers and trunks all featured with caller ID as well as 48 Vdc feed for analog subscribers to drive long loops Solution also...

Page 4: ...tection on analog DC loop trunks DTMF transceivers Conference hardware Integrated CMDR call records buffer Integrated DVR digital voice recorder with 100 hours capacity 4 playing and 4 recording chann...

Page 5: ...for SIP calls with using the basic SIP supplementary services such as Invite call hold call forward and call transfer with refer method Similarly these are also applicable for H 323 calls with using...

Page 6: ...softphones Licenses for IP to TDM and TDM to IP gateway channels which allow call routing between TDM and IP SIP H 323 users Licenses for xSIP VoIP phone users License for AES 256 encryption for VoIP...

Page 7: ...y and Health 2 Call Centers 3 Air Maritime Railway Traffic Control The integrated DVR digital voice recorder within Telesis PX24U PX24M Hybrid IP PBX Systems may be used in such operations and applica...

Page 8: ...of SIP user agents to be registered into its integrated registrar These endpoints may be IP trunk routes and or SIP hard soft phones with their own IP addresses Furthermore the PX24U PX24M Hybrid IP P...

Page 9: ...ally the Called Party s Nature of Address after which any or all of these parameters may be translated SYSTEM MANAGEMENT AND BILLING The Telesis PX24U PX24M Hybrid IP PBX can managed over IP System pr...

Page 10: ...g busy System controlled call forwarding no reply Call tranfer after answer Call back User controlled divert routed call Call transfer while the destination is busy Call transfer while the destination...

Page 11: ...stribution ACD B Party called party analysis Boot Xymphony Busy transfers do not clear Busy message Busy message download Busy message remove Busy message upload Busy tone Busy tone cadence modificati...

Page 12: ...vel modification Copy routing table Copy user properties Credited extension Credit edit CTI computer telephony integration DDI direct dialing in Declare external IP address for H 323 Declare external...

Page 13: ...buffer G 711 transmit silence suppress G 723 codec G 723 transmit buffer length G 723 transmit silence suppress G 723 transmit 6 4kbps compress G 723 preferred receive buffer G 723 receive ask for sup...

Page 14: ...ementary service MSN ISDN supplementary service UUS Last number redial LCR least cost routing Local call ring type1 tone Local call ring type2 tone Local call ring type3 tone Local call ring type4 ton...

Page 15: ...dial on destination busy Redial on incomplete dialing Reject diverted calls Reject diverted calls activation Reject diverted calls deactivation Reminder message Reminder message download Reminder mess...

Page 16: ...User authorizations User parameter upload User pool User pool update Use rport in invite message User service charges Vacant tone Vacant tone cadence modification Vacant tone frequencies modification...

Page 17: ...c distortion of all tones is 1 The accuracy of the timing is better than 10 Cadences Levels and Frequencies of the tones are programmable without interrupting the operation of the PX24U PX24M Hybrid I...

Page 18: ...ge 06 AlertingIni Alerting message for incoming calls through DID trunks Message 07 Reminder Reminder wake up call message Message 08 Hold Message or music on hold played repatedly Message 09 VmailSen...

Page 19: ...mphony form the CCE The CCE provides the functionality to initiate manage and terminate calls through the interfaces in a Telesis PX24U PX24M Hybrid IP PBX system In this communication the required co...

Page 20: ...l primitives from the CCE to Layer 3 Port Control RejectRequest DisconnectRequest MoreInfoRequest ProceedingRequest ReleaseRequest SetupRequest AlertingRequest ConnectRequest ConnectResponse HoldRespo...

Page 21: ...er voltage and over current protection on analog trunks conforms to ITU T K 20 K 21 recommendations Additional primary protection devices to those residing in the main distribution frame may also be e...

Page 22: ...operates only for the integrated gatekeeper routed calls in some circumstances While voice bridging distant offices over the IP security of a VoIP call is guaranteed with the encryption optional of vo...

Page 23: ...U PX24M Hybrid IP PBX system featuring an integrated SIP registrar provides an economical way for administrators to manage a central database of phone numbers without the expense of a separate box reg...

Page 24: ...algorithm explained here is applicable for H 323 endpoint to endpoint connection too it is recommended for H 323 endpoint to gatekeeper connection for further security The following paragraphs demonst...

Page 25: ...iciently long password is selected In the following cases the call fails before connect Authentication failure Authentication but missing half key in Setup message Authentication but missing half key...

Page 26: ...merous xSIP users Number IP translation is performed through an advanced routing algorithm Together with the integrated xSIP registrar call authorization call management enhanced billing functions fle...

Page 27: ...or analog DC loop trunks DTMF transceivers Conference hardware Integrated CMDR call records buffer Integrated DVR digital voice recorder with 100 hours capacity 4 playing and 4 recording channels for...

Page 28: ...ated SIP registrar for 160 VoIP users Integrated xSIP registrar Installation accessories Hundreds of supplementary services for analog digital and VoIP users 1 ltf akueuro AC DC power converter with b...

Page 29: ...n accessories Hundreds of supplementary services for analog digital and VoIP users 3 pxm sntis6x A basic capacity PX24M Hybrid IP PBX system It is equipped with Xymphony operating firmware 4 analog DC...

Page 30: ...etection capability Connectors are RJ11 type Inserted into a free expansion slot to increase the capacity of analog trunks w pxf lscdatf License for 1 pxd atfrj02 or 1pxd datfrj06 expansion cards 1 px...

Page 31: ...ves that could leak or cause condensation Vibration causing equipment Exposure heat sources or direct sunlight Power To ensure long operational life to your system and your safety the 220 VAC outlet t...

Page 32: ...when it is powered up Attach all covers in place after servicing equipment and before leaving the customer premises to avoid customer contact with damageable components Any auxiliary equipment that is...

Page 33: ...subscribers Default access codes are from 100 to 103 right to left 5 AC DC power converter connector 6 Fuse 7 Connector for optional battery 8 Status led 9 Service button 10 Parameter button 11 Expan...

Page 34: ...4U PX24M Hybrid IP PBX systems are shipped with a footprint sheet to guide the installer while placing screws on the wall Footprint sheet Using this sheet drill the wall and place the screws firmly on...

Page 35: ...rd 19inch rack with using the optional 19inch rack adapters The same adapters are used for both systems 19inch rack adapter set has the same right and left parts Each part is fixed to the system with...

Page 36: ...er Repeat the same for the other side It is done and so simple As a result Telesis PX24U PX24M Hybrid IP PBX system is ready to be placed in an industry standard 19inch rack A PX24U with rack adapters...

Page 37: ...socket Otherwise your system may not operate properly The power supply of the Telesis PX24U PX24M Hybrid IP PBX system may be backed up with batteries The recommended batteries for a 5 6 hour backup t...

Page 38: ...ake sure you are electro statically discharged by wearing an electrostatic bracelet or touching a metal object such as a radiator or a tap On the back of the card there is a male connector with multip...

Page 39: ...e expansion card needs to be licensed for its proper operation Certain parts of the software which deliver particular functionality to a particular optional part like an expansion card are technologic...

Page 40: ...r and screw it Connect all power sources to the system again DEM Analog E M Card Expansion Card for PX24M 2 or 4 wire selection can be made individually for each port through the jumpers P04 P14 P24 P...

Page 41: ...configured individually as a subscriber S0 or a trunk T0 through the jumpers as shown below Conductors of the RJ45 connector for S0 and T0 configuration are shown below Note DDL card can be inserted...

Page 42: ...ming ONLINE HELP PAGES AND DOCUMENTS After you connect to your PX24U PX24M system with using a web browser you may find online help pages and documents Online help system will guide you programming th...

Page 43: ...t any password and HTTP port as 80 REBOOTING THE SYSTEM PROGRAMMED PARAMETERS FACTORY DEFAULTS Memory Locations for Programmed Parameters The programmed parameters are stored in two locations in the P...

Page 44: ...olatile memories until the web browser command Save is operated Restoring the Programmed Parameters Whenever the Save command is operated all the parameters in the operational memories are transferred...

Page 45: ...ting call forward unconditional setting call forward busy setting call forward no reply setting hot line activating call waiting activating do not disturb activating wake up reminder service observing...

Page 46: ...lgorithms and proprietary VoIP codecs within the XPhone the bandwidth requirement is very small Telesis Xphone IP Softphone for Mobile Phones XPhone is the VoIP softphone with xSIP protocol and suppor...

Page 47: ...es to integrate the computer and Telesis PX24U PX24M system for telephony needs Moreover the XCom is a freeware utility CRM Customers Relations Management Integration Telesis XCom which is a freeware...

Page 48: ...nce service charges and any other taxes which may arise 2 TERMS OF PAYMENT Except as otherwise provided in the quotation proforma invoice payment terms are IN ADVANCE The USD account of the Seller is...

Page 49: ...with respect to the software product The Seller grants the Buyer the following rights use of Xymphony with its options limited by the invoiced amounts on a single TELESIS System that the Buyer have pu...

Page 50: ...Furthermore the Seller offers no support via email or otherwise for installation customization administration of licenses The Seller reserves the right to respond and answer questions 9 VALIDTY OF ORD...

Page 51: ...al detectors Yes A Party analysis Yes B Party analysis Yes Subscriber services Yes Credited subscribers Yes Remote access Yes Signaling interworking Yes Programmable tones Yes Programmable ring melodi...

Page 52: ...gistrar Yes H 323 endpoints which can register 160 SIP user agents which can register 160 xSIP users which can register Numerous with licensing VoIP SIP H 323 TDM gateway channels Yes with licensing P...

Page 53: ...ransceivers Yes Real time charging Yes 12 or 16kHz charge pulse detectors Yes Polarity reversal detectors Yes A Party analysis Yes B Party analysis Yes Subscriber services Yes Credited subscribers Yes...

Page 54: ...packet 1 2 3a 3b Yes MF shuttle signaling Pulse shuttle R1 5 Yes Pulse decadic signaling Yes ANI request and reception Yes ANI response generation Yes IP TELEPHONY Interface 10 100 BaseT H 323 protoco...

Page 55: ...Yes TDM to IP gateway capability Yes H 450 supplementary services Yes SIP supplementary services Yes DIMENSIONS without optional 19inch rack adapters Height 15 cm Width 23 cm Depth 23 cm This page is...

Reviews: