• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Internal Secure SIP / SRTP

Status
Not open for further replies.

akakern95

Silver Partner
Advanced Certified
Joined
Jan 28, 2020
Messages
22
Reaction score
1
Hey all,

i was trying to enable Secure SIP and SRTP internally for a possible customer who is into security features.
The goal is to encrypt the traffic between the phones. As far as i know the traffic between phones to PBX is encrypted because of the tunneled SBC connection.
Traffic from PBX to SIP provider is a different story.

We are using a 3CX provided FQDN and Yealink IP phones behind a SBC. Our 3CX PBX is hosted in a cloud.
When i enable TLS and use port 5061 for SIP Server i cannot get my Yealink T58 or T46S registered anymore.
Altough i can enable SRTP on the T58. I checked a Wireshark pcap and i was not able to hear the call from the phone to PBX anymore. So seems like this was working as expected.
But as soon as i enable SRTP on the T46S I am not able to connect a call anymore. As soon as i pick up the call, i get an error "Outgoing call not possible" on the phone.

Can anyone assist here maybe? I read through a lot of posts and it seems like no one really was able to get SIP TLS and SRTP working 100%.
 
Hi!



First of all, you are correct in saying that the traffic between the SBC and the PBX is encrypted.
The traffic between the IP Phone though and the SBC, at best, you can enable SRTP, but not SIP TLS (SBC does not listen for SIP TLS). Mind you, unless you are worried that there may be 'leaks' on the internal network, this should not be a problem because as mentioned, the traffic from/to the PBX is encrypted and that is what passes over the public internet.

So, SIP TLS + SRTP can only be usaed when the IP Phone is either "Local" or "Remote STUN".
Before saying what is needed, I also want to point out that SRTP + SIP TLS for IP Phones is not officially supported yet, otherwise we would have provisioning options that would allow you to do this.

Onto what you need to do:
  1. Provision the IP Phone normally as you usually would per the 3CX guides
  2. In the 3CX Extension Settings, in the "Phone Provisioning" tab, in the drop-down select "3CX App" and then set the RTP Mode to "Only secure", then press OK.
  3. Log into the IP Phone interface and in the case of Yealink, go to Account --> Advanced and set RTP Encryption (SRTP) to "Compulsory", then hit "Confirm".
  4. While still in the Yealink UI, go to Account --> Register and here change the SIP Port to 5061 (3CX SIP TLS port is always <default SIP Port> + 1) and the transport to TLS, then hit "Confirm".

Once you do this, the IP Phone should be working with SIP TLS and SRTP.

Important Note:
If you are configuring the IP Phone for remote STUN, remember that you will have to open port 5061/TCP for the SIP TLS connection to be allowed through (or whatever the SIP TLS port is on your installation).
 
Hi!



First of all, you are correct in saying that the traffic between the SBC and the PBX is encrypted.
The traffic between the IP Phone though and the SBC, at best, you can enable SRTP, but not SIP TLS (SBC does not listen for SIP TLS). Mind you, unless you are worried that there may be 'leaks' on the internal network, this should not be a problem because as mentioned, the traffic from/to the PBX is encrypted and that is what passes over the public internet.

So, SIP TLS + SRTP can only be usaed when the IP Phone is either "Local" or "Remote STUN".
Before saying what is needed, I also want to point out that SRTP + SIP TLS for IP Phones is not officially supported yet, otherwise we would have provisioning options that would allow you to do this.

Onto what you need to do:
  1. Provision the IP Phone normally as you usually would per the 3CX guides
  2. In the 3CX Extension Settings, in the "Phone Provisioning" tab, in the drop-down select "3CX App" and then set the RTP Mode to "Only secure", then press OK.
  3. Log into the IP Phone interface and in the case of Yealink, go to Account --> Advanced and set RTP Encryption (SRTP) to "Compulsory", then hit "Confirm".
  4. While still in the Yealink UI, go to Account --> Register and here change the SIP Port to 5061 (3CX SIP TLS port is always <default SIP Port> + 1) and the transport to TLS, then hit "Confirm".

Once you do this, the IP Phone should be working with SIP TLS and SRTP.

Important Note:
If you are configuring the IP Phone for remote STUN, remember that you will have to open port 5061/TCP for the SIP TLS connection to be allowed through (or whatever the SIP TLS port is on your installation).
Hi @NickD_3CX,

thank you very much for the detailed answer!
I already thought that SIP TLS and SBC in combination would not work, I just wasn't able to find a post where this was discussed.

With the Yealink T58 the SRTP was working as expected. It shows a little lock icon when a call is established and I can see in the pcap the RTP streams are encrypted.

Do you maybe have a hint why it is not working with the T46S? I just configured exactly the same option but the calls do not work anymore. Strangely internal calls between extensions work but when I try to call the echo service *777 or an external number i get the error mentioned above.
 
Hey @NickD_3CX,

you got me on the right track. I was able to fix it on the T46S now.

My problem was point 2 you mentioned:
In the 3CX Extension Settings, in the "Phone Provisioning" tab, in the drop-down select "3CX App" and then set the RTP Mode to "Only secure", then press OK.

I did this only for my extension while testing. Just after enabling it on the other one too, SRTP works with the T46S.

Thanks for your help!
 
You are very welcome! :)

Just to repeat myself though, it is not yet officially supported. Once it is, rest assured there will be a provisioning option making this much much easier to configure.
 
You are very welcome! :)

Just to repeat myself though, it is not yet officially supported. Once it is, rest assured there will be a provisioning option making this much much easier to configure.

I don't think i will need this very often, but in case a customer asks for this i have a proper answer to the question :)
And it seems like the Yealinks do not lose the option when auto provisioning happens so I do not have to fiddle around with custom templates.
 
Status
Not open for further replies.

Forum statistics

Threads
112,148
Messages
590,962
Members
165,168
Latest member
Stephan Eusebe