Question about SIP security

javond01

Customer
Joined
Jun 28, 2023
Messages
7
Reaction score
0
We have a SIP connection to Flowroute from our on-prem 3CX server using register-based authentication over 5060. We are on version 20. I have a few questions about the security of it.

1. Is the password sent to Flowroute encrypted or plain text?
2. Is the connection encrypted or unencrypted?
3. If it is unencrypted, how do we encrypt the connection? Is it as simple as changing it to use port 5061?
4. How to we switch to using IP based authentication to Flowroute? All I see in 3CX is when I select FlowRoute as the Provider is ID and password.

Thank you
 
Hai,
1. Is the password sent to Flowroute encrypted or plain text?
normally there will be challange which is like hash, you can do the packet capture and double check that.
2. Is the connection encrypted or unencrypted?
its depend how its configured.
3. If it is unencrypted, how do we encrypt the connection? Is it as simple as changing it to use port 5061?
provider side also it should same port. and even both side 5061 it doesnot mean its encrpted. u hv to check with provider is it really encrypted sip and ecncrypted RTP.
4. How to we switch to using IP based authentication to Flowroute? All I see in 3CX is when I select FlowRoute as the Provider is ID and password.
its not recomond to switch to IP based, better to be ID and password to that your SIP Trunk use by authenticated .

normaly telecome gave the SIP trunk on private network on seperate LAN port on fiber ONU, in that way it will standard SIP protocol with ID/Password registration. its way more secure.

Thank You
 
1. Is the password sent to Flowroute encrypted or plain text?
The password is never visible. Authentication is performed using Digest authentication

2. Is the connection encrypted or unencrypted?
The connection to Flowroute is unencrypted
3. If it is unencrypted, how do we encrypt the connection? Is it as simple as changing it to use port 5061?
No, Flowroute is not supported for TLS so you will need to do your own testing and also use a Generic template to do so. You will also need the root certificate of the certification authority Flowroute uses to sign their certificates. The Flowroute default template is not set up for TLS.
4. How to we switch to using IP based authentication to Flowroute? All I see in 3CX is when I select FlowRoute as the Provider is ID and password.
You will need to use a Generic template however please keep in mind this is not supported by 3CX. The default template is set up for registration which is what we test and support.
 
The password is never visible. Authentication is performed using Digest authentication


The connection to Flowroute is unencrypted

No, Flowroute is not supported for TLS so you will need to do your own testing and also use a Generic template to do so. You will also need the root certificate of the certification authority Flowroute uses to sign their certificates. The Flowroute default template is not set up for TLS.

You will need to use a Generic template however please keep in mind this is not supported by 3CX. The default template is set up for registration which is what we test and support.
Thank you. FlowRoute's website warns you that if you don't use IP based, it is not recommended. Is that something 3CX has plans to support in the future?
 
Thank you. FlowRoute's website warns you that if you don't use IP based, it is not recommended. Is that something 3CX has plans to support in the future?
Not at the moment. 3CX works best with registration based trunks so that is what we have tested and support.
 
  • Like
Reactions: javond01

Latest Posts

Members Online Now

Forum statistics

Threads
111,831
Messages
589,276
Members
164,660
Latest member
RJenkinsROCK