10.10.15 |
Gatekeeper |
| The Gatekeeper menu item is used to specify parameters for the gatekeeper. |
| A gatekeeper must be configured for each node in a network system. In addition, an SNTP server must be specified to synchronize the time of the individual nodes and all IP clients. For standalone systems, the SNTP server data is configured here. For a network system, by contrast, the SNTP server data is only displayed here. The configuration of the SNTP server data occurs via Settings | Netwide Data. |
Security as of HiPath 3000/5000 V5.0 |
| In order to prevent the operation of unauthorized IP clients and gatekeepers, a security mechanism was implemented starting with HiPath 3000/5000 V5.0. Every H.225 message from IP clients or gatekeepers can be optionally checked for validity via a realtime stamp (= crypto token). These crypto tokens are generated by the IP client and entered in the sent packets. The gatekeeper on the other side checks these crypto tokens for validity and discards the message if the token is invalid. The security functionality is defined by the parameters set under Gatekeeper and Security. |
10.10.15.1 |
Area: Gatekeeper |
HG 1500 Board |
| Shows in which slot the HG 1500 board that is assigned as a gatekeeper is inserted (see also Gatekeeper (V5.0 and Later). |
Identity |
| This parameter is used for authentication purposes when the gatekeepers communicate with one another. The gatekeeper Identity is an alphanumeric value that identifies the gatekeeper and is sent along with H.225 communications. |
| In the communication system, if the security is set to Reduced Security or Full Security, the identities of all gatekeepers and all IP clients of a HiPath domain must be set identically in order to enable communications between the gatekeepers. |
Password |
| The password is used for authentication purposes when the gatekeepers communicate with one another. It is also used to compute the crypto tokens for the H.225 send and receive packets. |
| In the communication system, if the security is set to Reduced Security or Full Security, the passwords of all gatekeepers of a HiPath domain must be set via HiPath 3000 Manager to be identical in order to enable communications between the gatekeepers. |
10.10.15.2 |
Area: SNTP Server |
IP address |
| IP address of the network-wide Time server. In order to use the H.235 security protocol, a central SNTP Time server and a time reference must be available for all IP clients and the gatekeeper, respectively. |
Polling Time |
| Multiple of 10 minutes. |
| The Polling Time defines how often the IP clients and the gatekeeper access the SNTP Time server to read the current time reference. The polling time depends on the accuracy of the internal clocks of the IP devices. Practical experience has shown that a value of 72 is appropriate (72x10=720 minutes = 12 hours = twice a day). |
Timezone |
| The time zone in which the gatekeeper is located is set here (local time zone of the communication system). |
10.10.15.3 |
Area: Security |
No Security, Reduced Security, Full Security |
| Activation of the H.235 security protocol is configured here: |
| - | No Security: The security protocol is not used, i.e., no crypto tokens are sent by the IP clients. |
| - | Reduced security: The IP clients send crypto tokens, and the HG 1500 verifies these tokens. However, the HG 1500 itself does not send any crypto tokens. |
| - | Full security: Both sides send and verify crypto tokens. |
Identity |
| The global gatekeeper identity is specified here. |
Password (only for trunking) / Confirm password |
| Enter the password here and confirm it by repeating the entry. |
Security time |
| This setting configures monitoring for the lifetime of IP packets. This means that a check is then performed in the communication system to ensure that the incoming IP packets are not older than the current time plus the time specified in the Security time field. This prevents IP packets from being potentially traced by a sniffer, for example, and then being resent to the original addressee after manipulation. The size of the Security time depends on the dynamic runtimes in the customer LAN. If the selected time is too small, and long runtimes occur, disruptions may occur in the VoIP traffic. A value of 90 seconds should work without problems in most cases. |
|
| |
| HiPath 3000/5000 V9, Manager E, Administrator Documentation, Issue 10 | up ![]() |
|
![]() |
||
| Disclaimer & Copyright | ID: P31003H3590M1000176A9 | 2014-03-03 |