9.2.3 |
Upgrade HiPath 3000 for Signaling & Payload encryption (SPE) |
Overview |
| The Signaling & Payload encryption feature is provided in HiPath 3000/5000 V7 R4 or higher. If a software version lower than V7 R4 is in use, it must be upgraded before the SPE feature can be used in HiPath 3000. Please refer to the published release notes. |
| A hardware upgrade is not required. As a result of the increased demand by SPE for resources further HG 1500 boards might be required. |
9.2.3.1 |
Upgrading |
| If a software version lower than V7 R4 is in use, the following software upgrades must be performed before the SPE feature can be used without restriction: |
| • | Upgrade of all HFA terminals to an SPE-enabled software version |
| Due to the introduction of EFC, HiPath 3000 V7 and higher is no longer upwardly compatible with regard to the "Signaling & Payload Encryption" feature, except to HiPath 3000 V6.0 systems which have an EFC-enabled HG 1500 and EFC-enabled IP terminals. |
| • | Upgrade of all HG 1500 gateways to V9 |
| • | Upgrade of the HiPath 3000/5000 to V9. The "VoIP Security" feature must be deactivated before upgrading a HiPath 3000/5000 V9 to HiPath 3000/5000 V7. This is necessary due to the fact that this feature is not compatible with the "Signaling & Payload Encryption (SPE) feature described here. |
| • | Upgrade of administration program DLS and HiPath Manager E |
| • | Changes to configuration so that SIP-Q instead of CorNet-IP is used to network HiPath 3000 with HiPath 4000 V4.0 systems. The HiPath 4000 supports SPE only via the SIP-Q protocol. |
|
| • | Changes to the configuration of the option "Always use DSP", if HiPath 4000 networking should still be achieved using H.323-Q (CorNet-IP). In this case, no SPE to the HiPath 4000 is possible either. |
| • | In HiPath 3000/5000 V7 and higher, the HiPath 4000 must be connected as an external H.323 gatekeeper or external SIP registrar. |
9.2.3.2 |
Additional System Load |
Overview |
| Activation of the Signaling & Payload Encryption feature has the following consequences for the HiPath network: |
| • | Higher bandwidth requirement due to continuous TLS sessions for: |
| - | Connections to HFA terminals (CorNet-IP TC/TS, H.225 CS) |
| - | Connections for SIP terminals (SIP including SDP) |
| - | H.323 and SIP trunking connections |
| • | Higher bandwidth requirement: |
| - | Due to the fill and authentication algorithms used by TLS during transmission of user data |
| - | Due to the proprietary encryption protocols used for IPDA and CTI connections |
| - | Due to SRTP/SRTCP |
| • | Higher network traffic due to periodic downloads of CRL ( Certificate Revocation List) or delta CRL by each Gateway |
| • | Higher network traffic due to recently introduced protocols |
| - | H.235 Annex D for DMC Slave connections |
| - | MIKEY messages |
| • | Additional data due to protocol extensions: |
| - | CorNet-TC/TS plus X messages |
| - | H.225 RAS (LEGK communication) |
| - | CorNet NQ |
| Because of the many configuration options and scenarios possible, it is difficult to accurately determine the effects of this feature on the system, that is, the additional bandwidth requirement and the increased data traffic volume. The following sections are intended as suggestions on how to calculate the additional system load. |
Increased bandwidth requirement with SRTP |
| The table provides an overview of the increase in bandwidth requirements caused by the SRTP. The bandwidth is assumed to rise by 70 bytes as a result of RTP, UDP, IP, 802.1Q VLAN tagging and MAC (incl. preamble, FCS). SRTP accounts for an additional increase of 10 bytes. This brings the overall increase to 80 bytes. |
Higher demand for resources by SPE |
| The following table provides an overview of the higher demand for resources caused by the SPE (Signaling & Payload Encryption) feature. The values are automatically applied by the system. If the SPE feature is active, a reduced number of channels is reported to the system. |
| |
Higher data volume as a result of SPE |
| This table can be used to calculate the additional system load resulting from the Signaling & Payload Encryption (SPE) feature: |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| If the individual data volumes are added together, then the per-call data traffic increases in the LAN as follows: |
| • | for a local call: 2 KB (60 CorNet TC + 4 H.225 CS messages over TLS + 2 MIKEY#0 messages) |
| • | for an external call: 700 bytes (12 H.225 CS messages incl. CorNet NQ messages over TLS + 2 MIKEY#0 messages) |
| The increased data traffic volume in payload connections is mainly due to the authentication code of 10 bytes, which is added to every data packet as a result of SRTP. The additional data volume due to SRTCP is negligible. |
| HiPath 3000/5000 V9, Service Documentation, Issue 7 | up ![]() |
|
![]() |
||
| Disclaimer & Copyright | ID: P31003H3590S100017620 | 2012-06-25 |