Jump to content

Snom and No Encryption


Sara

Recommended Posts

I hooked up my three Snom 370 Phones and all have encryption enabled so one would think they would automatically encrypt calls between each of the phones but NO they don't. I did a network scan and could see the unencrypted packets travelling back and forward ready for me to gather statists on the VOIP call and play it back in the clear.

 

I have tried just about everything but to no avail.

 

Sara.

Link to comment
Share on other sites

Are you using TLS? Are you able to see the SIP traffic?

 

The PBX uses SRTP only if TLS has been used.

 

Versions? Of the PBX and of the phones?

 

I use xxx.xxx.xxx:5061;transport=tls on outgoing proxy and yes I have encryption enabled on the Snom 370 phones all with firmware version 7.1.19, the pbxnsip is version 2.0.3.1715 windows. When I use xxx.xxx.xxx:5061;transport=tls it runs over UDP with my VPN OK but when I use sip:xxx.xxx.xxx:5061;transport=tls it does encrypt but I cannot receive any incoming calls.

 

Sara.

Link to comment
Share on other sites

Hmmmmmmmm.

 

Well, the only thing that I can think about right now it to use the latest and the greatest, which is currently http://www.pbxnsip.com/download/pbxctrl-2.1.0.2109.exe (see http://wiki.pbxnsip.com/index.php/Installi...#Manual_Upgrade on how to move to that version).

 

 

OK, I have finally got the encryption working. If you add the line transport=tls to your outbound proxy it plays havock with the encryption on Snom 370 but if you just register the Snom to the ip address without the tls line it shows that it offers AES Encryption. I tried it with a call to my mobile which supports secure calls and it encrypted the call ok. So I dont know why the tls line would effect the encryption but it does, you can either have outbound over tcp with tls or outbound over udp with tls or just outbound over tcp but these do not work with encryption, as soon as a line is added to the outbound proxy it cuts out the automatic encryption.

 

Sara.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...