Home > Ask the Unified Communications Experts > UC security with Andrew Graydon Questions & Answers > Traffic logging and VoIP encryption
Ask The Unified Communications Expert: Questions & Answers
EMAIL THIS

Traffic logging and VoIP encryption

Andrew Graydon EXPERT RESPONSE FROM: Andrew Graydon

Pose a Question
Other Unified Communications Categories
Meet all Unified Communications Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 24 May 2006
For best practices, what traffic logging should be performed at firewalls? Is there an encryption for Voice over IP -- for example, to protect traffic from snooping on Internet?

>
Typically best practices would entail traffic logging on ALL traffic coming through a perimeter firewall. Traffic of interest on the VoIP side would typically be User Datagram Protocol (UDP) traffic on port 5060 (SIP) and UDP traffic on the RTP ports opened on the perimeter firewall, typically 10000-30000. This is however a lot of information, so a log analyzer tool will probably be necessary.

Currently, there are a number of encryption technologies being proposed for VoIP by the Internet Engineering Task Force (IETF), the body which produces the documentation and recommendations for protocol design for the Internet. As typical Internet transmission of VoIP is accomplished through SIP, there are actually three protocols involved in the VoIP traffic: SIP, Session Description Protocol (SDP) and RTP. SIP and SDP are transmitted in cleartext over port 5060 and may be encrypted using Transport Layer Security (TLS) which some handsets and IP PBXs now support.

The media, which is transported using RTP, is where the standards are not yet fully developed. The two main contenders for this are Secure RTP (SRTP) and ZRTP, both of which utilize a variant of key exchange for encrypting the media stream. SRTP entails a separate key management system while ZRTP utilizes an in-band key exchange during the call setup. In other words, ZRTP is transparent to the user! However, neither of these proposals has gained widespread use in the vendor market, meaning you won't see many handsets supporting this yet.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
UC security with Andrew Graydon
Why is VoIP authentication essential?
Criminal abuse of VoIP
Alternative to keeping data and VoIP traffic on separate VLANs
Do session border controllers (SBCs) improve security at the level of VoIP traffic?
Will implementing VoIP increase our company's vulnerability to hackers and denial-of-service attacks?
Can VoIP and firewalls work together for the greater security good?

VoIP QoS and VoIP Security
Linking VoIP islands: The value of SIP trunking
SIP trunking ROI: Linking VoIP islands and more
The benefits of linking VoIP islands
Mobile IP networks: An overview
Tutorial: VoIP ROI
VoIP implementation study guide
How will VoIP impact the quality of phone calls on our network?
How does one cope with echo in a VoIP-enabled network? What's the best way to use an echo canceller?
Does implementing VoIP security affect the QoS? How would one handle it, if it does?
IBM, Avaya deals signal IP telephony quality control's coming of age

VoIP Protocols
How can MPLS help in VoIP implementation between a parent company and its branch offices?
HD voice value proposition: Just try using an HD phone
SIP trunks a no-brainer for VoIP rollouts
Digium's Asterisk PBX does God's work at Midwest church
Microsoft's Real-Time Codec (RTC) for VoIP optimization
Is there a difference between VoIP and IP telephony?
VoIP for the globe-trotting frequent traveler
SIP tutorial
Springer Handbook of Speech Processing
Top 10 VoIP tips for 2007

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
vishing  (SearchUnifiedCommunications.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Voice and Data Communications Tips
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts