How to ensure VoIP security?

aiden

Are there specific steps beyond standard network security practices that a business should take to make a VoIP system more secure?

Answer this Question

Answers

4 total
jimlynch
Vote Up (5)

This article might help:

How to get Water Tight VOIP Security
http://www.resourcenation.com/blog/how-to-get-water-tight-voip-security/...

"Applying security policies before you implement VOIP will enable you to have better protected devices. You can also apply and then test various security policies after your VOIP has been implemented to ensure that you are tightly secured.

For networks, you can implement MPLS VPN or Virtual Private Networks to enjoy a higher level of security. Implementing security protocol is essential and should be done based on the specific type of application being used. SIP applications for instance will require a different protocol than voice applications.

SAFW-SIP aware firewalls are a must and should be added to all of your existing systems. You can also add IPSec for security as well as encryption at the IP level.

Digital certificates can be added using a third party solution such as Kerberos and all of your UDP IPsec should be evaluated based on RFC 3948.

All call processing and feature servers need to be placed behind a firewall. Software feature loads should be encrypted and it is essential that you perform spyware, virus and intrusion as well as other security scans when you first boot up your systems.

Not overloading systems is essential as well. Ensure that all software and sets are only running the minimum of services that are required for use.

Gateways and phones should always be authenticated before signaling."

Agili Ron
Vote Up (3)

Hello Friends,

 

While VOIP, Voice over Internet Protocol, offers a number of cost advantages over traditional telephoning, it can also pose a security threat. When it comes to getting water tight security for VOIP, all companies will have different requirements. There are three levels of security that most of the companies can be categorized into. 1. Applying security policies before you implement VOIP will enable you to have better protected devices. You can also apply and then test various security policies after your VOIP has been implemented to ensure that you are tightly secured. 2. For networks, you can implement MPLS VPN or Virtual Private Networks to enjoy a higher level of security. Implementing security protocol is essential and should be done based on the specific type of application being used. SIP applications for instance will require a different protocol than voice applications. 3. SAFW-SIP aware firewalls are a must and should be added to all of your existing systems. You can also add IPSec for security as well as encryption at the IP level. 4. Digital certificates can be added using a third party solution such as Kerberos and all of your UDP IPsec should be evaluated based on RFC 3948. 5. All call processing and feature servers need to be placed behind a firewall. Software feature loads should be encrypted and it is essential that you perform spyware, virus and intrusion as well as other security scans when you first boot up your systems. 6. Not overloading systems is essential as well. Ensure that all software and sets are only running the minimum of services that are required for use. 7. Gateways and phones should always be authenticated before signaling.

Thanks and Regards,

Agili Ron

 

agiliron.com

aiden

Thanks!

ttopp
Vote Up (3)

Here is a pretty decent guide at CSO.

http://www.csoonline.com/article/478577/voip-security-the-basics

Ask a question

Join Now or Sign In to ask a question.
Google is feeling the heat over its decision to build its new Hangouts IM and audio/video chat product with proprietary technology that doesn't support server federation via the XMPP industry standard, but the company is defending its move.
Judging from the number of people poring over their smartphones on the sidewalk, in their cars and in public places, mobile seems to have stolen our attention away from the wired Internet and traditional TV.
Reprogramming the identification number of a cellphone could be punishable with a prison sentence of up to five years under the terms of a proposed law announced Friday.
It's been almost a year since Microsoft moved its newly acquired Skype for Linux out of beta with the release of version 4.0, surprising more than a few Linux fans with its apparent commitment to maintaining a telephony client for the free and open source operating system.
Users in the U.K. and France will have to wait a bit longer to get their hands on the HTC First. The first smartphone to come preinstalled with Facebook Home has been delayed in those countries while Facebook updates the software to address some negative user feedback.
SoftBank has received all the necessary state approvals for the Japanese mobile carrier to acquire a majority stake in Sprint Nextel for US$20 billion, the companies announced.
Box has acquired an unreleased application called Folders, designed to give iPhone and iPad users a mobile front-end interface for the cloud storage and file management and sharing service as well as for competitors Google Drive and Dropbox.
The latest victim of disruption by Internet technologies is a veteran of World War I: the missing persons search.
The U.S. government is in negotiations with SoftBank for greater control over equipment purchases by Sprint Nextel and the selection of one of the Japanese company's nominee to the U.S. carrier's board, according to a news report.
A mechanical engineering student in Taiwan has found the messaging application called Line warns and stops users in China from sending certain politically sensitive keywords.