Instruction manual

IP security
3-2 Issue 9 May 2003
Mission-critical assets
Unlike a regular PC or print server on the network, the telephony server
represents a mission-critical piece of equipment to the enterprise. As such, it
needs to be treated in a manner that is commensurate with any other piece of
equipment on the network that is needed for the ongoing operation of the
enterprise.
Physical security
The telephony server should be kept in secure environment. Placing the server in
a location that allows free access by any employee also allows those individuals
the opportunity for disruption of the server and consequently the service. Keep the
server isolated from all except those who need access.
Control networks
Avaya’s telephony servers use private control networks. These networks transfer
vital information for the ongoing operation of the server between it and its
gateways or redundant systems. Do not integrate these private networks with any
other networks on your enterprise. Physical separation is always best. In the case
of VLANs, logical separation needs to be maintained.
Firewalls and routing
The telephony server provides the ability for administration of extensions and
other user information via the network. The protocols and services of the server
that are necessary to accomplish this should not be accessible to each telephony
user in the enterprise. Company-managed firewalls and routers can restrict
access to these administrative services to only certain compartments of the
network or particular IP addresses. Firewalls, routers, and switches should be
implemented in a way to compartmentalize the server from unauthorized access.
Customer-managed applications
The telephony servers have been customized to provide telephony services under
the demands of telephony users. Additionally, high-availability has been a focus in
the design of the server architecture. As part of the effort to provide a server that
effectively works all of the time, Avaya has taken steps to remove software that is
not mission-critical or necessary for the normal operation of the server.
Incorporation of additional software (such as mail servers or virus scanners) and
use of installed software for purposed not intended by Avaya is strongly
discouraged.