Specifications

Matrix SETU ATA211 System Manual 83
Digest Authentication
Digest Authentication is a challenge-based authentication service of SIP to authenticate the identity of the
originator of SIP request in the INVITE message. The recipient of the request can ascertain whether or not the
originator of the request is authorised to make the request. When the digest credentials of the originator—User
Name and Password—in the INVITE message are authenticated and accepted by the recipient, the originator and
the recipient are connected.
SETU ATA211 supports Digest Authentication. The Digest Authentication feature works on the basis of the Digest
Authentication Table, in which the credentials, namely the User Name and Passwords of trusted/authorised calling
party SIP devices are stored. You must configure this table.
When you enable this feature on a SIP trunk, for all incoming calls (SIP requests),
SETU ATA211 will challenge the identity of the calling party, i.e. the SIP device initiating the request to
send its digest credentials.
When the calling party sends its credentials, SETU ATA211 authenticates the credentials by matching it
with its Digest Authentication Table.
If a match is found, the calling party will be authenticated and the call will be allowed on the SIP trunk.
If no match is found, SETU ATA211 will consider it as invalid authentication information and reject the call.
You may use Digest Authentication to
restrict access to SETU ATA211 to specific callers.
prevent unwanted or malicious calls.
Let us understand Digest Authentication with the help of an example:
A Company has its head office in Mumbai and branch offices in the cities of Kolkata, Chennai and New
Delhi.
For voice communication over IP, the Company has installed SETU ATA211 in all its branches for making
Peer-to-Peer Calls.
The Company wants to use a SIP trunk for exclusively for inter-office calling.
To be able to do this, the Company must do the following in all its branch offices:
set the SIP Trunk mode of the desired SIP trunk to Peer-to-Peer mode, and configure Peer-to-Peer
Numbers
8
.
enable Digest Authentication on this SIP Trunk.
configure the Digest Authentication Table with the User Name and Password of the SIP devices of all
branches, from which calls are to be allowed on this SIP trunk. In this case, the User Name and
Password will be of the dedicated Peer-to-Peer SIP trunk in the branch offices. For example, In the
Digest Authentication Table you configure at the Mumbai office, you must configure the User Name
and Password for the dedicated SIP trunks at the offices in Kolkatta, Chennai and New Delhi. Similarly,
8. Static IP address is assigned to the WAN port of all Gateways and the SIP trunks are set to Peer-to-Peer mode in all the offices.