Specifications

Engineering Guidelines
350
Secure management interfaces
The 3300 ICP includes a fully integrated set of management tools designed to install, manage,
and administer 3300 ICP systems. Three levels of access are provided in order to meet the
needs of system technicians, group administrators, and the desktop telephony users
themselves. All of these integral management tools use Secure Socket Layer (SSL) security
for data encryption. User access to the management tools is controlled by a login and password.
Once a user logs into the 3300 ICP, the system displays a menu of the specific tools to which
they have been granted access. Mitel also offers the Management Access Point to provide
secure remote administration for VPN or dial-up access.
Multi-Level Precedence and Preemption (MLPP)
When the 3300 ICP is deployed in an environment that requires MLPP, it may be necessary
for security reasons to prevent external network devices from accessing certain IP ports that
are used by the 3300 ICP.
MLPP is a licensable option on the 3300 ICP. When MLPP is enabled, the ESM form "IP Port
Filter" can be used to enable blocking on specific IP ports.
When blocking is enabled on a specific IP port external network devices will be prevented from
accessing this port.
In the default state all IP ports are unblocked so access is unrestricted.
SIP Security
Mitel has a number of phones that support the Session Initiation Protocol (SIP). SIP is a
signalling protocol used for establishing and terminating IP phone calls. SIP signalling is not
encrypted; however, phones using SIP are authenticated before providing access to system
features.