User`s guide

Administrator’s Guide for Polycom HDX Systems
8–24 Polycom, Inc.
To enable AES encryption:
1 Do one of the following:
In the local interface, go to System > Admin Settings > General >
Security > Security Settings (select if necessary).
In the web interface, go to Admin Settings > General > Security >
Security Settings.
2 Enable AES Encryption.
If encryption is enabled on the system, a locked padlock icon appears on
the monitor when a call is encrypted. If a call is unencrypted, an unlocked
padlock appears on the monitor. In a multipoint call, some connections
might be encrypted while others are not. The padlock icon might not
accurately indicate whether the call is encrypted if the call is cascaded or
includes an audio-only endpoint. To avoid security risks, Polycom
recommends that all participants communicate the state of their padlock
icon verbally at the beginning of a call.
Configuring Encryption Settings for Integration with Microsoft Office
Communications Server 2007 R2 and Microsoft Lync Server 2010
Polycom HDX systems use the SRTP standard to support media encryptions
in calls with Office Communicator. The encryption settings for each
component also affect the ability to place encrypted calls.
Both the Microsoft Office Communications Server or Lync Server pool and the
Polycom HDX system need to be configured to support encryption in order for
calls to connect with encryption. If both components have encryption turned
off, calls connect without encryption. If one component is set to require
encryption and the other is not, calls fail to connect.
Calls from a Polycom HDX system to a Polycom RMX system using Microsoft
Office Communications Server or Microsoft Lync Server require that the
Polycom HDX system have encryption set to When Available
For more information about encryption configuration in a Microsoft Office
Communications Server or Microsoft Lync Server environment, refer to the
Polycom Unified Communications Deployment Guide for Microsoft Environments.
Points to note about AES Encryption:
AES Encryption is not supported in Diagnostic Mode.
AES Encryption is not supported on systems registered to an Avaya H.323
gatekeeper.
For Polycom HDX systems with a maximum speed of 6 Mbps for unencrypted
calls, the maximum speed for encrypted SIP calls is 4 Mbps. The maximum
speed for encrypted calls with Security Mode enabled is also 4 Mbps.
Polycom HDX systems negotiate AES-256 and AES-128 in H.323 and SIP calls
with other HDX systems.