Specifications

SRTP-AES ShoreWare Server Release Notes
Page 78
SRTP-AES Description
System Support
ShoreTel 9 supports SRTP for encrypting, authenticating, and replaying media streams for
ShoreGear switches and ShorePhones that support encryption. ShoreWare encrypts RTP
(payload) packets sent within the ShoreTel network. Call control packets are not
encrypted. ShoreTel 9 retains the proprietary 128-bit encryption algorithm that is available
in previous version as an alternative to SRTP encryption.
Encryption is enabled or disabled on a system basis, encompassing all sites, and cannot be
specified for individual devices or selected calls. Encryption is transparent to end users and
cannot be selected for individual devices or calls. Calls in progress when the encryption
setting is changed remain the same encryption method through the duration of the call.
System administrators enable and select an encryption algorithm through ShoreWare
Director. The following encryption options are available:
None
128 bit ShoreTel Proprietary
SRTP - 128 bit AES
SRTP with AES and authentication has a significant impact on the system load when a large
number of media channels are encrypted.
SRTP-AES encryption is provided on all ShoreTel 9 systems and does not require an
additional license.
Devices
Switches and Codecs
SRTP encryption is supported by the following ShoreGear Voice Switches:
All Voicemail Model switches
All 1-U Half Width switches
All 1-U Full Width switches
Switches do not support SRTP with linear (LRNB/8000) or wide-band (LRWB/16000)
codecs. When SRTP is enabled, codec negotiation excludes these codecs.
ShoreGear switches support a maximum of 36 encrypted media streams. This limitation
potentially impacts switches that provide T1 or E1 channels with high 3-way conference
call traffic.
Each channel in a 3-way conference requires two media stream encryption resources,
limiting switches to 18 encrypted channels for 3-way conferences. In this scenario, all
remaining trunks provided by the switch are blocked while 18 channels are engaged in 3-
way conference calls. Switches can service any combination of two-way (one encrypted
media stream) and three-way (two encrypted media streams) calls that do not exceed 36
media streams. Analog ports on the SG-220T1A are included in this limitation.
Phones and Applications
All ShorePhones that run the ShoreTel 9 firmware support SRTP-AES. SoftPhone, which is
available through Call Manager, also supports SRTP-AES.