Specifications
A31003-D3000-P100-01-76A9, 10-2013
OpenStage and Desk Phone IP SIP V3, Security Checklist, Planning Guide 11
Phone Hardening Measures at a Glance
Customer Deployment - Overview
Enable IEEE 802.1x in the network and at the phone by installing the
appropriate certifications
Use digest authentication
Interfaces / Ports
• Disable factory reset via hooded claw
• Enable remote trace only when needed
• Enable PC port only if really required
• Enable SSH access only if really required
• Disable OSCS / Phone Manager access if not required?
• Enable CSTA/ CTI access only if really required?
• Disable USB access if not needed?
• Disable WBM access if not needed?
• Enable SNMP only if required?
• Disable BlueTooth if not needed?
• Use TLS encryption for LDAP
XML Applications / Send URL?
• Do not configure XML applications if not needed?
• Use HTTPS for XML and Send URL applications
• Deploy Server CA Certificates and enable checking
The recommended measures are listed in the following chapters.
Related Topics