Specifications

A31003-D3000-P100-01-76A9, 10-2013
OpenStage and Desk Phone IP SIP V3, Security Checklist, Planning Guide 25
Phone Hardening Measures
Secure Interfaces and Services to the Phone
Related Topics
4.6.4 Remote Call Control (CSTA)
Call Setup is possible by remote CTI clients running on a PC or server. The call
control is performed using CSTA and uaCSTA protocol in SIP messages from the
SIP server.
It is possible for this to be used in a malicious way and the service should only be
enabled where needed. A CTI service allowed/not allowed setting is available at
Admin level to control this
When the CTI service is allowed then the user can choose to use auto answer or
not. Setting auto answer to off will prevent unwanted automatic answering of calls
setup by a remote client - for example for phones in conference rooms or public
areas. When Auto Answer is configured off then each call will be presented to the
user, and the user must accept the call before it is answered.
Table: SIP Secure Signalling
Disable USB Backup /
Restore
Yes: No:
Customer Comments and
Reasons
CL-SIP Secure Signal-
ling
Measures Set CTI Service to Disallow if not needed
Set Auto Answer to No if not needed
References See Phone Administration Manual chapter on Feature
Access?
See Phone User Guide chapter on Enhanced phone func-
tions -> incoming calls -> CTI calls
Can be done via
Needed Access Rights Administrator
Executed
If CSTA feature is not
used then set CTI control
to disallow?
Yes: No:
CL-USB port