Avaya IP PBX

Opinion
Jun 24, 20044 mins

* The Reviewmeister looks at configurations from Avaya for his test of IP PBX security

Avaya submitted two configurations for our test of IP PBX security: A no-frills, out-of-the-box Avaya IP telephony deployment with no extra-priced security options; and a maximum-security alternative – featuring the same VoIP gear, but with an added firewall and Layer 2/Layer 3 infrastructure switches from Extreme Networks.

Security weaknesses earned the basic Avaya configuration a so-so rating, while the hardened package fared better.

The first configuration Avaya submitted for security assessment had a minimal network infrastructure. In fact, there was no Layer 3 network infrastructure at all. All IP communications traversed a single, flat, switched Layer 2 network, segregated into two isolated virtual LANs, one for voice and the other for data. No firewalls were employed.

Despite this minimal network infrastructure, the Avaya VoIP package does feature various inherent security mechanisms. However, the Avaya topology call-control information is not encrypted, and the passwords used for IP phone authentication are not very strong.

Our hackers learned quite a bit by querying Avaya’s IP phones via SNMP, using the universal default SNMP community name “public.” But the phones could not be reconfigured, disabled or otherwise exploited via SNMP sets (writes).

Avaya took home the lessons it learned from the first round and returned with a more hardened, more secure configuration.

Officially, Avaya says its IP-telephony package is switch-agnostic, with regard to the Layer 2 and Layer 3 equipment that underlies the VoIP infrastructure. So the Avaya Cajun P333 switch employed in the first test round was replaced in the second round with Layer 2/Layer 3 switches from Extreme, with which Avaya partners.

The key new components, all additions to the network infrastructure, included: an Avaya SG208 Security Gateway ($15,000); an Extreme Summit 300-48 Layer 2/Layer 3 switch ($8,000); and an Extreme Alpine 3804 Layer 3 switch ($10,000). The Avaya VoIP equipment was unchanged. In fact, the same software loads were run in this retest.

Architecturally, the addition of Layer 3 IP routing and other key configuration changes prevented the type of attack that was developed in the first test round, where a rogue hacker computer directly assaulted other IP phones.

The SG208 firewall was configured to let only traffic of specific ports pass to and from the call-control equipment. Only traffic within a narrow, specific UDP port range was allowed to pass to the media processing module, and only the ports and protocols associated with Avaya’s H.323-based call-control signaling were passed to the CLAN module. It didn’t take the hackers long, with straightforward techniques, to figure out which ports were open. Their surveillance confirmed that call processing was H.323, and that meant certain ports had to be in use. And using borrowed real-phone IP identities, they were able to contact the call-control infrastructure and get responses.

For the full report, go to https://www.nwfusion.com/reviews/2004/0524voipsecurity.html

WANTED:

Enterprise networks that need all-in-one security protection for remote sites or branch office

Network World is embarking on a comprehensive test of blended security appliances that at least comprise traditional firewall functionality, some content-based IPS technology (such as malicious URL blocking and protocol anomaly blocking) built-in, Site-to-site IPSec VPN capabilities and policy-based content management, such as virus scanning or URL filtering.

Devices under test will be tested in both a lab setting as well on live network connections.  We are looking for volunteer sites to deploy these test units for a minimum of 30 days.  Requirements for participating in this test as a volunteer site are:

* A T-1-style Internet connection (not DSL or cable unless it’s symmetrical DSL at T-1 speeds). 

* The number of users being protected by this blended security device should range from 10 to 200. 

* A willingness to let a security consultant from Network World assist in management (i.e., look at settings, logs, etc.) of the blended device. Please note that we are not asking volunteers to cede actual control of security policy or decisions.

* Minimum commitment of 30 days between July and August 2004.

Volunteers will have full access to testing data on all 10-12 products tested.

Interested parties need to contact Christine Burns at cburns@nww.com by June 30th.

Neal Weinberg

Neal Weinberg is an experienced technology journalist with in-depth knowledge of cybersecurity, networking, cloud, wireless, IoT, IT careers, AI, robotics, digital transformation, and self-driving vehicles. Before becoming a freelance writer, he spent 17 years as executive features editor for NetworkWorld. Prior to his time at NetworkWorld, Neal was business editor at Middlesex News. He studied at the University of Massachusetts in Amherst. His work has been published in Tech Target, Information Week, Robotics Business Review, and other publications.

More from this author