Re: TLS/SRTP
Who AmI via sr-users <[email protected]> Tue, 30 Jun 2026 17:14:02 +0100
| Newsgroups | gmane.comp.voip.ser |
|---|---|
| Message-ID | <CAMX7=peWRG-oDU=yHDDR4bczz5dKOiTdW=NhkS8f0aD5LvQo+Q@mail.gmail.com> |
--===============0788364285== Content-Type: multipart/alternative; boundary="000000000000afac1506557addfd" --000000000000afac1506557addfd Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable We have customers who require TLS and some who don't support it at all. We support both by adding a different listener port and decrypt at the edge with everything behind it (private network as we NAT) unencrypted. Thanks, John. On Tue, 30 Jun 2026 at 17:10, alexis via sr-users < [email protected]> wrote: > maybe not for a local network, absolutely yes for a public one no matter > the acl/rule/firewall > > > El El mar, 30 jun 2026 a la(s) 12:57, asma.bouddyach--- via sr-users < > [email protected]> escribi=C3=B3: > >> Hi all, >> >> My Kamailio SBC (in front of 3CX,) currently runs SIP in clear text, no >> SRTP. Security is mainly IP-based ACLs: >> >> if ($si =3D=3D PBX_IP) { >> route(FROM_PBX); >> if ($si =3D=3D ITSP_IP_IN || $si =3D=3D ITSP_IP_OUT) { >> route(FROM_ITSP); >> >> What are the concrete risks of staying without TLS/SRTP in this setup, >> and would you still recommend encryption given these ACLs already in pla= ce? >> >> Thanks, >> Asmaa BOUDDYACH >> __________________________________________________________ >> Kamailio - Users Mailing List - Non Commercial Discussions -- >> [email protected] >> To unsubscribe send an email to [email protected] >> Important: keep the mailing list in the recipients, do not reply only to >> the sender! >> > __________________________________________________________ > Kamailio - Users Mailing List - Non Commercial Discussions -- > [email protected] > To unsubscribe send an email to [email protected] > Important: keep the mailing list in the recipients, do not reply only to > the sender! > --000000000000afac1506557addfd Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>We have customers who require TLS and some who don= 9;t support it at all.=C2=A0</div><div><br></div><div>We support both by ad= ding a different listener port and decrypt at the edge with everything behi= nd it (private network as we NAT) unencrypted.</div><div><br></div><div>Tha= nks,</div><div><br></div><div>John.=C2=A0</div></div><br><div class=3D"gmai= l_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Tue= , 30 Jun 2026 at 17:10, alexis via sr-users <<a href=3D"mailto:sr-users@= lists.kamailio.org">[email protected]</a>> wrote:<br></div><bl= ockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-lef= t:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"auto">maybe not = for a local network, absolutely yes for a public one no matter the acl/rule= /firewall=C2=A0</div><div dir=3D"auto"><br></div><div><br><div class=3D"gma= il_quote"><div dir=3D"ltr" class=3D"gmail_attr">El El mar, 30 jun 2026 a la= (s) 12:57, asma.bouddyach--- via sr-users <<a href=3D"mailto:sr-users@li= sts.kamailio.org" target=3D"_blank">[email protected]</a>> esc= ribi=C3=B3:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi a= ll,<br> <br> My Kamailio SBC (in front of 3CX,)=C2=A0 currently runs SIP in clear text, = no SRTP. Security is mainly IP-based ACLs:<br> <br> if ($si =3D=3D PBX_IP) {<br> =C2=A0 =C2=A0 route(FROM_PBX);<br> if ($si =3D=3D ITSP_IP_IN || $si =3D=3D ITSP_IP_OUT) {<br> =C2=A0 =C2=A0 route(FROM_ITSP);<br> <br> What are the concrete risks of staying without TLS/SRTP in this setup, and = would you still recommend encryption given these ACLs already in place?<br> <br> Thanks,<br> Asmaa=C2=A0 BOUDDYACH<br> __________________________________________________________<br> Kamailio - Users Mailing List - Non Commercial Discussions -- <a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]= .org</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]= ilio.org" target=3D"_blank">[email protected]</a><br> Important: keep the mailing list in the recipients, do not reply only to th= e sender!<br> </blockquote></div></div> __________________________________________________________<br> Kamailio - Users Mailing List - Non Commercial Discussions -- <a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]= .org</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]= ilio.org" target=3D"_blank">[email protected]</a><br> Important: keep the mailing list in the recipients, do not reply only to th= e sender!<br> </blockquote></div> --000000000000afac1506557addfd-- --===============0788364285== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline __________________________________________________________ Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected] To unsubscribe send an email to [email protected] Important: keep the mailing list in the recipients, do not reply only to the sender! --===============0788364285==--