1-13
Cisco Unified IP Phone 7965G and 7945G Administration Guide for Cisco Unified Communications Manager 6.0
OL-12650-01
Chapter 1 An Overview of the Cisco Unified IP Phone
Understanding Security Features for Cisco Unified IP Phones
Related Topics
• Understanding Security Profiles, page 1-14
• Identifying Encrypted and Authenticated Phone Calls, page 1-14
• Device Configuration Menu, page 4-12
• Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-16
• Security Restrictions, page 1-18
CAPF (Certificate Authority
Proxy Function)
Implements parts of the certificate generation procedure that are too
processing-intensive for the phone, and it interacts with the phone
for key generation and certificate installation. The CAPF can be
configured to request certificates from customer-specified
certificate authorities on behalf of the phone, or it can be configured
to generate certificates locally.
Security profiles Defines whether the phone is nonsecure, authenticated, or
encrypted. See the
“Understanding Security Profiles” section on
page 1-14 for more information.
Encrypted configuration files Lets you ensure the privacy of phone configuration files.
Optional disabling of the web
server functionality for a phone
You can prevent access to a phone’s web page, which displays a
variety of operational statistics for the phone.
Phone hardening Additional security options, which you control from
Cisco
Unified Communications Manager Administration:
• Disabling PC port
• Disabling Gratuitous ARP (GARP)
• Disabling PC Voice VLAN access
• Disabling access to the Setting menus, or providing restricted
access that allows access to the User Preferences menu and
saving volume changes only
• Disabling access to web pages for a phone.
Note You can view current settings for the PC Port Disabled,
GARP Enabled, and Voice VLAN enabled options by
looking at the phone’s Security Configuration menu. For
more information, see the
“Device Configuration Menu”
section on page 4-12.
802.1X Authentication The Cisco Unified IP Phone can use 802.1X authentication to
request and gain access to the network. See the
“Supporting 802.1X
Authentication on Cisco Unified IP Phones” section on page 1-16
for more information.
1. CAPF = Certificate Authority Proxy Function
Table 1-3 Overview of Security Features (continued)
Feature Description