
80 Matrix SETU ATA211G System Manual
Digest Authentication
Digest Authentication is a challenge-based authentication service of SIP to authenticate the identity of the
originator of SIP request in the INVITE message. The recipient of the request can ascertain whether or not the
originator of the request is authorised to make the request. When the digest credentials of the originator - User
Name and Password - in the INVITE message are authenticated and accepted by the recipient, the originator and
the recipient are connected.
SETU ATA211G supports Digest Authentication. The Digest Authentication feature works on the basis of the Digest
Authentication Table, in which the credentials, namely the User Name and Passwords of trusted/authorised calling
party SIP devices are stored. You must configure this table.
When you enable this feature on a SIP trunk, for all incoming calls (SIP requests),
• SETU ATA211G will challenge the identity of the calling party, i.e. the SIP device initiating the request to
send its digest credentials.
• When the calling party sends its credentials, SETU ATA211G authenticates the credentials by matching it
with its Digest Authentication Table.
• If a match is found, the calling party will be authenticated and the call will be allowed on the SIP trunk.
• If no match is found, SETU ATA211G will consider it as invalid authentication information and reject the
call.
You may use Digest Authentication to
• restrict access to SETU ATA211G to specific callers.
• prevent unwanted or malicious calls.
Let us understand Digest Authentication with the help of an example:
• A Company has its head office in Mumbai and branch offices in the cities of Kolkata, Chennai and New
Delhi.
• For voice communication over IP, the Company has installed SETU ATA211G in all its branches for making
Peer-to-Peer Calls. (For more details, refer “Peer-to-Peer Numbers” topic).
• The Company wants to use a SIP trunk for exclusively for inter-office calling.
• To be able to do this, the Company must do the following in all its branch offices:
• set the SIP Trunk mode of the desired SIP trunk to Peer-to-Peer mode, and configure Peer-to-Peer
Numbers
6
.
• enable Digest Authentication on this SIP Trunk.
• configure the Digest Authentication Table with the User Name and Password of the SIP devices of all
branches, from which calls are to be allowed on this SIP trunk. In this case, the User Name and
Password will be of the dedicated Peer-to-Peer SIP trunk in the branch offices. For example, in the
Digest Authentication Table, you configure at the Mumbai office, you must configure the User Name
6. Static IP address is assigned to the WAN port of all Gateways and the SIP trunks are set to Peer-to-Peer mode in all the offices.
Comentários a estes Manuais