Skip to main content

Communications Server environment. How to secure?

As (UC) unified communications are getting to become much more popular, it has become apparent that unified communications networks are prone to many of the same types of security threats as normal TCP/IP networks. Some of the more common threats include things like spam directed at instant messaging, man-in-the-middle attacks, denial-of-service attacks, sniffing and the list goes on.

Unfortunately, there is no way that I can possibly provide even a high-level overview of unified communications security within the confines of an article. There are simply too many aspects of the unified communications infrastructure that would need to be addressed. That being the case, I want to focus my attention on one particular component that I think deserves some of the most attention: the Office Communications Server (OCS) edge server.

The edge server allows OCS to be accessible to the outside world. The OCS edge server is placed in the network's demilitarized zone and proxies requests between the Internet and the back-end network. The reason why I want to talk about the edge server is because it is exposed to the Internet.

Install the appropriate roles

The first suggestion I would make is that you install the appropriate roles on your edge server. An edge server actually supports three different roles. You can install one, two or all three roles. Installing roles that are not needed can constitute a security risk.

The three roles are:

Access Edge: Allows external users to authenticate into the OCS deployment.

A/V Edge: Allows external users to take advantage of the network's audio and video capabilities from outside the organization.

Web Conferencing Edge: Allows external users to participate in Web conferences.

Be careful with how you enable 'federation'

In an OCS environment, federation refers to the way in which your OCS infrastructure is exposed to the outside world. When you initially configure the edge server, there is a setup wizard screen called the Enable Features on Access Edge Server screen that allows you to choose whether or not you want to allow anonymous users to join meetings, and whether or not you want to enable federation.

Although it is not exactly spelled out on this screen, there are three types of federation you can use. The first type that OCS allows is called direct federation. Direct federation is basically a trust relationship between two organizations. The organizations would have made an agreement to share presence information with each other, and to support the use of direct collaboration between the two organizations. With this type of federation, the participants use digital certificates to positively verify each other's identities.

The second type of federation that is available is something called enhanced federation. Enhanced federation (sometimes called open federation) is enabled through the Enable Features on Access Edge Server screen that I described earlier. By selecting the Allow Discovery of Federation Partners check box, you allow users to communicate with users in other organizations that also run OCS or Live Communications Server. What makes this different from direct federation is that there is not a direct trust between organizations, but rather an open trust that allows communication with any external OCS or LCS organization.

The third type of federation is called federation with public instant messaging providers. Once again, this type of federation is activated through the Enable Features on Access Edge Server screen. The screen contains check boxes administrators can use to enable federation with MSN, Yahoo and AOL instant messaging.

None of these types of federation are necessarily dangerous to use, but they do give your organization varying degrees of exposure. It is therefore important to choose the federation type that fits your plans for unified communications. Of course if you only want to use OCS as an internal communications mechanism then you don't have to enable federation at all.

In this article, I have explained that one of the most important tasks in protecting your unified communications network is controlling access to it from the outside world. This is important, because sensitive information is often passed through unified communications networks, and you do not want to accidentally expose your unified communications network to the world.

From searchcio-midmarket.com

Comments

Popular posts from this blog

Want To Get Answering Machine For Your IM?

Computer's personal often face problems when they have to take a break from their PC for some time and can’t answer to emails and instant messages. Actually, for email you can set up an autoresponder if you use Outlook software, and there’s a way out for gmail, too. But what can you do with your instant messenger? I have a lot of IM accounts for any purposes with different people in each account. So what utility can tell these people that I am out on a vacation or down with fever? Answer.im comes to the rescue by setting up an automated web based answering machine for your instant messenger. It works with MSN, ICQ, AIM, Yahoo and Google Talk as of now. How it Works Setting it up is very simple. First, hop over to http://answer.im/. Then, select your IM network (like GTalk, Yahoo, etc). Fill in your username and password and hit Login. Features Now, you can customize your automated reply and select the status you would like your account to remain at. Since the service is web based, ...

Durov: The phone of the richest man in the world was hacked through WhatsApp.

The founder of "VKontakte" and Telegram Pavel Durov said that back in November 2019 he warned about the vulnerability of the WhatsApp application, through which hackers hacked the smartphone of the richest man on the planet Jeff Bezos. Durov wrote about it in his Telegram-channel. Earlier, the company Facebook, which owns WhatsApp, noted that the businessman's mobile phone was hacked because of vulnerabilities in the operating system from Apple. At the same time, Durov is convinced that the problem is not iOS. " WhatsApp in its marketing campaign uses the words 'end-to-end encryption' as a magic spell, which itself should ensure the security of all communications. But this technology alone cannot guarantee absolute confidentiality," says the founder of Telegram. One of the drawbacks of end-to-end encryption, he says, is that backups of transmitted data are often not encrypted. In addition, says Durov, each application has "ways around...

Primus to Provide VoIP for MSN Messenger

Primus Telecommunications Group, Inc. has entered into an agreement with Microsoft Corp. to provide Voice-over-Internet Protocol (VoIP) services for MSN Messenger Service customers. Marketed as "PrimusTalk," once a user has logged into MSN Messenger Service, calls can be made by clicking on the "Make a Phone Call" link. A phone dialer will appear where a call can be made to any number -- national, international or mobile. The McLean, Va.-based Primus will provide PrimusTalk service as an Internet telephony application that can be accessed by any user accessing MSN Messenger Service. Specifically, the PC-to-phone service will be integrated with the MSN Messenger Service as an option that may be accessed by users of Microsoft client software programs. "Primus is leading the way to a carrier class era of converged communications solutions," said John Melick, co-president of Primus and one of the principal developers and implementers of the company's VoIP ...