Source record · tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html
- Published
- 2026-09-22
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- A SIP trunk security profile sets Device Security Mode to Non Secure, Authenticated (integrity and authentication) or Encrypted (integrity, authentication and signaling encryption). in context
- The default incoming port for SIP over TLS on a Unified CM SIP trunk security profile is 5061. in context
- SIP trunk security profiles have separate checkboxes to accept out-of-dialog REFER, unsolicited NOTIFY, and new dialogs with a Replaces header. in context
- If SRTP Allowed is checked on a trunk with a non-encrypted security profile, SRTP keys are exposed in signaling and traces; Cisco recommends an encrypted TLS profile. in context
- Two SIP trunks cannot share the same X.509 subject name and incoming port combination. in context
- Unified CM accepts incoming out-of-dialog REFER requests on a SIP trunk only when Accept Out-of-Dialog REFER is checked in the trunk's security profile. in context
- The Accept Replaces Header check box lets Unified CM accept new SIP dialogs that replace existing SIP dialogs on the trunk. in context
- Checking Enable Application Level Authorization also requires checking Enable Digest Authentication and configuring digest authentication for the trunk. in context
- After a security profile is assigned to a SIP trunk and saved, the trunk is reset with Apply Config. in context
- A SIP trunk security profile that is assigned to a device cannot be deleted. in context
- The Secure Certificate Subject or Subject Alternate Name field takes up to 4096 characters. Multiple names are separated by a space, comma, semicolon or colon. in context
- The SIP trunk security profile offers three device security modes: Non Secure (TCP or UDP, no encryption), Authenticated (TLS with NULL/SHA, integrity only) and Encrypted (TLS with AES128/SHA). in context
- When Enable Digest Authentication is checked in the SIP trunk security profile, Unified CM challenges all SIP requests from the trunk. in context
- In the SIP trunk security profile, the default incoming port is 5060 for TCP and UDP SIP messages and 5061 for TLS. in context
- The Incoming Port set in a SIP trunk security profile applies to every SIP trunk that uses that profile. in context
- The Incoming Port field of a SIP trunk security profile takes a port number from 0 to 65535. in context
- The incoming transport type follows the device security mode: TCP+UDP when the mode is Non Secure, and TLS when it is Authenticated or Encrypted. in context
- Inference: the incoming port belongs to the security profile and applies to every trunk that uses it, so the 5060 PSTN trunk and the 5065 Webex trunk to the same LGW need two different SIP trunk security profiles. inferred in context
- TLS SIP trunks and non-TLS SIP trunks cannot share the same incoming port. in context
- The default Nonce Validity Time in the SIP trunk security profile is 600 seconds (10 minutes). in context
- With a Non Secure device security mode the administrator chooses TCP or UDP as the outgoing transport. With Authenticated or Encrypted mode the outgoing transport is TLS. in context
- SIP trunks that use TLS can share one incoming port, and SIP trunks that use TCP+UDP can share one incoming port. in context
- The trunk security task flow in the Release 15 guide runs: set up secure gateways and trunks, set up the SIP trunk security profile, apply it, synchronize it with the SIP trunks, then allow SRTP. in context
Cite this source record
APA
WarmTransfer. (2026, September 22). Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-sip-trunk-security
BibTeX
@misc{warmtransfer-cisco-cucm-secguide-15-sip-trunk-security,
title = {Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-secguide-15-sip-trunk-security},
note = {Cisco Systems, accessed 2026-09-24}
}