Apply online

TLS/SRTP Encryption Setup

In this article

Introduction

At the end of this article, you should be able to set up and manage TLS/SRTP for your Yealink devices should you wish to use this service.

TLS/SRTP encryption setup

Transport Layer Security (TLS) is a security protocol designed to facilitate privacy and data security encrypting voice traffic. SRTP will prevent the media from malicious attack such as eavesdropping. In-order to subscribe to this feature, please contact our support team and request for TLS support to be enabled on your account.Once our support department has confirmed you have TLS enabled, you will be able to see your standard registration port number updated to 7061.

TLS2.JPG

Login to the web interface of the Yealink handset. Choose TLS as your transport protocol and update the port number of the server host field. Click on the confirm button and the device will be registered.

TSL3.JPG

Select the advanced option from the menu on the left and set RTP encryption (SRTP) as optional, as the image below shows.

TSL4.JPG

The final process is to update the enabled codecs list. Select the account tab and clicking on the codec from the menu on the left. Remove G722 from the enable codecs and then click on confirm, once completed test an outbound call.

TSL5.JPG

TLS troubleshooting

Should you have issues with calls failing to establish you will need to check the security settings on the handset. The most likely cause is the firmware on the device not including a full list of the trusted security certificateauthorities. To resolve this issue select the security tab and then trusted certificates, update the option to accept only trusted certifications. Don't forget to confirm your changes.

TSL6.JPG

A quick search will help you find answers to most of the FAQ's.
If you are unable to find a solution from the knowledge base centre, please contact your service provider for technical assistance.