Cisco Systems IP Phone OL 8356 01 User Manual

C H A P T E R  
9
Phone Hardening  
To tighten security on the phone, you can perform tasks in the Phone Configuration window in  
Cisco CallManager Administration. This chapter contains information on the following topics:  
Disabling the Gratuitous ARP Setting  
By default, Cisco IP Phones accept Gratuitous ARP packets. Gratuitous ARP packets, which devices  
use, announce the presence of the device on the network. However, attackers can use these packets to  
spoof a valid network device; for example, an attacker could send out a packet that claims to be the  
default router. If you choose to do so, you can disable Gratuitous ARP in the Phone Configuration  
window of Cisco CallManager Administration.  
Note  
Disabling this functionality does not prevent the phone from identifying its default router.  
Disabling Web Access Setting  
Disabling the web server functionality for the phone blocks access to the phone internal web pages,  
which provide statistics and configuration information. Features, such as Cisco Quality Report Tool, do  
not function properly without access to the phone web pages. Disabling the web server also affects any  
serviceability application, such as CiscoWorks, that relies on web access.  
To determine whether the web services are disabled, the phone parses a parameter in the configuration  
file that indicates whether the services are disabled or enabled. If the web services are disabled, the  
phone does not open the HTTP port 80 for monitoring purposes and blocks access to the phone internal  
web pages.  
Cisco CallManager Security Guide  
OL-8356-01  
9-1  
 
   
Chapter 9 Phone Hardening  
Configuring Phone Hardening  
Configuring Phone Hardening  
Caution  
The following procedure disables functionality for the phone.  
To disable functionality for the phone, perform the following procedure:  
Procedure  
Step 1  
Step 2  
Step 3  
Step 4  
In Cisco CallManager Administration, choose Device > Phone.  
Specify the criteria to find the phone and click Find or click Find to display a list of all phones.  
To open the Phone Configuration window for the device, click the device name.  
Locate the following product-specific parameters:  
PC Port  
Settings Access  
Gratuitous ARP  
PC Voice VLAN Access  
Web Access Setting  
Tip  
To review information on these settings, click the question mark that displays next to the  
parameters in the Phone Configuration window.  
Step 5  
From the drop-down list box for each parameter that you want to disable, choose Disabled. To disable  
the speakerphone or speakerphone and headset, check the corresponding check boxes.  
Step 6  
Step 7  
Click Save.  
Click Reset.  
Additional Information  
Where to Find More Information  
Related Topics  
Cisco CallManager Security Guide  
OL-8356-01  
9-3  
 
     
Chapter 9 Phone Hardening  
Where to Find More Information  
Related Cisco Documentation  
Cisco IP Phone Administration Guide for Cisco CallManager  
Cisco CallManager Security Guide  
OL-8356-01  
9-4  
 

Blaupunkt Car Stereo System Verona C51 User Manual
Blodgett Range B36 COMBOS User Manual
Bosch Appliances Smoke Alarm FAS 420 TM User Manual
Bose Cell Phone Accessories AM316766 User Manual
Briggs Stratton Portable Generator 30381 User Manual
Brother All in One Printer Multi Protocol Print Server User Manual
Cary Audio Design Stereo Amplifier SLP 03 User Manual
Castelle Fax Machine FaxPress User Manual
Channel Vision DVR 43G User Manual
Chicago Electric Indoor Fireplace 91797 User Manual