Operation Manual

Administration
A31003-C1000-M102-5-76A9, 09/2017
62 OpenScape Desk Phone CP200/CP205/CP400/CP600 HFA, Administration Manual
administration.fm
IP Network Parameters
3.3.7 Configuration & Update Service (DLS)
The OpenScape Deployment Service (DLS) is a OpenScape Management Application for ad-
ministering workpoints. Amongst the most important features are: security (e.g. PSS genera-
tion and distribution within an SRTP security domain), mobility for OpenScape phones, soft-
ware deployment, plug&play support, as well as error and activity logging.
DLS address, i.e. the IP address or hostname of the DLS server, and Default mode port, i.e.
the port on which the DLS server is listening, are required to enable proper communication be-
tween phone and DLS. The Contact gap parameter controls a security function. It specifies a
minimum time interval that must elapse between individual HTTP requests from the phone
which are responding to a ContactMe request from the DLS. Any requests coming within that
time will be ignored. The purpose is to prevent DoS (Denial of Service) attacks on the phone.
Set Revert to default security to disable mutual authentication and return to DEFAULT mode.
SECURE mode related settings are reset and certificates are removed.
The Mode determines whether the communication between the phone and the DLS is secure.
A secure connection is established by exchanging credentials between the DLS and the phone
for mutual authentication. After this, the communication is encrypted, and a different port is
used.
A Security PIN can be provided which is used for decrypting data provided by the DLS during
bootstrap. For further information, please refer to the DLS documentation.
>
The additional WBM and DLI are alternative administration tools. DLI uses the same
technical inferface like DLS, but with less functionality.
>
It is possible to operate the DLS server behind a firewall or NAT (Network Address
Translation), which prevents the DLS from sending Contact-Me messages directly to
the phone. Only outbound connections from the phone are allowed. To overcome
this restriction, a DLS Contact-Me proxy (DCMP) can be deployed. The phone peri-
odically polls the DCMP (DLS Contact- Me Proxy), which is placed outside of the
phone’s network, for pending contact requests from the DLS. If there are contact re-
quests, the phone will send a request to the DLS in order to obtain the update, just
as with a regular DLS connection.
>
The URI of the DCMP, as well as the polling interval, are configured by the DLS. For
this purpose, it is necessary that the phone establishes a first contact to the DLS,
e. g. by phone restart or local configuration change.