PDA

View Full Version : Secure VTC's over SIPRNET


williamsdav
12-15-2005, 11:27 PM
I have 1 Secure VTC cart which uses KIV and ISDN. I have recently been tasked with supply 6 more Carts in 6 different cities. This type of setup is costly. After digging deeper, I started doing Secure VTC test thru SIPRNET circuits....just using a dumb IP unit such as a cheap Polycom VSX 7000. (Cheap compared to a full blown cart with KIV and ISDN bills to pay!!!) It worked great and there are bridges out there (3rd Army and others) on the SIPRNET than can get you connected over to an ISDN call. If your SIPRNET circuit is only 128 or 256K, it makes more sense to pay for the upgrade to 384k or 512k than to pay for a single function ISDN circuit, plus you have more bandwidth for your SIPRNET computers. - Polycom has fielded an new control module for the MGC-50 and MGC-100 MCU's that has a removable hard drive so you can go secure on your bridge if you own one. Just run SIPRNET to conference room in a hoffman box...use when needed...otherwise keep endpoint connected to your LAN for non-secure VTC's

Entropy3XD
12-15-2005, 11:43 PM
Williamsdav,

You should keep a few things in mind if you are plugging in secure and non secure LAN connections to a single codec, specifically if you are unhooking from SIPRNET to go unclass. When you do this you will basically need to wipe the codec of all of its information before you go unclass. This means all IP information, call history & logs, address books, etc. If you do not do this BEFORE you go unclass, you risk having classified IP information on your codec while on an unclass network. There are devices out there which can automate this process (depending on the codec), but I do not wish to turn this thread into a sales pitch. Just keep in mind that there is a ton of information on your codec which can result in a security breach when going from secure to non-secure. There are also some processes you should go through before you plug your equipment into SIPRNET. You should really talk to your comsec personel before doing so, if you haven't already.

williamsdav
12-16-2005, 08:22 AM
Thanks....already done that. Your right though....It is easier to leave it as a secure VTC only but it will work switching between the 2 with caution. The process to add an IP unit to the SIPRNET is easy but does need to be done. I have found that on the VSX-7000 menu, there is an option to reset the system which wipes all of that info. I also lock down the unit so that users can't view the call log, recent calls, and directory. They must enter the IP address manually to dial out.

Actually, in my case I'm switching between SIPRNET (Secure Classified) to SBU (Secure but Unclassified).

I would like to know about your device....please email me at williamsdav@yahoo.com

Vtech
02-21-2006, 10:12 AM
Criticom has a optical switch that is JITC approved that will do the system wipe and change the configuration for you. It costs about $13K and can be integrated into an AMX or Crestron system if needed. www.criticom.com if you need the federal sales contact let me know.