Unified Messaging servers that have Exchange Server 2007 SP1 installed can communicate with IP gateways, IP PBXs, and other Exchange 2007 computers in either Unsecured, SIP Secured, or Secured mode, depending on how the UM dial plan is configured. A Unified Messaging server can operate in any mode that is configured on a dial plan because the Unified Messaging server is configured to listen on TCP port 5060 for unsecured requests and TCP port 5061 for secured requests at the same time. A Unified Messaging server can be associated with a single or multiple UM dial plans and can be associated with dial plans that have different VoIP security settings. A single Unified Messaging server can be associated with dial plans that are configured to use a combination of Unsecured, SIP Secured, and Secured modes.
By default, when you create a UM dial plan, it will communicate in Unsecured mode and the Unified Messaging servers that are associated with the UM dial plan will send and receive data from IP gateways, IP PBXs and other Exchange 2007 computers without using encryption. In Unsecured mode, neither the RTP media channel nor the SIP signaling information will be encrypted.
You can configure a Unified Messaging server to use MTLS to encrypt the SIP and RTP traffic that is sent and received from other devices and servers. When you add a Unified Messaging server to a UM dial plan and configure the dial plan to use SIP Secured, only the SIP signaling traffic will be encrypted and the RTP media channels will still use TCP, which is not encrypted. However, if you add a Unified Messaging server to a UM dial plan and configure the dial plan to use Secured mode, both the SIP signaling traffic and the RTP medial channels are encrypted. An encrypted signaling media channel that uses SRTP also uses MTLS to encrypt the VoIP data.
You can configure the VoIP security mode either when you are creating a new dial plan or after you have created a dial plan by using the Exchange Management Console or the Set-UMDialPlan cmdlet. When you configure the UM dial plan to use SIP Secured or Secured mode, the Unified Messaging servers that are associated with the UM dial plan will encrypt the SIP signaling traffic or the RTP media channels or both. However, to be able to send encrypted data to and from a Unified Messaging server, you must correctly configure the UM dial plan and devices such as IP gateways or IP PBXs must support MTLS.
For more information about VoIP security and UM dial plans, see Understanding Unified Messaging VoIP Security.