Configuring The SBC For Ip Office Remote Worker
Configuring The SBC For Ip Office Remote Worker
September 2013
Avaya grants you a license within the scope of the license types
described below, for which the scope of the license is detailed below.
Where the order documentation does not expressly identify a license
type, the applicable license will be a Designated System License. The
applicable number of licenses and units of capacity for which the
license is granted will be one (1), unless a different number of licenses
or units of capacity is specified in the documentation or other materials
available to you. Designated Processor means a single stand-alone
computing device. Server means a Designated Processor that hosts
a software application to be accessed by multiple users.
Licence types
Designated System(s) License (DS). End User may install and use
each copy of the Software only on a number of Designated Processors
up to the number indicated in the order. Avaya may require the
Designated Processor(s) to be identified in the order by type, serial
number, feature key, location or other specific designation, or to be
provided by End User to Avaya through electronic means established
by Avaya specifically for this purpose.
Concurrent User License (CU). End User may install and use the
Software on multiple Designated Processors or one or more Servers,
so long as only the licensed number of Units are accessing and using
the Software at any given time. A Unit means the unit on which Avaya,
at its sole discretion, bases the pricing of its licenses and can be,
without limitation, an agent, port or user, an e-mail or voice mail account
in the name of a person or corporate function (e.g., webmaster or
helpdesk), or a directory entry in the administrative database utilized
by the Software that permits one user to interface with the Software.
Units may be linked to a specific, identified Server.
Database License (DL). End User may install and use each copy of the
Software on one Server or on multiple Servers provided that each of
the Servers on which the Software is installed communicates with no
more than a single instance of the same database.
CPU License (CP). End User may install and use each copy of the
Software on a number of Servers up to the number indicated in the
order provided that the performance capacity of the Server(s) does not
exceed the performance capacity specified for the Software. End User
may not re-install or operate the Software on Server(s) with a larger
performance capacity without Avayas prior consent and payment of an
upgrade fee.
Named User License (NU). You may: (i) install and use the Software
on a single Designated Processor or Server per authorized Named
User (defined below); or (ii) install and use the Software on a Server so
long as only authorized Named Users access and use the Software.
Named User, means a user or device that has been expressly
authorized by Avaya to access and use the Software. At Avayas sole
discretion, a Named User may be, without limitation, designated by
name, corporate function (e.g., webmaster or helpdesk), an e-mail or
voice mail account in the name of a person or corporate function, or a
directory entry in the administrative database utilized by the Software
that permits one user to interface with the Software.
Shrinkwrap License (SR). You may install and use the Software in
accordance with the terms and conditions of the applicable license
agreements, such as shrinkwrap or clickthrough license
accompanying or applicable to the Software (Shrinkwrap License).
Heritage Nortel Software
Heritage Nortel Software means the software that was acquired by
Avaya as part of its purchase of the Nortel Enterprise Solutions
Business in December 2009. The Heritage Nortel Software currently
available for license from Avaya is the software contained within the list
of Heritage Nortel Products located at http://support.avaya.com/
LicenseInfo under the link Heritage Nortel Products. For Heritage
Nortel Software, Avaya grants Customer a license to use Heritage
Nortel Software provided hereunder solely to the extent of the
authorized activation or authorized usage level, solely for the purpose
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Copyright
Downloading Documentation
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Contents
Chapter 1: Overview........................................................................................................... 7
Remote access......................................................................................................................................... 7
Licencing................................................................................................................................................... 7
Remote Worker best practices.................................................................................................................. 8
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
Chapter 1: Overview
The Avaya Session Border Controller for Enterprise (SBCE) delivers security to a SIP-based Unified
Communications network. This document describes how to configure the SBCE for IP Office Remote
Workers.
Remote access
When the SBCE is in an IP OFFICE Solution registration and remote access to the SBCE is
done jointly with IP Office. Remote access is thru the SSL VPN on the IP OFFICE and hopping
to the SBCE. For more information, see the document ASBCE GRT Registration and Remote
Connectivity via IP Office SSL/VPN NAPT on support.avaya.com.
Licencing
Licensing takes place once the SBCE is on the network and in the Commissioned state.
Retrieval and activation of licensing for Avaya SBCE is done via Avayas PLDS (Product
Licensing and Distribution System). Access to PLDS is via the Avaya Support Portal at the
URL https://plds.avaya.com.
For the SBCE, the SBCE EMS element is its own license hst for licensing specific to the SBCE.
Licensing is managed for SBCE within PLDS by a user-defined host name and the MAC
address of the management interface. ecide on a user defined license host name for the SBCE
at the physical site. This will be the license host name used to activate SBCE licenses in
PLDS.
On the SBCE, run the command ifconfig to determine the MAC address of the management
network interface.
The MAC address of the management interface of the Portwell CAD is the Eth5 port.
For a single Dell server deployment, the management interface MAC address is the Eth
5 port.
The license file for the SBCE must be uploaded so that Avaya Services can provide support
for what the customer is licensed for. Customers are still under the EULA for their license just
like in prior releases. After activating the license on PLDS and getting the XML file via emal,
use the SBCE management interface to upload and install the license.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
Overview
SRTP Audio
SRTP Video
Flare Experience
for IP Office R1.1.4
(Windows version)
Flare Experience
for IP Office R1.1.2
(iPad version)
one-X Mobile
Preferred VoIP
client for Android
one-X Mobile
Preferred VoIP
client for iOS
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Client type
SRTP Audio
SRTP Video
If the mobile client using TLS and/or SRTP will be used to roam from the network on
the ASBCE's external interface to the network on the IP Office side of the ASBCE, the
transport medium will have to be changed while the mobile client is connected to the
network on the IP Office side. IP Office 9.0 does not support direct SRTP connections
to these mobile clients and TLS is ONLY supported on the OneX Mobile Preferred
VOIP Client for Android.
If Media or Signaling QoS are required, they must be configured on the SBCE as the
SBCE does not pass through.
Customer firewall configuration requires forwarding of video/audio signaling and media
ports. SIP ALGs should be disabled on any firewalls.
For troubleshooting the best rules to follow are to look at Alarms/Incidents and take a
packet capture to determine if the issue is on the SBCE. If further debugging is required,
enable debug logs and get the appropriate elogs.
If doing remote worker and trunking on the same SBCE, you use a second set of IP
addresses on the SBCE for trunking. See the SBCE documentation and application notes
on configuring SBCE for trunking.
Review SBCE, IP Office, and endpoint release notes for fixes, limitations, and
workarounds.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
Overview
10
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Network interfaces
The example below shows a two wire deployment of a Dell Session Border Controller for
Enterprise (SBCE) in a demilitarized zone (DMZ). It is common to have only an external firewall,
but it is possible to have a firewall on both sides of the DMZ. For a description of the distinction
between one and two wire deployments, see Avaya Session Border Controller for Enterprise
Overview and Specification.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
11
Since the Portwell CAD has fewer interfaces, M2 or B2 are not listed on the back. M1,
A1, and B1 are the ports used on Portwell SBC hardware as well. All network interfaces
on the SBC are auto negotiate, so the switch or router ports that the SBC connects to
must also be set to auto negotiate.
Creating a backup
Backup the empty SBCE configuration. This enables you to start again from scratch.
Procedure
1. Login to the SBCE Control Center as Admin.
2. In the navigation tree on the left, select Backup/Restore and then select the
Snapshots tab.
3. Click Create Snapshot.
4. Enter a description and then click Create.
5. Click Download and save the file locally.
Next steps
When you have finished the configuration, create another snapshot. See Administering Avaya
Session Border Controller for Enterprise for a procedure to configure automatic backup to an
SFTP server.
12
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Network Management.
3. Select the Network Configuration tab.
4. Enter the IP address you are natting in the Public IP field.
The SBC will nat the SIP messages with the IP address.
Enabling interfaces
Enable the interfaces A1, internal to the IP Office, and B1, external to the phones, that were
configured during installation. If configuring a one-wire deployment, you will only enable A1.
For Portwell CAD hardware, B2 and M2 do not exist.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Network Management.
3. Select the Interface Configuration tab.
4. Enable the required interfaces.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
13
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Media Interfaces.
3. Click Add.
4. Enter the name for internal interface and then select the A1 IP address from the pull
down menu.
5. Enter the media port range and click Finish.
The default port range used is 35000-40000.
6. Click Add.
7. Enter the name for external interface and then select the B1 IP address from the
pull down menu.
8. Enter the media port range and click Finish.
The default port range used is 35000-40000.
14
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
TCP port 5060 is the required transport for remote workers on IP Office.
7. Click Add.
8. Enter the name for external interface and the select the B1 IP address from the pull
down menu.
9. For the transport to be used on that interface, put in the port in the chosen transport
field or fields and click Finish.
TCP port 5060 is the required transport for remote workers on IP Office.
10. TLS port 5061 is the preferred transport for remote worker towards the Avaya
endpoints if the endpoint supports it. If using TLS, select the default Avaya TLS
server profile on the external interface. If the endpoint doesnt support TLS, then
use TCP and look at the IP Office remote worker guides for Flare and one-X Mobile
clients for information on protocols to use.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Global Profiles.
3. Select Server Interworking.
4. The profile used for remote workers on the IP Office is avaya-ru server interworking.
Highlight the avaya-ru profile.
5. Click Clone.
6. Enter a name for the profile and click Finish.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
15
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Global Profiles.
3. Select Phone Interworking.
4. Select the avaya-ru profile and click Clone.
5. Enter a name for the profile and click Finish.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Global Profiles.
3. Select Server Configuration.
4. Click Add.
5. Enter a name.
6. In the Server Type field, select Call Server from the pull down menu.
7. In the IP Addresses field, the IP Office IP address.
8. Check the Supported Transports you want to use.
TCP is required for remote worker but you may have UDP if you are also using the
SBC for SIP trunks.
9. In the Transport Port fields enter the port to be used (for example port 5060).
10. Click Next three times.
11. Do not enable Grooming. IP Office uses different TCP connections to each
endpoint.
12. For the interworking profile, choose avaya-ru or a cloned version of it.
13. Click Finish.
16
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Global Profiles.
3. Select Routing.
4. Click Add.
5. Enter a name for the profile.
6. Click Next.
7. In the Next Hop Server 1 field, enter the IP Office IP address.
You can use the IP Office fully qualified domain name (FQDN).
If using a non default port of 5060, you must put the IP colon port in the Next Hop
field. For example 10.3.3.3:5070.
8. Click on the appropriate Outgoing Transport to be used for IP Office.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
17
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then Global Profiles.
3. Select Topology Hiding.
4. Click on the default profile and then click Clone.
5. Enter a name and click Finish.
6. The profile just created is highlighted. Click Edit.
If IP Office is configured to accept a specific domain then in the From, To, and
Request-Line field, select Overwrite, enter the domain name and click
Finish.
If IP Office is configured to accept a specific domain then in the From, To, and
Request-Line field, select Destination IPand click Finish.
If no special criteria is required, leave everything as Auto and click Finish.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Domain Policies and then End Point Policy Groups.
3. Click Add and enter a name for the IP Office server flow.
4. Click Next.
5. Choose the appropriate Rules and click Finish.
6. Click Add and enter a name for the subscriber flow.
7. Click Next.
8. Choose the appropriate Rules and click Finish.
Next steps
The following three procedures for end point policy groups show changing the application rule
for max sessions, the media rule for QoS and RTP or SRTP, and the signaling rule for QoS.
18
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
See Administering Avaya Session Border Controller for Enterprise for additional information
on domain polices.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Domain Policies and then Application Rules.
3. Click Add and enter a name for the one to be used by the IP Office End Point Policy
Group.
4. Click Next.
5. Check In and Out for Voiceand put in the amount of concurrent sessions required
for the license. Put the same value for Max Concurrent Sessions and Max
Sessions Per Endpoint.
It is best practice to put more than the license as this is not counted one or one with
license session. For example, if they have license of 300 concurrent sessions put
500 for each box.
If you need video, you must do the same for video. If you clone the default, Audio
is already enabled you only need to adjust the values and then enable video.
6. Click Finish.
7. Repeat to create a rule used by the Subscriber Flow End Point Policy Group. For
the subscriber flow rule, put the Max Concurrent Sessions higher than the license.
However, for Max Sessions Per Endpoint, the recommended value is 10. You can
use a higher value if required.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
19
20
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then End Point Flow.
3. Select Server Flow.
4. Click Add.
5. Enter a name for the IP Office flow.
6. In the Server Configuration field, select the IP Office server configuration.
7. In the Received Interface field, select the external signaling interface.
8. In the Media Interface field, select the IP Office interface.
9. In the Signaling Interface field, select the IP Office interface.
10. In the End Point Policy field, select the policy group created for IP Office.
11. In the Routing Profile field, select the default routing profile.
12. If required, in the Topology Hiding Profile, select profile created for IP Office.
13. Click Finish.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
21
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Global Parameters and then User Agents..
3. Click Add.
4. Enter a description then put in the type of user agent the endpoint you want to allow
using regular expression. You can use one type per policy or you can put multiple
types in one user agent profile.
5. Click Finish.
22
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
6. You can add the user agent header to a subscriber flow during the flow configuration
or by editing an existing flow. In the subscriber flow User Agent field, select the
user agent profile.
Procedure
1. In the navigation tree on the left, expand System Management.
2. Select Device Specific Settings and then End Point Flow.
3. Select Subscriber Flow.
4. Click Add.
5. Enter a name for the end point flow.
6. The URI Group and User Agent fields can be used to only allow certain DIDs or
phone types to use that flow.
7. In the Signaling Interface field, select the external signaling interface.
8. Click Next.
9. In the Media Interface field, select the external media interface.
10. In the End Point Policy Group field, select the policy group created for the
endpoints.
11. In the Routing Profile field, select the profile to route to the IP Office.
12. The Topology Hiding field can be used if you want to send something specific to
the phones. It can be left blank.
13. In the Phone Interworking Profile field, select avaya-ru or the recommended
cloned copy of avaya-ru.
14. If using TLS, put in the default TLS Client Profile called AvayaSBCClient.
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
23
24
Configuring the Avaya Session Border Controller for IP Office Remote Workers
Comments? infodev@avaya.com
September 2013
Index
B
backup ........................................................................ 12
E
end point policy groups ......................................... 1820
application rules ................................................... 19
media rules .......................................................... 20
signalling rules ..................................................... 20
overview ....................................................................... 7
P
phone interworking profiles ........................................ 15
R
registration ................................................................... 7
remote access .............................................................. 7
remote worker best practices ....................................... 8
routing profiles ............................................................ 17
licensing ....................................................................... 7
T
topology hiding ........................................................... 17
Configuring the Avaya Session Border Controller for IP Office Remote Workers
September 2013
25