Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Section
column
Column
width40%
Panel
titleTable of Contents
Table of Contents
Info
titleAbout this Page

This document details a complete

implmentation

implementation of the SBC's RBA Feature

Tip
titleRelated Articles

...

Prerequisites

Tip

Assumes the user is familiar with navigating the SBCx000's WebUI

...

Note

The RBA Feature is included only in SBC version 3.0 or betternewer.

SBC Configuration

This quick start document shows the steps and interlational parameters required to configure a UX to successfully route calls. The configuration process of a UX should always begin with running a wizard; however, the wizard only needs to be run for the very first configuration.

Tip

There are many different architectures which might be used for connecting remote sites to a main site. The manual pages for this 3G4G feature specify a VLAN switch with the 3G4G and WAN networks sharing a single port of the UX.

The implementation below uses a 3G4G router connected to the remote LAN segment, thus dedicating the WAN connection to a SBC port. This configuration elminates then need for a VLAN-capable switch.

Network Diagram

Panel
borderStylenone

Caption
0Figure
1Network Diagram

Image Modified

 

 

Before Beginning

As a prerequisite to installing the RBA feature, check the following items:

...

Configure Send STUN Packets to Enabled in the Media | Media System Configuration.

Panel
borderStylenone

Caption
0Figure
1STUN Setting

Image Modified

 

RBA Image

Tip

If your HQ-side SBC was running version 2.2, you will need upgrade both the ASM image as well as the SBC firmware. The latest ASM image is available at support.net.com.

...

Under the Tasks Tab | Application Solution Module | Reinitialize the pull-down selection will supply the possible images currently available on your ASM. Update your ASM images if you are implementing Lync Server 2013 and there is no Lync 2013 image available on your ASM.

Panel
borderStylenone

Caption
0Figure
1Reinitialization

Image Modified

 

Check the RBA License

Verify that your SBC is licensed for the RBA feature.

Panel
borderStylenone

Caption
0Figure
1Check RBA License

Image Modified 

 

DNS Configuration

Add both SBCs to the DNS server. In the example, SBC2000 is the HQ SBC and SBC1000 is the remote network SBC. The DNS server is configured only with the LAN-side IP addresses of these nodes, 10.1.1.74 and 10.1.2.71, respectively.

...

  • Remote-network SBC
  • HQ SBC
  • HQ ASM
  • Lync Server

Image Removed

Panel
borderStylenone

Caption
0Figure
1DNS Configuration

Image Added

 

Lync Server Topology Configuration

...

Open the Lync Topology Builder

  1. Start the Topo Builder

    Panel
    borderStylenone

    Caption
    0Figure
    1Start Topology Builder

    Image Modified 

     

     

  2. Enter Login Credentials

    Panel
    borderStylenone

    Caption
    0Figure
    1Login Credentials

    Image Modified

     

     

  3. Download the Topology

    Panel
    borderStylenone

    Caption
    0Figure
    1Download Topology

    Image Modified

     

     

  4. Specify a Filename

    Panel
    Image Removed
    borderStyle
    Confirm Changes
    none
    Image Removed

    Caption

New Branch Site

  1. 0Figure
    1Specify Filename

    Image Added

     

     

  2. Confirm Changes

    Panel
    borderStylenone

    Caption
    0Figure
    1Confirm

    Image Added

New Branch Site

Add Add a new Branch Site. In the example, Taveuni is the new remote branch.

  1. Right-click on Branch Sites and select New Branch Site

    Panel
    borderStylenone

    Caption
    0Figure
    1New Branch Site

    Image Modified

     

     

  2. Enter the remote site identity

    Panel
    borderStylenone

    Caption
    0Figure
    1Remote Site Identity

    Image Modified

     

     

  3. Configure the site details

    Panel
    borderStyle
    Image Removed
    none

New PSTN Gateway

  1. Caption
    0Figure
    1Site Details

    Image Added

     

     

New PSTN Gateway

Add sbc1000.Add sbc1000.sbc.net as Taveuni's PSTN Gateway.

Panel
borderStylenone

Caption
0Figure
1New PSTN Gateway

Image Modified

Panel
borderStylenone

Caption
0Figure
1Define PSTN Gateway

Image Modified

Panel
borderStylenone

Caption
0Figure
1Define IP Address

Image Modified

info
Panel
borderStylenone

Caption
0Figure
1Define Root Trunk

Image Modified

 

 

Info

The RBA function requires media bypass, which, in turn requires TLS/SRTP. Later this document, the remote PSTN gateway will be re-configured from TCP/RTP to TLS/SRTP. Employing the simplier TCP/RTP model will help ease the implementation by providing a phased approach to the implementation.

...

Finally, Publish the newly configured topology.

Panel
borderStylenone

Caption
0Figure
1Publish Topology

Image Modified

Panel
borderStylenone

Caption
0Figure
1Publishing Wizard Complete

Image Modified 

 

Lync Server Configuration

Create a new Site Voice Policy

  1. Click New

    Panel
    borderStylenone

    Caption
    0Figure
    1New

    Image Modified

     

     

  2. Add a Site Policy

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Site Policy

    Image Modified

     

     

  3. Select the remote site you just added to the Lync topology.

    Image Removed

  4. Add a new PSTN Usage

    Image Removed

  5. Panel
    borderStylenone

    Caption
    0Figure
    1Select Remote Site

    Image Added

     

     

  6. Add a new PSTN Usage

    Panel
    borderStylenone

    Caption
    0Figure
    1Add PSTN Usage

    Image Added 

     

     

  7. Supply Supply a Name and Add a Route

    Panel
    borderStylenone

    Caption
    0Figure
    1Name and Route

    Image Modified

     

     

  8. Configure a call route pattern

    Panel
    borderStylenone

    Caption
    0Figure
    1Configure Call Route Pattern

    Image Modified 

     

     

  9. Add a Trunk

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Trunk

    Image Modified

     

     

  10. Choose the newly added remote-network SBC

    Panel
    borderStylenone

    Caption
    0Figure
    1Select Trunk

    Image Modified

     

     

  11. Click OKat each of the configuration layers

    Image Removed

    Image Removed

    Image Removed

Commit New Site Voice Policy

Commit the changes to the Voice Policy

  1. Click the Commit pulldown and Commit All

    Image Removed

  2. Click OK

    Image Removed

Verify Route and PSTN Usage

  1. Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 1

    Image Added

    Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 2

    Image Added

    Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 3

    Image Added

     

    Pagebreak

Commit New Site Voice Policy

Commit the changes to the Voice Policy

  1. Click the Commit pulldown and Commit All

    Panel
    borderStylenone

    Caption
    0Figure
    1Commit All

    Image Added

     

     

  2. Click OK.

    Panel
    borderStylenone

    Caption
    0Figure
    1OK Configuration Settings

    Image Added

Verify Route and PSTN Usage

Verify the Route and Verify the Route and PSTN Usages were added properly in the previous steps.

  1. In the top navigation bar, click Route. Ensure that the route was added.

    Panel
    borderStylenone

    Caption
    0Figure
    1Ensure Route Added

    Image Modified

     

     

  2. In the top navigation bar, click PSTN Usage. Ensure that the PSTN Usage was added.

    Image Removed

    Usage. Ensure that the PSTN Usage was added.

    Panel
    borderStylenone

    Caption
    0Figure
    1Ensure PSTN Usage Added

    Image Added

     

    Pagebreak

Create a User New Dial Plan

...

  1. Click Dial Plan in the top navigation. Click New_and select _New User Plan.

    Panel
    borderStylenone

    Caption
    0Figure
    1New User Dial Plan

    Image Modified

     

     

  2. Enter the information for your site and click OK.

    Panel
    borderStylenone

    Caption
    0Figure
    1OK Information

    Image Modified

     

     

Create A New User Voice Policy

...

  1. Click Voice Policy in the top navigation. Click New and select User Policy.

    Panel
    borderStylenone

    Caption
    0Figure
    1Voice Policy

    Image Modified

     

     

  2. Fill in the form as shown using information for your particular installation.

    Image Removed

    installation.

    Panel
    borderStylenone

    Caption
    0Figure
    1Fill in Form

    Image Added

     

     

  3. Click New under Associated PSTN Usages.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Associated PSTN Usages

    Image Modified

     

    Pagebreak

Create a New PSTN Usage

Create a PSTN Usage to be used with the User-level policies.

  1. Create a New PSTN Usage record.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create PSTN Usage Record

    Image Modified

     

     

  2. Enter your site-specific configuration information.

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Enter Configuration Information

    Image Added

     

     

  3. Click Add for Associated Trunk

    Panel
    borderStylenone

    Caption
    0Figure
    1Add

    Click Add for

    Associated Trunk

    Image Modified

     

     

  4. Select the remote-network SBC gateway

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Select Trunk

    Image Added

     

     

  5. Click OKfor all the configuration layers.

    Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 1

    Image Added

    Pagebreak

     

    Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 2

    Image Added

    Panel
    borderStylenone

    Caption
    0Figure
    1Configuration Level 3

    Image Added

     

     

    Click OKfor all the configuration layers.

    Image Removed

    Image Removed

    Image Removed

Commit Changes

Commit the additions to your Lync configuration.

  1. Click the Commit pulldown, then select Commit All.

    Panel
    borderStylenone

    Caption
    0Figure
    1Commit All

    Image Modified

     

     

  2. Click OK.

    Panel
    borderStylenone

    Caption
    0Figure
    1OK Configuration Settings

    Image Added

    Pagebreak

     

     

  3. Verify the Route was added.

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify Route Added

    Image Added

     

     

  4. Verify the Route PSTN Usagewas added.

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify

    the

    PSTN Usage

    was added.

    Added

    Image Modified

     

    Pagebreak

Add or Move a User into the

...

New Remote Location

You will need to have a user homed to the remote-network location.

  1. Click Users in the left-hand navigation. Enter the name of the user to move to the remote network and click Find.

    Panel
    borderStylenone

    Caption
    0Figure
    1Find User

    Image Modified

     

     

  2. In the Edit pulldown, select Show Details.

    Panel
    borderStylenone

    Caption
    0Figure
    1Show Details

    Image Modified

     

     

  3. Set the Dial Plan and Voice Policy of the user to thos of the remote network Userpolicies.

    Image Removed

    Userpolicies.

    Panel
    borderStylenone

    Caption
    0Figure
    1Edit Lync Server User

    Image Added

     

    Pagebreak

Configure the Network Configuration

...

  1. Click Network Configuration in the left-hand navigation. Click Global in the top navigation, click the Edit pulldown, and select Show Details.

    Panel
    borderStylenone

    Caption
    0Figure
    1Show Details

    Image Modified

     

     

  2. Ensure that the CAC and Bypass options are selected. Change the settings and commit, if necessary.

    Panel
    borderStylenone

    Caption
    0Figure
    1Edit Global Setting

    Image Modified

     

     

Create a

...

New Bandwidth Policy

Create a Bandwidth Policy to be used to control the CAC from the RBA function.

  1. Click Bandwidth Policy in the top navigation and select New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Bandwidth Policy

    Image Modified

    Pagebreak

     

     

  2. Enter the bandwidth specification for your remote network link, then click Commit.

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Enter Bandwidth Specification

    Image Added 


    Pagebreak

Create a

...

New Region

Create regions to be used with the RBA feature. There will be a region for the HQ, as well as the remote-network.

  1. Click Region in the top navigation and select New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Region

    Image Modified

     

     

  2. Add a record for the remote region and Commit.

    Panel
    borderStylenone

    Caption
    0Figure
    1Remote Region Record

    Image Modified

     

     

  3. Click New New to add the second region.

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Second Region

    Image Modified

     

    Pagebreak

  4. Add a record for the HQ site and Commit.

    Panel
    borderStylenone

    Caption
    0Figure
    1HQ Site Record

    Image Added 

    Add a record for the HQ site and Commit.

    Image Removed

Create a new Site

Create sites to be used for the RBA function. Again, there will be a HQ site, as well as a remote site.

  1. Click Site in the top navigation and select New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Site

    Image Modified

     

     

  2. Enter the information for your remote site. Click Commit.

    Panel
    borderStylenone

    Caption
    0Figure
    1Remote Site Information

    Image Modified

     

     

  3. Click New and enter the information for your HQ site. Click Commit.

    Panel
    borderStylenone

    Caption
    0Figure
    1HQ Site Information

    Image Modified

     

    Pagebreak

Create

...

New Subnets

IP addresses are used by the Lync Server to identify the origin of a Lync client. Create subnet records for both the HQ and remote network sites.

  1. Click Subnet in the top navigation and select New.

    Image Removed

    New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Subnet

    Image Added

     

     

  2. Enter the IP network information for the remote network.

    Panel
    borderStylenone

    Caption
    0Figure
    1IP Network Information - Remote Network

    Image Modified

     

     

  3. Click Newand enter the IP network information for the HQ network.

    Panel
    borderStylenone

    Caption
    0Figure
    1IP Network Information - HQ Network

    Image Modified

     

     

Create a Region Link between the sites.

  1. Click Region Link in the top navigation and select New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Region Link

    Image Modified

     

     

  2. Using the pulldowns, select the HQ Region, the Remote Region and the Bandwidth Policy profile you previously created.

    Image Removed

    previously created.

    Panel
    borderStylenone

    Caption
    0Figure
    1Select From Pulldowns

    Image Added

    Pagebreak

     

Create a

...

New Region Route

Create a Region Route for the Region Link.

  1. Click Region Route in the top navigation and select New.

    Panel
    borderStylenone

    Caption
    0Figure
    1New Region Route

    Image Modified

     

     

  2. Add the Network Regions as shown and add the newly created Region Link.

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Network Regions

    Image Modified

     

     

Domain Controller Configuration

...

  1. On the Domain Controller, open the Server Manager

    Panel
    borderStylenone

    Caption
    0Figure
    1Open Server Manager

    Image Modified

     

     

  2. Add a new computer to Active Directory. You should have already selected a FQDN for the ASM module during the DNS Configuration section.

    Image Removed

    section.

    Panel
    borderStylenone

    Caption
    0Figure
    1Add new Computer

    Image Added

     

     

  3. Input the name of the ASM computer

    Panel
    borderStylenone

    Caption
    0Figure
    1Input Name of ASM Computer

    Image Modified 

     

     

  4. Add the computer to the RTCUniversalServerAdminsgroup

    Image Removed

  5. Click OK

    Image Removed

  6. RTCUniversalServerAdminsgroup

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Computer

    Image Added

     

     

  7. Click OK

    Panel
    borderStylenone

    Caption
    0Figure
    1OK User or Group

    Image Added

     

     

  8. Click OK

    Panel
    borderStylenone

    Caption
    0Figure
    1OK new Object

    Image Added

     

     

    Click OK

    Image Removed

Configuring the RBA

Tip

Have you added the RBA as a computer in the Domain Controller and made it part of the RTCUniversalServerAdmins group?

  1. Verify the ASM Board is Available using the Tasks Tab | Operational Statusselection

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify ASM Board

    Image Modified

     

     

  2. Click Setup SBA in the left-hand navigation

    Panel
    borderStylenone

    Caption
    0Figure
    1Setup SBA

    Image Modified

  3. Click the ASM Config Tab and supply the information for your ASM. Click Apply.

    Panel
    borderStylenone

    Caption
    0Figure
    1Apply ASM Information

    Image Modified

     

     

  4. Click the Domain tab and supply the domain information for your network. Click OK. It will take a minutes to add the ASM to the domain and reboot.

    Image Removed

    the domain and reboot.

    Panel
    borderStylenone

    Caption
    0Figure
    1Domain Tab

    Image Added

     

     

  5. The Current Activity Panel will show when the domain join and rebooting processes are complete

    Panel
    borderStylenone

    Caption
    0Figure
    1Current Activity Panel

    Image Modified

     

     

  6. Click the Deploy SBA tab and select Prepare SBA. This will install the necessary components for the ASM to process the CAC changes supplied by the remote-network SBC. It will take approximately 30 minutes for the installation to complete.

    Panel
    borderStylenone

    Caption
    0Figure
    1Prepare SBA

    Image Modified

     

     

Info

The RBA requires only the Prep SBA step. The other SBA deployment steps are not required.

...

Ensuring the WAN and IPsec traffic use the appropriate routes is crucial to successful RBA failover.

SBC 1000 Static Routes

  1. Click the Settings Tab and select Static Routes as shown in the diagram

    Panel
    borderStylenone

    Caption
    0Figure
    1Static Routes

    Image Modified

  2. On the remote-network SBC, add a Static IP Route

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Static IP Route

    Image Added

     

    Image Removed

     

  3. Create a default route that points to the WAN interface on the HQ SBC. Set the Metric to 1.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Default Route - Metric 1

    Image Modified

     

     

  4. Create another default route that points to the IPSec IPsec interface on the HQ SBC. Set the Metric to 2.

    Tip

    Default routes are required for the automated routing failover to function. Only use default routes.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Default Route - Metric 2

    Image Modified

     

     

  5. Verify the newly added static routes

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify Static Routes

    Image Modified

     

     

SBC 2000 Static Routes

On the HQ SBC, add specific subnet routes that point to the remote-network. One route should use the remote-network SBC's WAN connection (metric 1), the other should point to the Internet gateway (metric 2).

  • When the WAN is up, the WAN-specific route to the remote-network will be used.
  • When the WAN is down, the default Internet router will be used to send the traffic via the 3G4G carrier network.network.
Panel
borderStylenone

Caption
0Figure
1Static IP Route Table

Image Added

 

 Image Removed

SIP Server Tables and Signaling Groups

...

  1. Click SIP Server Tablesin the left-hand navigation

    Panel
    borderStylenone

    Caption
    0Figure
    1SIP Server Tables

    Image Modified

     

     

  2. Add a SIP Server Table

    Panel
    borderStylenone

    Caption
    0Figure
    1Add SIP Server Table

    Image Modified

     

     

  3. Enter a description and click Apply.

    Image Removed

    Panel
    borderStylenone

    Caption
    0Figure
    1Apply Description

    Image Added

     

     

  4. Click the newly added SIP Server Table

    Panel
    borderStylenone

    Caption
    0Figure
    1Click New

    Click the newly added

    SIP Server Table

    Image Modified 

     

     

  5. Enter the information for the HQ SBC

    Panel
    borderStylenone

    Caption
    0Figure
    1HQ SBC Information

    Image Modified 

     

     

SBC 1000 Signaling Groups

  1. Click Signaling Groupsin the left-hand navigation. Add a Signaling Group for the HQ SBC.

    Panel
    borderStylenone

    Caption
    0Figure
    1Signaling Groups

    Image Modified

     

     

  2. Add the information to the newly added SG.

    Panel
    borderStylenone

    Caption
    0Figure
    1Add SG Information

    Image Modified 

     

     

SBC 2000 SIP Server Table

  1. On the HQ SBC, add a SIP Server Table that points to the remote-network SBC

    Image Removed

    SBC

    Panel
    borderStylenone

    Caption
    0Figure
    1Add SIP Server Table

    Image Added

     

     

SCB 2000 Signaling Groups

  1. On the HQ SBC, add a Signaling Group that points to the remote-network SBC

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Signaling Group

    Image Modified

     

     

  2. On both SBCs, ensure that the Signaling Groups come Up

    Panel
    borderStylenone

    Caption
    0Figure
    1Ensure Signaling Groups Come Up - SBC 1000

    Image Modified 

    Panel
    borderStylenone

    Caption
    0Figure
    1Ensure Signaling Groups Come Up - SBC 2000

    Image Modified

     

     

Verification

Verifying Routing

On the HQ SBC, verify that the Routing Table shows the route to the remote network using the WAN IP address of the remote SBC. In this case, the route to 10.1.2.0 (remote network) uses the remote SBC's 134.56.242.16 as the gateway..

Panel
borderStylenone

Caption
0Figure
1Routing Table

Image Modified

 

...

At this point you should be able to call Lync-to-Lync over the WAN.

Creating the

...

IPsec Tunnel

Use the following steps to configure an IPsec tunnel between the remote and HQ SBCs.

SBC1000

...

IPsec Configuration

The following steps configure the remote SBC to generate an IPsec tunnel to the HQ SBC when the WAN is down.

  1. Click IPSec IPsec | Tunnel Tablein the left-hand navigation.

    Panel
    borderStylenone

    Caption
    0Figure
    1Tunnel Table

    Image Modified

     

     

  2. Add a Tunnel Table

    Panel
    borderStylenone

    Caption
    0Figure
    1Add Tunnel Table

    Image Modified

     

     

  3. Enter the configuraton information for your IPsec tunnel.
  • The Local Subnet Address must be programmed with IP information for the remote network.
  • The Remote Subnet Addressmust be programmed with IP information for the HQ network.

    Panel
    borderStylenone

    Caption
    0Figure
    1Enter Configuration Information

    Image Modified

     

     

SBC2000

...

IPsec Tunnel Configuration

The following steps configure the HQ SBC to receive an IPsec tunnel from the remote SBC when the WAN is down.

  1. Configure an IPsec tunnel on the HQ SBC with information appropriate to your network. On the HQ SBC, the Local Subnet Address is the HQ network, the Remote Subnet Addressis the remote network subnet(s).

    Image Removed

    subnet(s).

    Panel
    borderStylenone

    Caption
    0Figure
    1Create IPsec Tunnel Entry

    Image Added 

     

     

Verification

In this section you will test the IPsec tunnel to ensure connectivity exists when the WAN link is down.

...

  1. Pull the cable from the WAN port on the Remote SBC. You must pull the cable from the WAN port on the Remote SBC for this verification step. Downing the WAN port results in automatically disabling the WAN IP route.
  2. Manually remove the WAN Route from the HQ SBC

    Panel
    borderStylenone

    Caption
    0Figure
    1Remove WAN Route

    Image Modified

     

     

  3. On the Remote SBC, use the refresh button to verify the Service Status is Link Up.

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify Service Status

    Image Modified

     

     

  4. The Signaling Groups should come back up after the IPsec tunnel is esablished.

    Image Removed

    .

    Panel
    borderStylenone

    Caption
    0Figure
    1Signaling Groups - SBC 1000

    Image Added 

    Panel
    borderStylenone

    Caption
    0Figure
    1Signaling Groups - SBC 2000

    Image Modified

Verifying PC Connectivity

...

Before proceeding, replace the HQ SBC WAN route to the remote SBC.

Panel
borderStylenone

Caption
0Figure
1Create Static IP Route Entry

Image Modified 

 

Configuring for Automated Switchover

With the successful testing of the static IPsec tunnel, it is time to make the tunnel dynamic so that the 3G4G link is only used activated when the WAN is down.

  1. Modify the Remote SBC IPSec IPsec Tunnel Activation to Link Monitor Action and click OK.

    Panel
    borderStylenone

    Caption
    0Figure
    1Modify Tunnel Activation

    Image Modified

     

     

SBC 1000 CAC Profiles

The CAC profiles are transmitted to the Lync Server via the HQ SBC when the WAN transitions link states.

...

  1. Click WAN in the left-hand navigation and select CAC Profiles.

    Panel
    borderStylenone

    Caption
    0Figure
    1CAC Profiles

    Image Modified

     

     

  2. Create a profile for the WAN up situation. Set the bandwidths according to your desired WAN link configuration and capacity. Click Applywhen finished.

    Image Removed

    .

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Profile for WAN Up

    Image Added

     

     

  3. Now, create a CAC profile for WAN down. Setting the Bandwidth State to Disabledresults in any HQ<>remote-network calls being routed over the PSTN.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create CAC Profile for WAN Down

    Image Modified

     

     

SBC 1000 Link Monitor Configuration

The Link Monitors provide the ability for the remote SBC to know whether the WAN is up and available.'

  1. Click Link Monitor Configuration

    Panel
    borderStylenone

    Caption
    0Figure
    1Link Monitor Configuration

    Image Modified

     

     

  2. Add a monitor to monitor the public IP interface of the HQ SBC and click Apply.

    Panel
    borderStylenone

    Caption
    0Figure
    1Monitor Public IP Interface

    Image Modified

     

     

  3. Add a monitor to monitor the 3G4G router port. Associate this Link Monitor with the IPsec Tunnel you recently created. With this link activated (due to WAN down), the IPsec tunnel will be automatically started.

    Image Removed

    tunnel will be automatically started.

    Panel
    borderStylenone

    Caption
    0Figure
    1Monitor 3G4G Router Port

    Image Added

     

     

Verification

Verify the following tables on the remote SBC

Panel
borderStylenone

Caption
0Figure
1Verify CAC Profile Table

Image Modified

Panel
borderStylenone

Caption
0Figure
1Verify Link Monitor Configuration Table

Image Modified

 

SBC 2000 Link Monitor Configuration

...

  1. Create a fake CAC entry. This entry will be ignored for purposes of bandwidth adjustment.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Fake CAC Entry

    Image Modified

     

     

  2. Create a Link Monitor that monitors the WAN interface of the remote SBC.

    Image Removed

    remote SBC.

    Panel
    borderStylenone

    Caption
    0Figure
    1Create Link Monitor

    Image Added

     

     

 

Verification

Verify the condition of the routes and IPsec links.

...

With the WAN link up, the HQ SBC routing table and Link Monitor should resemble the following.

Panel
borderStylenone

Caption
0Figure
1HQ SBC Routing Table

Image Modified

Panel
borderStylenone

Caption
0Figure
1HQ SBC Link Monitor

Image Modified

 

Remote SBC

  1. With the WAN link up, the remote SBC's routing table should point to the WAN interface on the HQ SBC.

    Panel
    borderStylenone

    Caption
    0Figure
    1Routing Table - Point to WAN Interface

    Image Modified

     

     

  2. The Link Monitor Table should be Readyon the WAN link

    Image Removed

    WAN link

    Panel
    borderStylenone

    Caption
    0Figure
    1Link Monitor Table - Ready

    Image Added

     

     

  3. The IPsec tunnel should be Link Down

    Panel
    borderStylenone

    Caption
    0Figure
    1IPsec Tunnel - Link Down

    Image Modified

     

     

Lync Server

Verify the Lync Bandwidth Profile using the Bandwidth Policy Service Monitor, which is installed as a component of the optional Lync Server Resource Kit (available from the Microsoft Lync Server website).

  1. Open Windows Explorer to C:\Program Files\Microsoft Lync Server 2013\ResKit\BandwidthPolicyServiceMonitor and select PDPMonUI.exe.

    Panel
    borderStylenone

    Caption
    0Figure
    1Select PDPMonUI.exe

    Image Modified

     

     

  2. Expand the server name in the left-hand navigation and select the expanded server.

    Image Removed

    and select the expanded server.

    Panel
    borderStylenone

    Caption
    0Figure
    1Expanded Server Name

    Image Added

     

     

  3. Click the Topology Infotab

    Click the
    Panel
    borderStylenone

    Caption
    0Figure
    1

    Topology Info tab

    Image Modified

     

     

  4. Verify the bandwidth settings are for the WAN up values.

    Panel
    borderStylenone

    Caption
    0Figure
    1Verify Bandwidth Settings

    Image Modified

     

     

Lync Clients

Test a call between a HQ and Remote Lync client. Calls between HQ and Lync clients should connect directly over the WAN without need for a PSTN connection.

...

Downing the WAN Link should result in the following status. With the WAN link down, verify your implementation to the following:

HQ SBC Status

  1. On the HQ SBC, the WAN Link Monitor should show down and the IPsec tunnel up.

    Panel
    borderStylenone

    Caption
    0Figure
    1Link Monitor Service Status

...

  1. Image Added

    Panel
    borderStylenone

    Caption
    0Figure
    1IPsec Tunnel Service Status

    Image Added

     

     

    On the HQ SBC, the WAN Link Monitor should show down and the IPsec tunnel up.

    Image Removed

    Image Removed

Remote SBC Status

On the Remote SBC, the Link Monitor should show the 3G4G link up, the WAN link down, and the IPsec tunnel up.

Panel
borderStylenone

Caption
0Figure
13G4G Link Up and WAN Link Down

Image Modified

Panel
borderStylenone

Caption
0Figure
1IPsec Tunnel Link UP

Image Modified

 

Lync Server

Within two or three minutes, the Bandwidth Policy should automatically update to the Bandwidth Policy should automatically update to the WAN down bandwidth values.

...

WAN down bandwidth values.

Panel
borderStylenone

Caption
0Figure
1Bandwidth Policy Update

Image Added

 

Lync Clients

Test a call between a HQ and Remote Lync client. In the WAN down condition, you should be able to call between HQ and Remote Lync clients. The calls should utilize the PSTN connection between the SBCs.

...

  1. On the Lync Server, start the Topology Builder and Edit Properties for the remote site Trunk.

    Panel
    borderStylenone

    Caption
    0Figure
    1Edit Properties

    Image Modified

     

     

  2. Change the port and configuration to support TLS as shown.

    Panel
    borderStylenone

    Caption
    0Figure
    1Change Port and Configuration

    Image Modified

     

     

  3. Publish the topology.

    Panel
    borderStylenone

    Caption
    0Figure
    1Publish Topology

    Image Modified

     

     

Certificate for the SBC

Certificates are required for TLS/SRTP functionality. The following steps will assist you in installing certificates on the remote SBC.

  1. Click the Taskstab.

    Image Removed

    .

    Panel
    borderStylenone

    Caption
    0Figure
    1Tasks Tab

    Image Added 

     

     

  2. Click Lync Setupin the left-hand navigation

    Panel
    borderStylenone

    Caption
    0Figure
    1Lync Setup

    Image Modified

     

     

  3. Obatin the root certificate from your network administrator and copy it to your PC. From the webui, click Import Trusted CA Certificateas shown.

    Panel
    borderStylenone

    Caption
    0Figure
    1Import Trusted CA Certificate

    Image Modified

     

     

  4. Set the Mode to File Upload and Browseto find the file containing the root certificate.

    Image Removed

    the root certificate.

    Panel
    borderStylenone

    Caption
    0Figure
    1CA Certificate File Upload

    Image Added

     

     

  5. Click OKto import the root certificate.

    Panel
    borderStylenone

    Caption
    0Figure
    1Import Root Certificate

    Image Added

     

     

    Click OKto import the root certificate.

    Image Removed

  6. Click the Generate CSRto generate a certificate request for the SBC. You will send this certificate request to be signed by the your certificae authority.

    Panel
    borderStylenone

    Caption
    0Figure
    1Generate CSR

    Image Modified

     

     

  7. Copy and paste the certificate request into a file and send it to your root certificate authority for signing.

    Panel
    borderStylenone

    Caption
    0Figure
    1Result

    Image Modified

  8. When the signed certificate is returned, click the Sonus SBC Certificatetab and import the certificate.

    Panel
    borderStylenone

    Caption
    0Figure
    1Import Certificate

    Image Modified

     

     

  9. Set the Mode to File Upload and Browseto find the file containing the SBC certificate.

    Image Removed

    the SBC certificate.

    Panel
    borderStylenone

    Caption
    0Figure
    1SBC Server Certificate File Upload

    Image Added 

     

     

  10. Verify the SBC and root certificates

    Panel
    borderStylenone

    Caption
    0Figure
    1Sonus SBC Certificate

    Image Modified

    Panel
    borderStylenone

    Caption
    0Figure
    1Trusted CAs

    Image Modified

     

     

Setting the SIP Server and Signaling Group for TLS/SRTP

  1. On the remote SBC, set/create the Lync Server SIP Server as shown.

    Panel
    borderStylenone

    Caption
    0Figure
    1Set/Create Lync Server SIP Server

    Image Modified

     

     

  2. Set/create a Lync Server Signaling Group as shown.

    Panel
    borderStylenone

    Caption
    0Figure
    1SIP Signaling Group Details

    Image Modified 

     

     

  3. The Lync Server Signaling Group should come up

    Panel
    borderStylenone

    Caption
    0Figure
    1Lync Server Signaling Group - Up

    Image Modified

     

     

RBA Data Flows

WAN Up Flow

Image Removed

 

WAN Down Instant Message Flow

Image Removed

WAN Up Flow

Panel
borderStylenone

Caption
0Figure
1WAN Up Flow

Image Added

 

WAN Down Instant Message Flow

Panel
borderStylenone

Caption
0Figure
1WAN Down Instant Message Flow

Image Added

 

WAN Down Lync-to-Lync Call Flow

Panel
borderStylenone

Caption
0Figure
1

...

WAN Down Lync-to-Lync Call Flow

Image Modified

 

  1. As an IP router, the SBC forwards the SIP request from the remote Lync to the Lync Server
  2. Lync server sends a SIP request to the remote SBC (as a SIP --> PSTN gateway)
  3. Remote SBC dials the HQ SBC via PSTN
  4. HQ SBC (as a SIP Gateway) sends a SIP request to the Lync server
  5. Lync Server sends SIP Request to the HQ Lync client
  6. Remote Lync client audio bypasses directly to the remote SBC.

...

A wireshark trace which shows an exception due to an unrecognized cmdlet is likely due to the Prep SBA function not being executed. Review the Configuring the RBA section of this document.

Panel
borderStylenone

Caption
0Figure
1Prep SBA Function Not Executed

Image Modified

 

RBA computer not a member of RTCUniversalServerAdmins group

...

Check the routing table on the remote SBC. The remote SBC must use default routes (0.0.0.0/0) rather than network routes.

Panel
borderStylenone

Caption
0Figure
1Link Monitor Configuration Table

Image Modified

...

Panel
borderStylenone

Caption
0Figure
1

...

Route Table

...

With No Default Routes

Image Added



OPTIONS with Carrier's IP address

...

This wireshark trace shows a properly working cmdlet to change the CAC bandwidth policies.

Panel
borderStylenone

Caption
0Figure
1Wireshark Trace

Image Modified

 

rev 0.2