...
Add_workflow_for_techpubs |
---|
AUTH1 | UserResourceIdentifier{userKey=8a00a0c85b2726c2015b58aa779d0003, userName='null'} |
---|
JIRAIDAUTH | SYM-2300024331 |
---|
REV5 | UserResourceIdentifier{userKey=8a00a0c85b2726c2015b58aa779d0003, userName='null'} |
---|
REV6 | UserResourceIdentifier{userKey=8a00a0c85b2726c2015b58aa779d0003, userName='null'} |
---|
REV3 | UserResourceIdentifier{userKey=8a00a02355cd1c2f0155cd26cd700a1f, userName='null'} |
---|
REV1 | UserResourceIdentifier{userKey=8a00a02355cd1c2f0155cd26cc5207f0, userName='null'} |
---|
|
Excerpt Include |
---|
| UXDOC61:Not_for_SWe |
---|
| UXDOC61:Not_for_SWe |
---|
nopanel | true |
---|
|
...
Note |
---|
SBC Edge now supports a new deployment with CCE 2.1.0 in release 7.0.1. Before this release, if your CCE auto-updates to CCE 2.1.0: - To rerun the step “Transfer Credential from SBC”, it will require 7.0.1.
|
Info |
---|
Info |
---|
For details on troubleshooting, see Troubleshooting Cloud Connector 6.1.2. |
Multiexcerpt include |
---|
MultiExcerptName | BeforeYouStart |
---|
PageWithExcerpt | Configuring the SBC Edge for a Single CCE |
---|
|
...
In this best practice the router/firewall is configured with the following rules:
Caption |
---|
0 | Table |
---|
1 | Internal Firewall Rules for CCE |
---|
|
Source IP | Destination IP | Source Port | Destination Port |
---|
Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | Internal clients | TCP 49 152 – 57 500* | TCP 50,000-50,019 (Optional) | Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | Internal clients | UDP 49 152 – 57 500* | UDP 50,000-50,019 | Internal clients | Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | TCP 50,000-50,019 | TCP 49 152 – 57 500* | Internal clients | Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | UDP 50,000-50,019 | UDP 49 152 -57 500* |
|
Caption |
---|
0 | Table |
---|
1 | External Firewall Rules for CCE |
---|
|
Source IP | Destination IP | Source Port | Destination Port |
---|
Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | Any | TCP 5061 | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | Any | TCP 80 | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | Any | UDP 53 | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | Any | TCP 53 | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | TCP 50,000-59,999 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | UDP 3478 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | UDP 50,000-59,999 | Any | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | TCP 5061 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | TCP 443 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | TCP 50,000-59,999 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | UDP 3478 | Any | Cloud Connector Edge External Interface – 192.168.211.81 & 192.168.211.86 | Any | UDP 50,000 - 59,999 |
|
Caption |
---|
0 | Table |
---|
1 | Host Firewall Rules - Internal or External Access |
---|
|
Source IP | Destination IP | Source Port | Destination Port |
---|
ASM | Any | Any | TCP 53 | ASM | Any | Any | TCP 80 | ASM | Any | Any | TCP 443 |
|
Multiexcerpt include |
---|
MultiExcerptName | DNSSettings |
---|
PageWithExcerpt | Configuring the SBC Edge for a Single CCE |
---|
|
...
Update the SBC Edge firmware to the latest release version.
Note |
---|
- Ensure the Node FQDN is definitive. Changing this information requires the CCE to be redeployed.
- Ensure that an NTP server is configured.
|
Sonus recommends starting with a clean and empty configuration.
...
Step | Action |
---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Task tab, and then click Operational Status. |
3 | Verify that: - The ASM Board Status is Up
- The appropriate Service Status is Running
- The Service is the latest version. If the service version (SBC Communications Service) is not the latest, update it by following the steps in Installing an ASM Package.
|
4 | Change the ASM Admin password: - Login to WebUI of both SBC Edge systems
- Click the Task tab and then click Change Admin Password.
- Enter the desired password twice and then click OK.
|
...
Step | Action |
---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition and click the CCE Public Certificate tab. |
3 | On SBC-1, click the Action drop-down list and select the appropriate option: - Import X.509 Signed Certificate. This option is used if you generated a Certificate Request (CSR) and this is the initial deployment. Paste the certificate in the window and click OK.
- Import PKCS12 Certificate and Key. Imports a certificate you created. Enter the password, select the file (certificate) to import, and click OK.
- Export PKCS12 Certificate and Key. Export the CCE certificate for backup purposes. Enter password and click OK.
- Transfer Public Certificate to Edge. Transfers the public certificate to the CCE (after deployment).
- Display Certificate. Displays the current SBC Edge certificate.
|
4 | On SBC-2, click the Action drop-down list and select the appropriate option: - Import X.509 Signed Certificate. This option is used if you generated a Certificate Request (CSR) and this is the initial deployment. Paste the certificate in the window and click OK.
- Import PKCS12 Certificate and Key. Imports a certificate you created. Enter the password, select the file (certificate) to import, and click OK.
- Export PKCS12 Certificate and Key. Export the CCE certificate for backup purposes. Enter password and click OK.
- Transfer Public Certificate to Edge. Transfers the public certificate to the CCE (after deployment).
- Display Certificate. Displays the current SBC Edge certificate.
|
45 | After receiving the activity status as successfully completed, click on Configure CCE tab. |
...
Step | Action |
---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the Configure CCE tab. |
4 | Configure all necessary information and then click OK. Note |
---|
TLS 1.2 is supported; the following fields are required to configure TLS: - Primary SBC Transport Protocol. Options: TCP or TLS (supports TLS 1.2).
- Secondary SBC Transport Protocol (optional). Options: TCP or TLS (supports TLS 1.2).
If TLS is configured as the Primary SBC Transport Protocol, you must run the Synchronize CCE/SBC CA Certificate task to allow a successful TLS handshake between CCE and SBC Edge. However, if TCP is configured as the Primary SBC Transport Protocol the Synchronize CCE/SBC CA Certificate task is not mandatory. See Managing Cloud Connector Edition Private Certificates. |
Caption |
---|
0 | Figure |
---|
1 | Configuring the ASM – CCE-1 |
---|
| Image RemovedImage Added |
Caption |
---|
0 | Figure |
---|
1 | Configuring the ASM – CCE-2 |
---|
| Image RemovedImage Added | Note: Enterthe ASM's IP address in the HA Master IP Address field. The Slave uses the same root certification as the Master, and this location contains the shared folder that contains the Root CA of the Master. |
5 | To increase Fast Failover (which shortens the time where certain ported numbers have a long delay from ITSP PSTN provider) configure Trunk Information: Refer Support. Indicates whether Gateways support Refer for a Call Transfer scenario. Valid entries: Enable (the Gateway(s) supports Refer which can handle call transfer) or Disable (the Gateway does not support Refer and the Mediation Server handles call transfer). Fast Failover Timer. Determines whether outbound calls that are not answered by the gateway within ten seconds will be routed to the next available trunk; if there are no additional trunks, the call will automatically be dropped. Valid entries: Enable or Disable. Forward Call History. Indicates whether call history information is forwarded through the trunk. Valid entries: Enable or Disable. Forward PAI. Indicates whether the P-Asserted-Identity (PAI) header will be forwarded along with the call. Valid entries: Enable or Disable. |
6 | After After receiving the activity status as successfully completed, click the Prepare CCE tab to continue. |
...
Step | Action |
---|
1 | Login to the WebUI of each SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the Cutomize CCE VMs tab. |
4 | In Domain Controller and Central Management Store VM > Windows Product Key 1, enter the first Microsoft Product Key. To identify the Product Key, see Identify Microsoft Product Key. |
5 | In Under Mediation Server and Edge Server VM > Windows Product Key 2, enter the second Microsoft Product Key.To identify the Product Key, see Identify Microsoft Product Key. |
6 | From the Proxy Usage drop down list, select Enabled (enables the Proxy Server on the DMZ facing the internal network) If you select Disable, the Proxy Server is disabled. |
7 | In the Proxy Server IP Address field, enter the server IP address for the Proxy Server in IPv4 format. This field is available only when Proxy Usage is set to Enabled. |
8 | In the Proxy Server Port field, enter the port number for the Proxy Server. Valid entry: 1 - 65535. This field is available only when Proxy Usage is set to Enabled. |
9 | Click Apply. |
10 | Access Tasks> Operational Status to verify Windows Activation. If activation fails, see Troubleshooting. |
11 | |
...
Caption |
---|
0 | Figure |
---|
1 | Building your SBC Edge-2 Configuration |
---|
|
|
Multiexcerpt include |
---|
MultiExcerptName | BasicCallVerification |
---|
PageWithExcerpt | Configuring the SBC Edge for a Single CCE |
---|
|
Multiexcerpt include |
---|
MultiExcerptName | O365KnownIssues |
---|
PageWithExcerpt | Configuring the SBC Edge for a Single CCE |
---|
|
Updating the CCE Password
Follow these steps if you need to update the O365 tenant admin password or account.
Step | Action |
---|
1 | On the WebUI, run Preparing the CCE to specify a new Password. Select the existing password and enter the new password. Only the O365 should be modified for a running instance of CCE. |
|
---|
1 | On the WebUI, click Tasks and select the Prepare CCE tab (see Preparing the CCE). |
2 | Click Prepare CCE. |
3 | From the Password Setting drop down list, select Change Password. Keep the same passwords for the Edge Server, CCE Service and CA Backup File, but change the passwords for Tenant Account User and Tenant Account Password. |
42 | On Remote desktop, start the Sonus Cloud Link Deployer, and check Transfer Password from SBC to reset the credentials. |