Add_workflow_for_techpubs | ||||
---|---|---|---|---|
|
...
|
...
...
|
Warning | |
---|---|
|
| |
You must follow these steps completely and in the order shown. Failure to do so increases the risk of node failure. |
...
Panel | ||||
---|---|---|---|---|
In this section....
|
Info |
---|
For details on troubleshooting, see Troubleshooting Cloud Connector 6.1.2. |
...
Note |
---|
SBC Edge now supports a new deployment with CCE 2.1.0 in release 7.0.1. Before this release, if your CCE auto-updates to CCE 2.1.0:
|
Info |
---|
For details on troubleshooting, see Troubleshooting Cloud Connector. |
This page provides a step-by-step procedure for Non High Availability Deployment on SBC Edge CCE.
Multiexcerpt | |||||||
---|---|---|---|---|---|---|---|
| |||||||
Before You StartCCE Deployment ScenariosThe following diagram shows typical CCE deployment scenarios on a PSTN site. The PSTN site is a combination of Cloud Connector instances, deployed at the same location, and with common PSTN gateways pool connected to them. PSTN sites allow you to:
|
Scenario 3 and Scenario 4 are covered in Configuring the SBC Edge for Two CCEs. This document contains steps for Scenario 1 and Scenario 2 deployments.
Multiexcerpt | ||
---|---|---|
| ||
Prerequisites |
...
...
0 | Table |
---|---|
1 | Prerequisites |
...
|
...
|
...
Note | ||
---|---|---|
| ||
Latest System Release SbcComms Firmware
Important!
|
...
|
For this best practice, Cloud Connector Edition deployment follows the cabling shown below:
Caption | ||||
---|---|---|---|---|
| ||||
For this best practice, the Router/Firewall is configured using the following rules:
Caption | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||||||
|
For this best practice, Cloud Connector Edition deployment follows the cabling shown below:
...
0 | Figure |
---|---|
1 | Typical Deployments |
...
...
Caption | |||
---|---|---|---|
|
...
|
...
|
...
Internal clients
...
TCP 49 152 – 57 500*
...
TCP 50,000-50,019 (Optional)
...
Cloud Connector Mediation component
...
Internal clients
...
UDP 49 152 – 57 500*
...
UDP 50,000-50,019
...
Internal clients
...
Cloud Connector Mediation component
...
TCP 50,000-50,019
...
TCP 49 152 – 57 500*
...
Internal clients
...
Cloud Connector Mediation component
...
UDP 50,000-50,019
...
UDP 49 152 -57 500*
...
0 | Table |
---|---|
1 | External Firewall Rules |
...
Source IP
...
Destination IP
...
Source Port
...
Destination Port
...
Any
|
|
...
|
...
TCP 5061
|
...
|
...
Any
...
UDP 53
|
...
Cloud Connector Edge External Interface
...
Any
...
Any
...
|
Caption |
---|
...
|
...
Any
...
Cloud Connector Edge External Interface
...
Any
...
TCP 443
...
Any
...
Cloud Connector Edge External Interface
...
Any
...
TCP 50,000-59,999
...
Any
...
Cloud Connector Edge External Interface
...
Any
...
UDP 3478
...
Any
...
Cloud Connector Edge External Interface
...
Any
...
UDP 50,000 - 59,999
| ||||||||||||||||
|
Multiexcerpt | ||||
---|---|---|---|---|
| ||||
DNS SettingsMake sure that CCE FQDN is resolving to the
|
Caption | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||
|
...
MultiExcerptName | DNSSettings |
---|
...
Spacevars | ||
---|---|---|
|
...
address. To do so, login to your DNS server and create the relevant entries. |
Spacevars | ||
---|---|---|
|
Update the
Spacevars | ||
---|---|---|
|
Note |
---|
|
Sonus recommends starting with a clean and empty configuration.
Caption | ||||
---|---|---|---|---|
| ||||
Info | ||||||||
---|---|---|---|---|---|---|---|---|
Optionally, if you want to configure a secondary |
If your ASM have been used before, you should re-Initialize it now. Refer to Re-Initializing the ASM for details.
Confirm that the ASM is ready to deploy the Cloud Connector Edition. To do so:
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Task tab and then select Operational Status. |
3 | Verify the following:
|
Caption | ||||
---|---|---|---|---|
| ||||
After you update the ASM, change its Admin Password.
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Settings tab and then click Change Admin |
...
...
Login to the WebUI of the SBC Edge.
...
Navigate to Tasks > Setup Cloud Connector Edition.
...
Click the ASM Config tab and configure/verify the Network and IP settings of your ASM.
...
Password. | |
3 | Enter and confirm your new password and then click OK. |
Caption | ||||
---|---|---|---|---|
| ||||
Deploying the CCE on the
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
Warning |
---|
|
...
|
Anchor | ||||
---|---|---|---|---|
|
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the ASM Config tab and configure/verify the Network and IP settings of your ASM. |
4 | From the Remote Desktop Enabled drop down list, select Yes (to enable Remote Desktop) or No (to disable Remote Desktop). |
5 | From the Windows Firewall Enabled drop down list, select Yes (to enable Windows Firewall) or No (to disable Windows Firewall). |
6 | From the Proxy Enabled drop down list, Enables use of the Proxy Server on the ASM. Select from the drop down list: Yes (enables Proxy Server on the ASM) or No (disables Proxy Server). |
7 | From the Proxy Address drop down list, select Yes (to enable the IP address for the Proxy Server in IPv4 format). This field is available only when Proxy Enabled is set to Yes. |
8 | From the Proxy Port drop down list, select Yes (to enable the port in which the Proxy Server connects). Valid entry: Valid entry: 1 - 65000. This field is available only when Proxy Enabled is set to Yes. |
9 | Configure/verify the Network and IP settings of your ASM. |
10 | Click Apply. After receiving the activity status as successfully completed, click the Generate CSR tab. |
Caption | ||||
---|---|---|---|---|
| ||||
This process is required only if you don't have a public certificate for your deployment. If you already have a certificate, proceed to Import Certificate.
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the Generate CSR tab. |
4 | Generate the CSR as shown below with following information. To ensure creating a valid CSR for Cloud Connector Edition usage, please see the section "Certificate requirements" on https://technet.microsoft.com/en-us/library/mt605227.aspx. |
5 | Copy the CSR from the lower pane of the Generate CSR page and save it as a .txt file. |
6 | After the CSR is signed by the Certificate Authority and you receive the PKCS7 Certificate file, continue the wizard by clicking on CCE Public Certificate tab. |
Caption | ||||
---|---|---|---|---|
| ||||
Anchor | ||||
---|---|---|---|---|
|
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition and click the CCE Public Certificate tab. |
3 | Click the Action drop-down list and select the appropriate option:
|
4 | After receiving the activity status as successfully completed, click on Configure CCE tab. |
Caption | ||||
---|---|---|---|---|
| ||||
|
Note |
---|
If you configure TLS and downgrade the system to a release prior to Release 7.0, the Exchange CA Certificate for TLS will be unavailable; you must re-deploy or upgrade to Release 7.0. Along with TLS configuration on the CCE, the TLS capability requires a loaded Root CA certificate and a signed certificate on the SBC. |
Step | Action | ||||
---|---|---|---|---|---|
1 | Login to the WebUI of the SBC Edge. | ||||
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. | ||||
3 | Click the Configure CCE tab. | ||||
4 | Configure all necessary information and then click OK. All the pre-configured fields are valid as is, and recommended by Sonus. These fields may be edited, but all entries must meet Microsoft requirements.
| ||||
5 | To increase Fast Failover (which shortens the time where certain ported numbers have a long delay from ITSP PSTN provider) configure Trunk Information: Refer Support. Indicates whether Gateways support Refer for a Call Transfer scenario. Valid entries: Enable (the Gateway(s) supports Refer which can handle call transfer) or Disable (the Gateway does not support Refer and the Mediation Server handles call transfer). Fast Failover Timer. Determines whether outbound calls that are not answered by the gateway within ten seconds will be routed to the next available trunk; if there are no additional trunks, the call will automatically be dropped. Valid entries: Enable or Disable. Forward Call History. Indicates whether call history information is forwarded through the trunk. Valid entries: Enable or Disable. Forward PAI. Indicates whether the P-Asserted-Identity (PAI) header will be forwarded along with the call. Valid entries: Enable or Disable. | ||||
6 |
After receiving the activity status as successfully completed, click the |
...
Prepare CCE tab to continue. |
Caption |
---|
...
0 | Figure |
---|---|
1 | ASM Config |
...
| ||||
Info |
---|
See Managing Cloud Connector Edition Private Certificates for the following setup options:
|
Anchor | ||||
---|---|---|---|---|
|
This process is required only if you don't have a public certificate for your deployment. If you already have a certificate, proceed to Import Certificate.
...
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate |
...
Generate the CSR as shown below with following information. To ensure creating a valid CSR for Cloud Connector Edition usage, please see the section "Certificate requirements" on https://technet.microsoft.com/en-us/library/mt605227.aspx .
...
to Tasks > Office 365 Cloud Connector Edition> Setup. | |
3 | Click the Prepare CCE tab. |
4 | Click the Prepare CCE button. A confirmation will request you to enter the password again for the new password. Only the Tenant credentials are already existing. Click OK as shown below. |
5 | After confirmation, click on Customize CCE VMs. |
Caption | ||||
---|---|---|---|---|
| ||||
This step stores the two Microsoft product keys, and customizes the CCE VM (which is not yet activated).
Info |
---|
The CCE requires four VMs; each Microsoft Product Key activates two VMs. |
...
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to |
...
Tasks > |
...
Office 365 Cloud Connector Edition |
...
> Setup. | |
3 | Click the |
...
...
Select the relevant certificate file using the Choose File button and then click OK.
...
Select the file by browsing to it using Select File.
...
Click OK.
...
After receiving the activity status as successfully completed, click on Configure CCE tab.
...
Customize CCE VMs tab. | |
4 | In Domain Controller and Central Management Store VM > Windows Product Key 1, enter the first Microsoft Product Key. To identify the Product Key, see Identify Microsoft Product Key. |
5 | In Under Mediation Server and Edge Server VM > Windows Product Key 2, enter the second Microsoft Product Key.To identify the Product Key, see Identify Microsoft Product Key. |
6 | From the Proxy Usage drop down list, select Enabled (enables the Proxy Server on the DMZ facing the internal network) If you select Disable, the Proxy Server is disabled. |
7 | In the Proxy Server IP Address field, enter the server IP address for the Proxy Server in IPv4 format. This field is available only when Proxy Usage is set to Enabled. |
8 | In the Proxy Server Port field, enter the port number for the Proxy Server. Valid entry: 1 - 65535. This field is available only when Proxy Usage is set to Enabled. |
9 | Click Apply. |
10 | Access Tasks> Operational Status to verify Windows Activation. If activation fails, see Troubleshooting. |
11 | Click on CCE Private Certificate |
Warning |
---|
If the deployment environment consists of multiple-site with a single certificate or a wild card certificate, ensure the CCE Site Name and the Edge Server Public Hostname are correct before proceeding. |
...
. |
Caption | |||
---|---|---|---|
|
...
| |
|
...
Info |
---|
...
| ||
|
...
|
Info | ||||||
---|---|---|---|---|---|---|
| ||||||
|
...
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Open the Tasks tab and click Setup Cloud Connector Edition in the navigation pane. |
3 | Click the Prepare CCE tab. |
4 | Click the Prepare CCE button. A confirmation will request you to enter the password again for the new password. Only the Tenant credentials are already existing. Click OK as shown below. |
5 | To complete the deployment, continue with installing the CCE Appliance using the Sonus Cloud Link Deployer. |
...
0 | Figure |
---|---|
1 | Prepare the CCE |
...
Anchor | ||||
---|---|---|---|---|
|
...
...
title | CCE Deployment - Using a Proxy on the ASM Host |
---|
...
Note | ||
---|---|---|
| ||
|
...
|
Step | Action |
---|---|
1 | Remote desktop to the ASM system. |
2 | Launch the Sonus Cloud Link Deployer from icon on the desktop. |
3 | Check the first three actions:
Select Apply. |
Caption | ||||
---|---|---|---|---|
| ||||
After the CCE is deployed, integrate the Sonus SBC Edge and allow calls from/to O365 clients. In this example, the following steps will set up the Sonus SBC Edge for:
SIP Provider (NNN.NNN.NNN.NNN) – SBC Edge (NNN.NNN.NNN.NNN) – CCE (mediation Server: NNN.NNN.NNN.NNN) – O365 Cloud |
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Tasks tab, and then click SBC Easy Setup > Easy Config Wizard in the navigation pane. |
3 | Follow steps 1, 2, and 3 as shown below and then click Finish.
|
4 | Click OK on the next two popups to complete the setup. |
5 | The wizard configures the necessary settings for the single SBC Edge and CCE integration. Relevant configuration items are shown in the Settings tab below:
|
Step | Action |
---|---|
1 | Login to the WebUI of the Secondary SBC Edge. |
2 | Click the Tasks tab and then run the Easy Config. |
3 | The preceding step will configure the Secondary SBC Edge with the appropriate configuration items. |
Multiexcerpt | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
Basic Call Verification after CCE Deployment and Spacevars |
|
Spacevars | ||
---|---|---|
|
...
Similarly, a Skype For Business (O365) client can dial the number of an endpoint off of ITSP and reach out to it over
|
Multiexcerpt | ||||
---|---|---|---|---|
| ||||
O365 Known Issue and Workarounds for CCERedeploying the CCE
|
...
Clean Office 365 tenantIf the CCE was previously deployed, previously installed information must be cleared in O365. To do so, follow the steps below |
...
:
|
...
|
...
Select the appropriate image from the drop-down list and then click Apply.
If the CCE was previously deployed, previously installed information must be cleared in O365. To do so, follow the steps below:
Step | Action |
---|---|
1 | Remote Desktop to the ASM system |
2 | Connect the Office365 Tenant through a series of commands as follows: a. Execute the following command: Import-Module skypeonlineconnector $cred = Get-Credential b. When prompted, execute the credentials for O365 Admin Tenant. c. Execute the following command: $Session = New-CsOnlineSession -Credential $cred -Verbose Import-PSSession $session |
3 | Display all the Appliances assigned to your tenant, identify the Appliance you just re-initialized, and copy the identity into your clipboard.
|
4 | Execute the following command to remove the appliance:
|
5 | Execute the following command to verify that the appliance has been removed:
|
6 | This completes the cleanup. |
...
Re-Initializing of the ASMThe ASM must be re-initialized with the image that contains the latest CCE software . To do so:
|
The “.ini” file is the configuration of the Microsoft CCE (Cloud Connector Edition) running on the ASM. The
...
contents of the ".ini" file must be as defined by Microsoft. From the Configure CCE panel, the Raw INI Config drop-down list enables you to edit, export, or import the ".ini" file.
Working with the ".ini" file
...
allows you to provision multiple CCEs in a similar manner. Once you configure a CCE, you can export the ".ini" file, modify it for the second system, and then import the CCE. This procedure can then be repeated for the third system, etc. Also, backing up the SBC configuration and CCE configuration helps recover faster in the case of lost data.
Step | Action |
---|---|
1 | After receiving the activity status completion message, click the Click to re-configure CCE application button. |
2 | Click OK on the popup. |
4 | Click the Raw (INI) Config drop-down list, select Edit. Configurable fields are displayed for editing. Modifications to the CCE configuration requires redeployment of the CCE VM, and this action takes approximately two hours. Note: The example uses AEPSITE2 for the these attributes. |
5 | After verifying the information click OK. |
Step | Action |
---|---|
1. |
Working with the ".ini" file allows you to provision multiple CCEs in a similar manner. Once you configure a CCE, you can export the ".ini" file, modify it for the second system, and then import the CCE. This procedure can then be repeated for the third system, etc. Also, backing up the SBC configuration and CCE configuration helps recover faster in the case of lost data.
...
After receiving the activity status completion message, click the Click to re-configure CCE application button. | |
2. |
...
Click OK |
...
on the popup. |
...
3. |
...
From the Raw (INI) Config drop |
...
down list, |
...
select Import or Export.
|
Follow these steps if you need to update the O365 tenant admin password or account.
Note: The example uses AEPSITE2 for the these attributes.
...
After verifying the information click OK.
...
Step | Action |
---|---|
1 |
...
...
On the WebUI, click Tasks and select the Prepare CCE tab (see Preparing the CCE). |
2 |
...
Click |
...
Prepare CCE. |
3 |
...
From the |
...
Password Setting drop down list, |
...
select Change Password. Keep the same passwords for the Edge Server, CCE Service and CA Backup File, but change the passwords for Tenant Account User and Tenant Account Password. | |
4 | On Remote desktop, start the Sonus Cloud Link Deployer, and check Transfer Password from SBC to reset the credentials. |
Info |
---|
For details on Certificates, refer to Generating Certificate Signing Requests. |
Follow these steps to renew the CCE Public Certificate.
...
Follow these steps if you need to update the O365 tenant admin password or account.
...
Step | Action |
---|---|
1 | On the WebUI, |
...
click Tasks and select the Generate CSR. | |
2 | Sign the certificate with your public CA. |
3 | Import the new certificate into the Public Certificate tab. |
4 | Transfer the Certificate to the SBC Edge using the Public Certificate tab. |
...
Pagebreak |
---|