Anchor | ||||
---|---|---|---|---|
| ||||
Excerpt Include |
add_workflow_for_ | UXDOC61:Not_for_SWe |
---|---|
nopanel | true |
Warning | ||
---|---|---|
| ||
You must follow these steps completely and in the order shown. Failure to do so increases the risk of node failure. |
Panel | ||||
---|---|---|---|---|
In this section...
|
Info |
---|
For details on troubleshooting, see Troubleshooting Cloud Connector 6.1.2. |
Multiexcerpt include | ||||
---|---|---|---|---|
|
Scenario 1 and Scenario 2 are covered in Configuring the SBC Edge for a Single CCE. This document contains steps for Scenario 3 and Scenario 4 .
Multiexcerpt include | ||||
---|---|---|---|---|
|
Note |
---|
We recommend deploying both Appliances on the same subnet with a resilient connection. |
For the purposes of this document, the CCE is deployed in the following network:
Caption | ||||
---|---|---|---|---|
| ||||
|
techpubs | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Excerpt Include | ||||||
---|---|---|---|---|---|---|
|
Warning | ||
---|---|---|
| ||
You must follow these steps completely and in the order shown. Failure to do so increases the risk of node failure. |
Panel | ||||
---|---|---|---|---|
In this section...
|
Note |
---|
SBC Edge now supports a new deployment with CCE 2.1.0 in release 7.0.1. Before this release, if your CCE auto-updates to CCE 2.1.0:
|
Info |
---|
For details on troubleshooting, see Troubleshooting Cloud Connector. |
Multiexcerpt include | ||||
---|---|---|---|---|
|
Scenario 1 and Scenario 2 are covered in Configuring the SBC Edge for a Single CCE. This document contains steps for Scenario 3 and Scenario 4.
Multiexcerpt include | ||||
---|---|---|---|---|
|
Note |
---|
We recommend deploying both Appliances on the same subnet with a resilient connection. |
For the purposes of this document, the CCE is deployed in the following network:
Caption | ||||
---|---|---|---|---|
| ||||
|
In this best practice the router/firewall is configured with the following rules:In this best practice the router/firewall is configured with the following rules:
Caption | |||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||||||||||||||||||||||||||||||
Source IP | Destination IP | Source Port | Destination Port | ||||||||||||||||||||||||||||||||||||||||||
Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | Internal clients | TCP 49 152 – 57 500* | TCP 50,000-50,019 (Optional) | ||||||||||||||||||||||||||||||||||||||||||
Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | Internal clients | UDP 49 152 – 57 500* | UDP 50,000-50,019 | ||||||||||||||||||||||||||||||||||||||||||
Internal clients | Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | TCP 50,000-50,019 | TCP 49 152 – 57 500* | Internal clients | Cloud Connector Mediation component – 192.168.210.123 & 192.168.210.117 | UDP 50,000-50,019 | UDP 49 152 -57 500*|||||||||||||||||||||||||||||||||||||||
Caption | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
|
Caption | ||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||||||||||||||||||
|
Multiexcerpt include | ||||
---|---|---|---|---|
|
Update the SBC Edge firmware to the latest release version.
Note |
---|
Ensure the Node FQDN is definitive. Changing this information requires the CCE to be redeployed. |
Sonus recommends starting with a clean and empty configuration.
Caption | ||||
---|---|---|---|---|
| ||||
|
Info | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
When configuring a secondary
|
If your ASM has been used previously, reinitialize it following the steps in Re-Initializing the ASM.
Confirm that the ASM is ready to deploy the CCE by following these steps.
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Task tab, and then click Operational Status. |
3 | Verify that:
|
4 | Change the ASM Admin password:
|
Deploying the CCE on the
Spacevars | ||
---|---|---|
|
Note |
---|
|
...
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | Action |
---|---|
1 | Login to the WebUI of both SBC Edge. |
2 | Navigate to Tasks > Setup Cloud Connector Edition. |
3 | Click the ASM Config tab and configure/verify the Network and IP settings of your ASM as shown below. |
4 | Click Apply. After receiving the activity status as successfully completed, click the Generate CSR tab. |
Caption | ||||
---|---|---|---|---|
| ||||
Caption | ||||
---|---|---|---|---|
| ||||
This process is required only if you don't have a public certificate for your deployment. If you already have a certificate, proceed to Import Certificate.
Note | ||||
---|---|---|---|---|
Perform these steps on only one of the
|
...
Navigate to Tasks > Setup Cloud Connector Edition > Generate CSR.
...
|
Caption | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||
|
Multiexcerpt include | ||||
---|---|---|---|---|
|
Update the SBC Edge firmware to the latest release version.
Note |
---|
|
Sonus recommends starting with a clean and empty configuration.
Caption | ||||
---|---|---|---|---|
| ||||
|
Info | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
When configuring a secondary
|
If your ASM has been used previously, reinitialize it following the steps in Re-Initializing the ASM.
Confirm that the ASM is ready to deploy the CCE by following these steps.
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Click the Task tab, and then click Operational Status. |
3 | Verify that:
|
4 | Change the ASM Admin password:
|
Deploying the CCE on the
Spacevars | ||
---|---|---|
|
Note |
---|
|
Anchor | ||||
---|---|---|---|---|
|
Generate the CSR as shown below with following information.
...
To ensure creating a valid CSR for Cloud Connector Edition usage, please see the section "Certificate requirements" on https://technet.microsoft.com/en-us/library/mt605227.aspx .
Caption | ||||
---|---|---|---|---|
| ||||
|
...
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | ActionAction | ||
---|---|---|---|
1 | Login to the WebUI of botheach SBC Edge. | ||
2 | Navigate to | Tasks Tasks > | Setup Office 365 Cloud Connector Edition | and then click the Import Certificate/Keys tab.
3 | On SBC-1, click the Action drop-down list and select the appropriate option:
| ||
4 | Click OK. | ||
5 |
|
...
> Setup. | ||
3 | Click the ASM Config tab and configure/verify the Network and IP settings of your ASM as shown below. | |
4 | From the Remote Desktop Enabled drop down list, select Yes (to enable Remote Desktop) or No (to disable Remote Desktop). | |
5 | From the Windows Firewall Enabled drop down list, select Yes (to enable Windows Firewall) or No (to disable Windows Firewall). | |
6 | From the Proxy Enabled drop down list, Enables use of the Proxy Server on the ASM. Select from the drop down list: Yes (enables Proxy Server on the ASM) or No (disables Proxy Server). | |
7 | From the Proxy Address drop down list, select Yes (to enable the IP address for the Proxy Server in IPv4 format). This field is available only when Proxy Enabled is set to Yes. | |
8 | From the Proxy Port drop down list, select Yes (to enable the port in which the Proxy Server connects). Valid entry: Valid entry: 1 - 65000. This field is available only when Proxy Enabled is set to Yes. | |
9 | Configure/verify the Network and IP settings of your ASM. | |
10 | Click Apply. After receiving the activity status as successfully completed, click the Generate CSR tab. |
Caption | ||||
---|---|---|---|---|
| ||||
Caption | ||||
---|---|---|---|---|
| ||||
This process is required only if you don't have a public certificate for your deployment. If you already have a certificate, proceed to Import Certificate.
Note | ||||
---|---|---|---|---|
Perform these steps on only one of the
|
Step | Action |
---|---|
1 | Login to the WebUI of one of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the Generate CSR tab. |
4 | Generate the CSR as shown below with following information. Note: This example uses aepsite1.sonusms01.com and sip.sonusms01.com as common name and SAN. To ensure creating a valid CSR for Cloud Connector Edition usage, please see the section "Certificate requirements" on https://technet.microsoft.com/en-us/library/mt605227.aspx. |
Caption | ||||
---|---|---|---|---|
| ||||
|
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | Action |
---|---|
1 | Login to the WebUI of the SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition and click the CCE Public Certificate tab. |
3 | On SBC-1, click the Action drop-down list and select the appropriate option:
|
4 | On SBC-2, click the Action drop-down list and select the appropriate option:
|
5 | After receiving the activity status as successfully completed, click on Configure CCE tab. |
Caption | ||||
---|---|---|---|---|
| ||||
|
Caption | ||||
---|---|---|---|---|
| ||||
Anchor | ||||
---|---|---|---|---|
|
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Note |
---|
If you configure TLS and downgrade the system to a release prior to Release 7.0, the Exchange CA Certificate for TLS will be unavailable; you must re-deploy or upgrade to Release 7.0. Along with TLS configuration on the CCE, the TLS capability requires a loaded Root CA certificate and a signed certificate on the SBC. |
Step | Action | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Login to the WebUI of the SBC Edge. | ||||||||||||||||
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. | ||||||||||||||||
3 | Click the Configure CCE tab. | ||||||||||||||||
4 | Configure all necessary information and then click OK.
Note: Enterthe ASM's IP address in the HA Master IP Address field. The Slave uses the same root certification as the Master, and this location contains the shared folder that contains the Root CA of the Master. | ||||||||||||||||
5 | To increase Fast Failover (which shortens the time where certain ported numbers have a long delay from ITSP PSTN provider) configure Trunk Information: Refer Support. Indicates whether Gateways support Refer for a Call Transfer scenario. Valid entries: Enable (the Gateway(s) supports Refer which can handle call transfer) or Disable (the Gateway does not support Refer and the Mediation Server handles call transfer). Fast Failover Timer. Determines whether outbound calls that are not answered by the gateway within ten seconds will be routed to the next available trunk; if there are no additional trunks, the call will automatically be dropped. Valid entries: Enable or Disable. Forward Call History. Indicates whether call history information is forwarded through the trunk. Valid entries: Enable or Disable. Forward PAI. Indicates whether the P-Asserted-Identity (PAI) header will be forwarded along with the call. Valid entries: Enable or Disable. | ||||||||||||||||
6 |
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Step | Action | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Login to the WebUI of the SBC Edge. | |||||||||||||||
2 | Open the Tasks tab and click Setup Cloud Connector Edition in the navigation pane. | |||||||||||||||
3 | Click the Configure CCE tab. | |||||||||||||||
4 |
Caption | ||||
---|---|---|---|---|
| ||||
|
Caption | ||||
---|---|---|---|---|
| ||||
|
...
Warning |
---|
...
Step | Action |
---|---|
1 | Login to the WebUI of both SBC Edge systems. |
2 | Open the Tasks tab and click Setup Navigate to Tasks > Office 365 Cloud Connector Edition in the navigation pane> Setup. |
3 | Click the Prepare CCE tab. |
4 | Click the Prepare CCE button. Enter the requested password. A confirmation will request you to enter the password again. The same password should be used on all Appliances in the site. Click OK as shown below. |
5 | To complete the deployment, continue with Activating the CCE. |
Anchor | ||||
---|---|---|---|---|
|
...
This step stores the two Microsoft product keys, and activates customizes the CCE VM (which is not yet activated).
Note | ||||
---|---|---|---|---|
Perform these steps on both
|
Info |
---|
Each CCE requires four VMs; each Microsoft Product Key activates two VMs. |
both
|
Info |
---|
Each CCE requires four VMs; each Microsoft Product Key activates two VMs. |
Step | Action |
---|---|
1 | Login to the WebUI of each SBC Edge. |
2 | Navigate to Tasks > Office 365 Cloud Connector Edition> Setup. |
3 | Click the Cutomize CCE VMs tab. |
4 | In Domain Controller and Central Management Store VM > Windows Product Key 1, enter the first Microsoft Product Key. To identify the Product Key, see Identify Microsoft Product Key. |
5 | In Under Mediation Server and Edge Server VM > Windows Product Key 2, enter the second Microsoft Product Key.To identify the Product Key, see Identify Microsoft Product Key. |
6 | From the Proxy Usage drop down list, select Enabled (enables the Proxy Server on the DMZ facing the internal network) If you select Disable, the Proxy Server is disabled. |
7 | In the Proxy Server IP Address field, enter the server IP address for the Proxy Server in IPv4 format. This field is available only when Proxy Usage is set to Enabled. |
8 | In the Proxy Server Port field, enter the port number for the Proxy Server. Valid entry: 1 - 65535. This field is available only when Proxy Usage is set to Enabled. |
9 | Click Apply. |
10 | |
Step | Action |
1 | Login to the WebUI of each SBC Edge. |
2 | Open the Tasks tab and click Setup Cloud Connector Edition in the navigation pane. |
3 | Click the Activate CCE tab. |
4 | In Domain Controller and Central Management Store VM > Windows Product Key 1, enter the first Microsoft Product Key. To identify the Product Key, see Identify Microsoft Product Key. |
5 | In Under Mediation Server and Edge Server VM > Windows Product Key 2, enter the second Microsoft Product Key. To identify the Product Key, see Identify Microsoft Product Key. |
6 | Click Activate. |
7 | Access Tasks> Operational Status to verify Windows Activation. |
11 If activation fails, see Troubleshooting.8 | To complete the deployment, continue with installing the Installing the CCE Appliance using Sonus Cloud Link Deployer. |
Caption | ||||
---|---|---|---|---|
| ||||
|
Info | ||||||
---|---|---|---|---|---|---|
| ||||||
|
Info | ||||||
---|---|---|---|---|---|---|
| ||||||
|
Info |
---|
See Managing Cloud Connector Edition Private Certificates for the following setup options:
|
...
Anchor | ||||
---|---|---|---|---|
|
|
...
|
...
Note | ||
---|---|---|
| ||
|
Using Sonus Cloud Link Deployer via Remote Desktop on the ASM Module:
...
Step | Action |
---|---|
1 | Remote desktop to the ASM of the SBC Edge System 1. |
2 | Launch the Sonus Cloud Link Deployer from icon on the desktop. |
3 | Check the last two actions:
|
4 | Click Apply. |
Caption | ||||
---|---|---|---|---|
| ||||
|
...
Caption | ||||
---|---|---|---|---|
| ||||
Multiexcerpt include | ||||
---|---|---|---|---|
|
Multiexcerpt include | ||||
---|---|---|---|---|
|
Follow these steps if you need to update the O365 tenant admin password or account.
Step | Action | ||
---|---|---|---|
1 | On the WebUI, run Preparing the CCE to specify a new Password. Select the existing password and enter the new password. Only the O365 should be modified for a running instance of CCE. | On the WebUI, click Tasks and select the Prepare CCE tab (see Preparing the CCE). | |
2 | Click Prepare CCE. | ||
3 | From the Password Setting drop down list, select Change Password. Keep the same passwords for the Edge Server, CCE Service and CA Backup File, but change the passwords for Tenant Account User and Tenant Account Password. | ||
42 | On Remote desktop, start the Sonus Cloud Link Deployer, and check Transfer Password from SBC to reset the credentials. |