Overview
When the SBC SWe Edge is deployed in Azure, the SBC SWe Edge supports Local Media Optimization.
The Central SBC and the Proxy SBC roles are supported in all deployments as follows:
- Confirm that in all deployments, private interfaces are assured between relevant parties, as identified at: https://docs.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization
- Secondly, acceptable network connectivity and performance between all nodes (typically indicated by KPIs) must be maintained for an acceptable level of LMO service.
- Exercise caution and ensure a high quality link to the Public Cloud (Azure) to ensure acceptable Central SBC/Proxy SBC roles and LMO behavior. Currently, Ribbon and Microsoft strongly encourage the use of ExpressRoute to ensure proper LMO performance.
- Ribbon and Microsoft reserve the right to decline support for LMO issues should proper care and network conditions not meet the requirements listed out in the point above.
This best practice uses the term Microsoft Teams Direct Routing, which is also known as Phone System Direct Routing.
This best practice outlines how to use the Ribbon SBC Edge Portfolio to configure Local Media Optimization for Microsoft Teams Direct Routing. Local Media Optimization allows the Microsoft Teams Direct Routing media flow to always use the shortest path to improve the SBC Edge Portfolio's media quality and bandwidth usage. The Microsoft Teams Direct Routing media flow can be directly established between the Teams client and the SBC, even if the SBC does not have Microsoft Teams Direct Routing connectivity. The SBC 1000, SBC 2000, and SBC SWe Edge support the Proxy and Downstream SBCs. For more details about this feature, refer to Local Media Optimization for Direct Routing.
This best practice describes greenfield and migration deployments and explains the requirements for each case. This best practice includes cautions to specify the deployment scenarios.
Though the SBC 1000, SBC 2000, and SBC SWe Edge support all Local Media Optimization roles for Microsoft Teams Direct Routing, this best practice uses the following configurations as examples:
the SBC SWe Edge as a Proxy SBC in the central site
- the SBC 1000 as a Downstream SBC in a local branch office
For the Proxy SBC, Ribbon recommends that you use the SBC SWe Edge because it has higher CPS (up to 10 CPS) and higher session density (up to 1200 simultaneous Direct Routing calls).
Make sure the licensed quantity of sessions on the SBC SWe Edge accommodates the maximum number of Local Media Optimization calls that the subtended (attached behind the Proxy SBC) Downstream SBCs carry.
Microsoft Limitations
Microsoft does not support Music on Hold. You should disable Music on Hold for all users that use Local Media Optimization. To disable Music on Hold, refer to Set-CsTeamsCallingPolicy.
Microsoft does not support Early 183. You should disable Early 183 for all SBC signaling groups that use Local Media Optimization. For information about Early 183, refer to the Early 183 section in Creating and Modifying SIP Signaling Groups.
Prerequisites
This section outlines the prerequisites for Local Media Optimization for Microsoft Teams Direct Routing.
SBC Capacity
When deploying Local Media Optimization, the Proxy SBC has to handle its usual local traffic plus all traffic from the Downstream SBC. You must make sure the Proxy SBC has the capacity and the license to handle the load. See the following load impacts:
- Call made to and from a Teams client that is internal to the customer network:
- The Proxy SBC consumes the Proxy Media Mode with Encryption resource.
- The Downstream SBC consumes the SIP with corresponding RTP Media resource.
- The Proxy SBC consumes the Proxy Media Mode with Encryption resource.
- Call made to and from a Teams client that is external to the customer network:
- The Proxy SBC consumes the SIP with corresponding RTP Media resource.
- The Downstream SBC consumes the SIP with corresponding RTP Media resource.
- The Proxy SBC consumes the SIP with corresponding RTP Media resource.
Microsoft Certified Endpoints
When using LMO for a Proxy Downstream SBC Deployment, all endpoints must be Microsoft compliant/certified.
Firmware Requirement
The Proxy SBC requires the following firmware:
- SBC SWe Edge: Release 8.1.5 Build 239 and later, or Release 9.0.0 and later.
- SBC Edge Portfolio: Release 9.0.x latest GA build.
Ribbon recommends the following versions for the Downstream SBC for an easier configuration:
- SBC SWe Edge: Release 8.1.5 Build 239 and later, or Release 9.0.0 and later.
- SBC Edge Portfolio: Release 9.0 latest GA build.
This document outlines only the recommended firmware.
Microsoft Direct Routing Configuration
You must configure the following for Microsoft Teams Direct Routing:
- You must plan the Microsoft Teams tenant for Local Media Optimization usage according to the Local Media Optimization for Direct Routing document.
- You must configure the Microsoft Teams tenant for Local Media Optimization usage according to the Configure Local Media Optimization for Direct Routing document. When you configure the Microsoft Teams Direct Routing, you must also configure the following items:
CsTenantTrustedIPAddress
CsTenantNetworkRegion
CsTenantNetworkSite
CsTenantNetworkSubnet
CSOnlinePSTNGateway
CsOnlineVoiceRoute
Licensing Requirements
The LMO functionality requires the Downstream SBCs to use a Proxy/Central SBC as a registrar, hence this requires the Proxy/Central SBC to have SIP Registration licenses. This applies for both 1000/2000 and SBC SWe Edge.
Certificate Usage
The Proxy SBC requires a certificate signed by a public certificate authority.
The Downstream SBC requires a certificate to support the encrypted media. This certificate can be signed by a private or public certificate authority.
Since the Proxy SBC and Downstream SBC use the same domain in this best practice, the SBC Edge Portfolio reuses the wildcard certificate from the Proxy SBC on each Downstream SBC.
Public Certificate
The public certificate must be issued by one of the supported certification authorities (CAs). Wildcard certificates are supported.
Refer to Microsoft documentation for certificate information.
Refer to CCADB Documentation for the comprehensive list of supported CAs.
- See Domain Name for certificate formats.
Domain Name
For the SBC Edge Portfolio to pair with Microsoft Teams, the SBC FQDN domain name must match a name registered in both the Domains and DomainUrlMap fields of the Tenant. Verify the correct domain name is configured for the Tenant as follows:
- On the Microsoft Teams Tenant side, execute Get-CsTenant.
- Review the output.
- Verify that the Domain Name configured is listed in the Domains and DomainUrlMap attributes for the Tenant. If the Domain Name is incorrect or missing, the SBC will not pair with Microsoft Teams.
Users may be from any SIP domain registered for the tenant. For example, you can configure user user@SonusMS01.com with the SBC FQDN name sbc1.hybridvoice.org, as long as both names are registered for the tenant.
Name Resolution
The Proxy SBC FQDN needs to be resolved in a publicly accessible DNS.
The Proxy SBC and Downstream SBC can resolve each other's FQDN with their private IP through using one of the following architectures:
This best practice uses host entries.
- host entries
- The Proxy SBC has a host entry resolve each Downstream SBC FQDN.
- The Downstream SBC has a host entry resolve the Proxy SBC FQDN to its private IP address.
- private DNS
- The Proxy SBC and Downstream SBC use a split DNS to resolve each other's FQDN with their private IP address.
Implementation
This best practice uses the FQDN and ports illustrated in the following figure.
Prepare Proxy SBC
This section outlines how to prepare the Proxy SBC.
Install SBC and Perform Initial Setup
Perform this procedure only if you are creating a new SBC for the Proxy role (a greenfield scenario).
Use the following procedure to install the SBC and perform the initial setup: Installing SBC SWe Edge
Run Easy Config Wizard on Proxy SBC
Once your SBC is up and running, you must configure the SBC to connect to the Microsoft Teams Direct Routing Server and allow the Downstream SBC connection.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Tasks > SBC Easy Setup > Easy Config Wizard.
In the Application field, select your application. This best practice configures the SIP Trunk ↔ Microsoft Teams.
- Configure the other fields in Step 1 and click Next.
In the SIP Trunk section, enter the information for the central SIP Trunk provider.
In the Teams Connection Type field, select Local Media Optimization.
Configure the other fields in the Microsoft Teams section and click Next.
Review your configuration information in Step 3 and click Finish.
Import Certificate on Proxy SBC
This section outlines how to import a certificate on the Proxy SBC.
Configure and Generate Certificates on the SBC
Update the Current Call Routing
Perform this procedure only if you are using a node that is already configured with another signaling group (a migration scenario).
If this is not a newly deployed SBC and you have already configured one of the following, follow the corresponding instructions:
If you configured a SIP Trunk or PSTN Access on this SBC, you must perform the following procedure to select the previously created signaling group in the From Microsoft Teams Direct Routing table (see the following example call flow).
Select Settings > Call Routing > Call Routing Table.
- Select the call routing table for Microsoft Teams Direct Routing.
Select the To Outside (Passthrough) route entry.
In the Destination Signaling Groups field, select the Border Element signaling group and click Remove.
In the Destination Signaling Groups field, click Add and add your previously created SIP Trunk or PSTN Access.
In the Audio Stream Mode field, select Direct Preferred over DSP.
Click Apply.
- Click Signaling Groups.
- Delete the Border Element signaling group.
If you configured a connection to Teams Direct Routing or Skype for Business, you must remove the previously created signaling group (see the following example call flow).
Disable Validate Server FQDN in TLS Profile
This section applies to only the Proxy SBC.
Use the following procedure to disable the Validate Server FQDN in the TLS Profile.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Settings > Security.
- From the TLS Profiles drop-down menu, select the TLS profile for the Teams Direct Routing TLS.
- In the Validate Server FQDN field, select Disabled.
Verify the Deployment
After you configure the Proxy SBC, use the following procedure to verify that the SBC works properly.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Settings > Signaling Groups.
Make sure the Service Status for all signaling groups is Up.
- If the Service Status for the Teams Direct Routing signaling group is Down, refer to Best Practice - Troubleshoot Issues with Microsoft Teams Direct Routing.
Prepare Downstream SBC
You must perform the procedures in this section for each Downstream SBC you must add. Make sure the FQDN for each Downstream SBC is different.
The information to prepare a Downstream SBC applies to both the SBC 1000/2000 and SBC SWe Edge unless otherwise stated.
When the SBC Edge Portfolio is acting as the Downstream SBC and interacting with the SBC Core, the Key Identifier Length in the SRTP should be configured as "0". The SBC Core does not support MKI and ignores the Crypto lines which has the MKI parameter.
Install SBC and Perform Initial Setup
Perform this procedure only if you are creating a new SBC for the Downstream role (a greenfield scenario).
Use the following procedure to install the SBC and perform the initial setup: Installing SBC 1000/2000
For the SBC SWe Edge, use the following procedure to install the SBC and perform the initial setup: Installing SBC SWe Edge
Run Easy Config Wizard on Downstream SBC
Once your SBC is up and running, you must configure the SBC to connect to the Proxy SBC.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Tasks > SBC Easy Setup > Easy Config Wizard.
In the Application field, select your application. This best practice configures SIP Trunk ↔ Microsoft Teams.
In the Teams Connection field, select Teams Downstream SBC.
- Configure the other fields in Step 1 and click Next.
In the SIP Trunk section, enter the information for the Branch 1 SIP Trunk provider.
CautionYou must target the Proxy with an FQDN for the TLS to properly establish.
- Configure the other fields in the Microsoft Teams section and click Next.
Review your configuration information in Step 3 and click Finish.
Import Certificate on Downstream SBC
Since the Proxy SBC and Downstream SBC use the same domain in this best practice, the SBC Edge Portfolio reuses the wildcard certificate from the Proxy SBC on each Downstream SBC.
If your deployment requires a different certificate for the Downstream SBC, see Configure and Generate Certificates on the SBC.
Configure Proxy FQDN Resolution on Downstream SBC
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Settings > Protocols > DNS > Hosts.
Click the + icon to create a host entry.
Enter the FQDN and IP address for the Proxy SBC.
Configure Downstream FQDN Resolution on Proxy SBC
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Settings > Protocols > DNS > Hosts.
Click the + icon to create a host entry.
Enter the FQDN and IP address for the Downstream SBC.
Update the Current Call Routing
Perform this procedure only if you are using a node that is already configured with another signaling group (a migration scenario).
If this is not a newly deployed SBC and you have already configured one of the following, follow the corresponding instructions:
If you configured a SIP Trunk or PSTN Access on this SBC, you must perform the following procedure to select the previously created signaling group in the From SBC as Teams Downstream table (see the following example call flow).
Select Settings > Call Routing > Call Routing Table.
- Select the call routing table for the SBC as Teams Downstream.
Select the To Outside (Passthrough) route entry.
In the Destination Signaling Groups field, select the Border Element signaling group and click Remove.
In the Destination Signaling Groups field, click Add and add your previously created SIP Trunk or PSTN Access.
- Click Apply.
- Click Signaling Groups.
- Delete the Border Element signaling group.
If you configured a connection to Teams Direct Routing or Skype for Business, you must remove the previously created signaling group (see the following example call flow).
Verify the deployment
After you configure the Downstream SBC, use the following procedure to verify that the SBC works properly.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
Select Settings > Signaling Groups.
Make sure the Service Status for all signaling groups is Up.
Place a Test Call
Use the following procedure to place a test call.
- Access a compatible web browser.
- In the browser, enter the IP address of the SBC Edge Portfolio in the URL address bar. The Welcome to Ribbon screen is displayed.
- Review the Pre-Login message.
- Enter the administrator User Name and Password configured during initial setup.
- If the Acknowledge Pre-Login Message checkbox is displayed, click on it to acknowledge you have reviewed the pre-login information above. After initial login, this checkbox can be enabled and disabled via the Global Security Options. By default, this checkbox is configured as disabled.
Click Login. The main screen provides all WebUI functions, including tabbed options, menu tree, device name, and the last login date and time of the system.
In the WebUI, click the Diagnostics tab.
In the left navigation pane, click Test a Call.
Configure the parameters according to your SBC.
Use the following table to configure the parameters for a Proxy SBC.
See the following example configuration of testing a call for a Proxy SBC.
Use the following table to configure the parameters for a Downstream SBC.
See the following example configuration of testing a call for a Downstream SBC.
Click OK.