Remote phone support

Last Updated : Apr 03, 2019 |

IP phones using NAT router

IP Office supports remote 9600 Series IP phones with the H.323 FW which resides behind a NAT router to IP Office. The configuration does not require any VPN concentrator equipment. Remote 9600 H.323 IP phones can connect to IP Office even if it is located behind a NAT router. The phones are authenticated in the same way as phones in the private network. IP Office determines that a phone is located outside the private network and relays the VOIP RTP traffic to ensure it transverses the NAT router.
Note:

H.323 signaling and the media traffic is not encrypted.

To reach IP Office from the remote private network, remote H.323 IP phones need to be configured to the public IP address of the NAT router hosting the IP Office. Configurable ports need to be forwarded to IP Office. IP Office requires a valid public IP address be configured and the public IP address can be statically configured or dynamically discovered via a STUN server. The Remote Worker feature requires the Essential Edition license which provides 4 remote worker seats. Enable the Remote Worker feature using IP Office Manager. Additional remote worker capability is available with the Teleworker User or Power User licenses and a Preferred Edition license.

VPN phones

VPN phones provide secure communication over public ISP networks to IP Office at the company headquarters. It is a software-only product that runs on 5610/5620/5621 or 4610/21 IP phones. In combination with one of these phones and the most popular VPN gateway products, the software extends enterprise telephony to remote locations. VPN functionality is supported on 9600 IP phones, and does not require a separate software load. VPN phone has been tested with a number of VPN-gateways from major vendors like Cisco or Juniper as well as with smaller VPN-access devices from companies like Adtran, Kentrox, Netgear, and SonicWall. Refer to the Avaya Support website for a list of available application notes on VPN-gateways tested with each line of phones.

SIP phones using Avaya SBC

The Avaya Session Border Controller (Avaya SBC) sits on the edge of customer’s network with both internal and external IP interfaces. Using these IP interfaces, Avaya SBC functions as the gateway for SIP traffic into and out of the network. When used internally, SIP clients register to the IP Office directly. When used externally, the SIP clients connect to the Avaya SBC. This is achieved using Split DNS, which automatically resolves the FQDNs to the internal IP address of the IP Office or the public IP address of the Avaya SBC depending on where the clients are currently located. Apart from acting as a gateway, Avaya SBC also provides protection against any external SIP-based attacks. For privacy over the public internet, the public side of the Avaya SBC facing the remote workers must be configured to use the recommended values of TLS for signaling and SRTP for media encryption, as long as they are supported by the endpoints.