The Avaya SBCE is recommended to be located behind the Enterprise firewall, and serves as a security and demarcation device between the IP-PBX and the Carrier facility. Avaya also supports an implementation of the Avaya SBCE parallel to the firewall, although it is better as recommended for best practices security to put it behind the firewall as part of a layered defence strategy. The Avaya SBCE performs NAT traversal, securely anchors signalling and media, and can normalize SIP protocol implementation differences between carrier and Enterprise SIP implementations.
-
If an SBC or SIP Application Level Gateway (ALG) is deployed, some of the IP Office security measures must be moved from the IP Office to the SBC/ALG; the IP Office source IP address blacklisting should be disabled with the No User Source Number ‘B_DISABLE_SIP_IPADDR’. The SBC/ALG black/white listing must be activated to compensate.