Configuring the Avaya Aura Session Border Controller media interface for external mobile client

Last Updated : Aug 27, 2021 |

About this task

Use this procedure to configure the media interface for external mobile client.

For detailed information about media tunneling, media interface, media video, and end point policy groups, see Administering Avaya Session Border Controller.

Before you begin

To configure the media interface, you must use the same listen IP interface that is selected for STUN/TURN. Therefore, ensure that you take a note of the listen IP interface.

Procedure

  1. Log on to the EMS web interface with administrator credentials.
  2. In the Device drop-down list, select ASBCE.
  3. In the navigation pane, click Network & Flows > Advanced Options.
  4. On the Feature Control tab, select the Media Tunneling check box and click Save.
  5. Click Add.
  6. Configure the external media interface: In the navigation pane, click Network & Flows > Media Interface.
  7. Click Add or clone an existing media rule.
  8. In the Name field, enter the name for the external media interface.
  9. In the IP Address field, enter the B1 IP address ensuring that you:
    • Do not use this IP address for any other interface bound to port 443 (HTTP tunneling configuration).

    • Do not use VLAN tag for media tunneled interface.

  10. In the Port Range field, enter a range such as 35000-40000.
  11. In the TLS Profile field, select the TLS server profile for the media interface that you created. For self-signed certificates on the client, use the TLS server profile created for the external media interface.

    If media tunneling is disabled, keep the value None.

  12. In the Buffer Size field, select the buffer size from the list containing values from 400 to 1000 in KB.
  13. Click Finish.
  14. Configure the internal media interface: In the navigation pane, click Network & Flows > Media Interface.
  15. Click Add or clone an existing media rule.
  16. In the Name field, enter the name for the internal media interface.
  17. In the IP Address field, enter the A1 IP address for media tunneling.
  18. In the Port Range field, enter a range such as 35000-40000.
  19. In the TLS Profile field, select the TLS server profile for the media interface that you created. For self-signed certificates on the client, use the TLS server profile created for the internal media interface.
  20. In the Buffer Size field, select the buffer size from the list containing values from 400 to 1000 in KB.
  21. Click Finish.
  22. Enable video media: In the navigation pane, click Domain Policies > Application Rules.
  23. Clone an existing rule or add a new rule.
  24. Enable In/Out Audio/Video application types.
  25. Configure Maximum Concurrent Sessions and Maximum Sessions Per Endpoint fields.
  26. Configure media encryption and enable BFCP/FECC: In the navigation pane, click Domain Policies > Media Rules.
  27. Clone an existing rule or add a new rule.
  28. On the Encryption tab, in the Miscellaneous section, select the Capability Negotiation check box.
  29. On the Advanced tab, select the BFCP Enabled and FECC Enabled check boxes.
  30. Configure the policy group with the newly created application and media rules: In the navigation pane, click Domain Policies > End Point Policy Groups.
  31. Clone an existing policy group or add a new policy group.
  32. Disable interworking when using HTTP tunneling: In the navigation pane, click Domain Policies > Media Rules > Encryption.
  33. Clear the Interworking check box.