Configuring the TLS server profile for Avaya Aura Session Border Controller media tunneling

Last Updated : Dec 08, 2020 |

About this task

With a TLS profile, Avaya Aura® Session Border Controller can control parameters when it performs a TLS handshake with a remote entity. HTTPS media tunneling requires its own TLS server profile. Session Border Controller supports media tunneling for sign-in and guest users. This configuration is required only for external mobile calls that are inbound towards Session Border Controller.

Procedure

  1. Log on to the EMS web interface with administrator credentials.
  2. In the Device drop-down list, select ASBCE.
  3. In the navigation pane, click TLS Management > Server Profiles.
  4. On the Server Profiles page, click Add.
  5. In the Profile Name field, type the name of the profile.
  6. In the Certificate field, select the certificate that the TLS server profile uses for external communication.
  7. In the SNI Options field, click None.
  8. In the Peer Verification field, click Optional.
  9. Leave the Peer Certificate Authorities field empty.
  10. Leave the Peer Certificate Revocation Lists field empty.
  11. In the Verification Depth field, set the value to 1.
  12. Leave the Extended Hostname Verification check box cleared.
  13. In the Renegotiation Time field, set the value to 0.
  14. In the Renegotiation Byte Count field, set the value to 0.
  15. In the Version of handshake options field, select TLS 1.2.
  16. In the Ciphers field, set the value to Default.

    For more information, see Administering Avaya Session Border Controller.

  17. Click Finish.