Remote worker solution architecture

Last Updated : Sep 09, 2020 |

The following diagram depicts the high-level architecture of the remote worker solution with Avaya WebRTC Connect capabilities:

Figure : 1. Remote Avaya WebRTC Connect Worker Solution


Remote Avaya WebRTC Connect Worker Solution

The following diagram depicts the high-level architecture of the remote worker solution with Multimedia capabilities:

Figure : 2. Remote Multimedia Worker Solution


Remote Multimedia Worker Solution

All workers inside the bigger box use Avaya Oceana® FQDNs to directly access solution functionality on the internal LAN. All workers outside the bigger box are considered as external workers. The external workers must transit through firewall layers and network elements by using interfaces on the external firewall to connect to the Avaya Oceana® and Avaya Analytics™ applications. Customers must deploy this level of infrastructure so that remote workers can get secure access to enterprise applications.

For the remote worker capability, you must deploy and provision the following:

  • Avaya Aura® Session Border Controller that acts as a TURN relay for the WebRTC Connect voice media of agents.

    You must configure and enable the following on Session Border Controller:

    • One externally facing IP address on its external (B1) side.

    • One internally facing IP address on its internal (A1) side.

    • A certificate for the B1 external interface. You use this certificate for the reverse proxy.

    • A certificate for the A1 internal interface. You use this certificate for the reverse proxy.

  • External DNS capability to resolve the Avaya Oceana® and Avaya Analytics™ FQDNs to an IP address that is accessible from the Internet.

  • External firewall to provide a double layer of security (DMZ) between the Internet and the backend Avaya Oceana® servers.

    You must have an external firewall with the following configured items:

    • One external IP address on the WAN side.

    • One internal IP address on the LAN side.

    You must enable the following ports on the external firewall:

    • Port 443 for general signaling of the remote worker devices/clients to Avaya Oceana® AuthorizationService.

    • Port 9443 for authorization of the remote worker devices/clients to contact center applications.

  • Internal firewall

    You must have an internal firewall with the following configured items:

    • Up to six externally facing IP addresses on the external (WAN) side.

    • One internally facing IP address on the internal (LAN) side.

The following are the additional considerations for the remote worker solution:

  • You must use the split-horizon DNS so that on-premise and remote workers can use the same FQDNs to use Avaya Oceana®. However, the FQDNs resolve to different IP addresses depending on whether the agent is remote or on-premise.

  • All Avaya Oceana® FQDNs resolve to a single IP address on the external firewall and proxies are used internally to the correct Avaya Oceana® server or cluster based on the request URL from the client.

  • Minimum network characteristics must be achieved with the internet connection from the remote workers to the on-premise infrastructure containing the contact center.

    Remote workers utilize Avaya Workspaces, and its performance degrades, or it becomes unresponsive on network connections with a latency greater than 300 ms Round Trip Time (RTT). Remote workers must have a reliable internet connection that can deliver an RTT less than 300 ms.

  • Avaya Oceana® and Avaya Analytics™ are deployed and operational for all required channels.

  • On-premise agents can log in to Avaya Workspaces and process contacts.

  • Avaya Oceana® must completely use secure connections:

    • The Only allow secure web communication check box must be selected in the cluster attributes of all Avaya Oceana® clusters.

    • The Secure Communications attribute must be enabled in the OceanaConfiguration service.

  • Any screen-pops required for agents must be externalized so that they are accessible to the remote agents.