Configuring Avaya Session Border Controller for Enterprise

Last Updated : Feb 11, 2019 |
Prolog information
A session border controller is a device used to exert control over incoming and outgoing signaling and media streams in an enterprise Avaya Aura® solution. It is typically deployed at the edge of a corporate network and used to control inbound and outbound sessions.
In the Presence Services to Microsoft external domain federation deployment, the Avaya Session Border Controller for Enterprise is used to isolate the Aura servers from the public network.
In addition to the configuration described in the Administering Avaya Session Border Controller for Enterprise guide, the following must be configured and or executed to setup federation:
Note:
It is strongly recommended that TLS 1.2 be used in all TLS Client and Server Profiles.
  1. Generate Avaya Session Border Controller for Enterprise identity certificate to be used in the TLS Client Profiles. This certificate will be used in creating TLS client connections to the Microsoft Edge server and also to the Session Manager in the internal Avaya Aura® network/domain.
  2. Retrieve the CA certificate from the Microsoft Edge server to import into the Avaya Session Border Controller for Enterprise.
  3. Retrieve the CA certificate from the Session Manager to import into the Avaya Session Border Controller for Enterprise. If the System Manager is used as the CA, the Session Manager CA can be downloaded from the System Manager by navigating to the ServicesSecurity CertificatesAuthorityCA Structure & CRLs page.
  4. Create two TLS Client Profiles for the outgoing connections to the Microsoft Edge and Session Manager.
  5. Create two TLS Server Profiles for the incoming connections from the Microsoft Edge and Session Manager.
  6. Configure an external Signaling Interface using the external TLS Server Profile.
  7. Configure an internal Signaling Interface using the internal TLS Server Profile.
  8. Create internal and external Media Interfaces.
  9. Create Server Interworking Profiles for both the Session Manager and Microsoft Edge.
  10. Create Server Configuration Profiles for both the Session Manager and Microsoft Edge.
  11. Default Application Rules can be used, as there is no customization required.
  12. Default Media Rules can be used, as there is no customization required.
  13. Default Signaling Rules can be used, as there is no customization required.
  14. Create two End Point Policy Groups for the Microsoft Edge and the Session Manager.
    1. The Microsoft Edge End Point Policy Group requires a Border Rule.
    2. The Session Manager End Point Policy Group uses defaults, as there is no customization required.
  15. Create two Routing Profiles for the Microsoft Edge and the Session Manager. Each Routing Profiles will use the specific Server Configuration Profile created for Microsoft Edge and Session Manager.
  16. Avaya Session Border Controller for Enterprise specific configuration for System Manager to Microsoft federation:
    1. The DNS server used by the Avaya Session Border Controller for Enterprise needs to be able to resolve the FQDN of the Microsoft Edge server.
    2. Enable topology hiding in both directions. Only enable topology hiding for the following headers: Via, SDP, and Record-Route. Specifically not Request-Line, To or From. This is required to enable back-to-back SIP dialogs between the Microsoft Edge and the Session Manager using FQDNs for Record Routes and Contact URIs.
    3. Setup a Border Rule for the Microsoft Edge End Point Policy Group. This changes the contact in the initial SUBSCRIBE message sent from the System Manager to use an FQDN instead of an IP address. This is required to enable the Microsoft Edge to properly send NOTIFYs back to System Manager.
    4. Create a Signaling Manipulation Rule to remove the GSID request URI parameter from the in-dialog SUBSCRIBEs sent from System Manager to the Microsoft Edge. This is required, since the Edge will not accept the modified in-dialog SUBSCRIBE request URI.
  17. Create two End Point Flows. End Point Flows associate the various configuration profiles and options together to control signaling messages that flow thru the Avaya Session Border Controller for Enterprise.