Server configuration profile field descriptions

Last Updated : Nov 19, 2024 |

General options

Note:

The Registration tab and Heartbeat tab are not available when the Server type is administered as Remote Branch Office.

Name

Description

Server Type

The type of SIP server for which this profile is being defined. The options are:

  • Trunk Server: To configure a trunk server.

  • Call Server: To configure a call server.

  • Media Server: To configure a media server.

  • Remote Branch Office: To configure a branch office in a remote site that connects to the enterprise through Avaya SBC.

  • Recording Server: To configure a Recording Server to record SIP sessions.

SIP Domain

The SIP domain that validates the host name in a certificate.

You must specify a SIP Domain when:

  • You have enabled extended host name validation.

  • Custom host name is blank in the client TLS profile associated in the server configuration.

To validate the extended host name, Avaya SBC first looks for custom host names configured in the TLS profile. If the custom host name is blank, Avaya SBC then looks for the SIP Domain specified in the server configuration.

DNS Query Type

The DNS query type that Avaya SBC sends to the DNS server. The options are:

  • None/A: Used when IP address or FQDN of A-query is configured in the EMS server. You must configure IP Address/FQDN, Port, and Transport fields to save any changes for the None/A type DNS query for the new SIP server profile.

  • SRV: Used when Avaya SBC sends the SRV type query to the DNS server. Use this setting when using the DNS SRV for trunk registration feature. You must configure FQDN in the IP Address/FQDN and Transport fields to save any changes for the SRV type DNS query for the new SIP server profile.

  • NAPTR: Used when Avaya SBC sends the NAPTR type query to the DNS server. You must configure FQDN in the IP Address/FQDN field to save any changes for the NAPTR type DNS query for the new SIP server profile.

Note:
  • Avaya SBC does not support AAAA-query for FQDN.

  • You can select DNS Query Type for Server Type as Trunk Server only.

Inbound Connection Reuse Policy

The inbound connection reuse policy for the SIP server. The options are:

  • None: With this option, Avaya SBC initiates a connection towards the SIP server and uses that connection for any outgoing requests from Avaya SBC. The default value is None.

  • Without alias: With this option, the SIP server initiates a connection towards Avaya SBC. SIP server does not add the alias parameter in the via header and Avaya SBC reuses the incoming connection to send any outgoing SIP requests.

  • Alias (RFC 5923): With this option, the SIP server initiates a connection towards Avaya SBC. SIP server adds the alias parameter in the via header and Avaya SBC reuses the incoming connection to send any outgoing SIP requests.

This field only applies to the following SIP server types:

  • Call server

  • Trunk server

  • Recording server

Note:

Avaya SBC supports a maximum of 256 inbound SIP server connections. This includes incoming connections from the following server types:

  • Call server (Inbound connection reuse policy not set to None)

  • Trunk server (Inbound connection reuse policy not set to None)

  • Recording server (Inbound connection reuse policy not set to None)

  • Remote Branch office

TLS Client Profile

The TLS Client profile to be used for the SIP server. The TLS Client Profile option is activated only when DNS Query Type is set to NAPTR.

IP Address/FQDN

The IP address or Fully Qualified Domain Name (FQDN) of the SIP server.

You can add multiple IP addresses or FQDNs.

While configuring a Remote Branch Office server, if the Remote Branch Office is:

  • Behind a NAT router, enter the IP address or FQDN of the public interface of the router.

  • Not behind a NAT router, enter the IP address or FQDN of the IPO that is used to connect to the Avaya SBC.

IP Address / FQDN / CIDR Range

The EMS server displays this field when the Server Type is Trunk Server.

The IP address, Fully Qualified Domain Name (FQDN) or CIDR range of the SIP server.

You can add multiple IP addresses, FQDNs or CIDR ranges.

When you configure CIDR range in the SIP Server by default CIDRs will be configured as whitelist entries. So Avaya SBC enables inbound calls from all IP addresses within the CIDR range. However, the CIDR will not be used for routing outbound calls. For example, in the case of Microsoft Direct Routing, inbound calls to the Avaya SBC can originate from any of the IP addresses within the CIDR blocks 52.112.0.0/14 and 52.120.0.0/14. By configuring these CIDRs along with the Direct Routing Server FQDNs, the Avaya SBC will no longer reject inbound calls from any IP address within the CIDR block. Outbound calls will still route to the resolved FQDN addresses.

Verify TLS Common Name

The EMS server displays this field when the Server Type is Remote Branch Office.

The option for specifying whether the TLS common name must be verified during the TLS handshake.

TLS Common Name

The string used to verify whether the TLS connection from the IPO is valid. If the TLS Common Name configured in the server configuration does not match the TLS Common Name provided by the IPO, Avaya SBC rejects the TLS connection. Use one of the following values for the TLS Common Name field:

  • FQDN

  • IP Address

  • Name

  • Domain beginning with a wild card (*)

The EMS server displays this field only when the Server Type is Remote Branch Office.

Port

The port number.

The Port field is not active when the Server Type is Remote Branch Office.

Transport

The type of transport protocols for the SIP server. The options are:

  • TCP

  • UDP

  • TLS

The Transport field is set to TLS when the Server Type is Remote Branch Office.

Whitelist

The call is not blocked if the call originator exists in the Whitelist.

Authentication options

Avaya SBC supports the following secure digest algorithms for authentication challenge responses:

  • MD5 (Message digest)

  • SHA-256 (Secure Hash)

  • SHA-512

Secure digest algorithm is a simple challenge-response mechanism that allows a server (service provider) to challenge a client (Avaya SBC) request and allows a client (Avaya SBC) to provide authentication information in response to that challenge.

SHA-256 and SHA-512 are more secure and strong algorithms than the default algorithm, MD5.

For JITC deployments, Avaya SBC uses the algorithms in the following priority order (high to low):

  • SHA-512

  • SHA-256

For Non-JITC deployments Avaya SBC uses the algorithms in the following priority order (high to low):

  • SHA-512

  • SHA-256

  • MD5

Name

Description

Enable Authentication

The field to indicate whether the SIP server requires authentication.

If selected, authentication is required and the remaining fields are activated.

If cleared, authentication is not required and the remaining fields remain inactivate.

User Name

The user name required for authentication.

Realm

The realm from which the legitimate authentication request is made.

Password

The password required for authentication.

Confirm Password

The password entered in the Password field.

Heartbeat options

Name

Description

Enable Heartbeat

Indicates whether a synchronization signal (heartbeat) is established between the Avaya SBC security device and the SIP server.

Select this check box to indicate that a heartbeat is established and maintained and the remaining fields are activated.

Clear the check box to indicate that no heartbeat is maintained and the remaining fields remain inactivated.

Method

Specifies the method by which the heartbeat is maintained. The options are:

  • OPTIONS

  • PING

Retry Timeout on Connection Failure

Specifies the duration for which Avaya SBC pauses after raising the "Server down" incidence, and before sending the next heartbeat signal.

The default value is 2 seconds.

Frequency

Specifies the frequency of sending the heartbeat signal.

From URI

Specifies the source of the heartbeat signal.

To URI

Specifies the destination of the heartbeat signal.

Registration options

Name

Description

Register with All Servers

To send a REGISTER message to all servers.

  • For the DNS Query Type as None/A, Avaya SBC sends the REGISTER message to the server configured in the DNS server or the resolved IP address by the DNS server.

  • For DNS Query Type as SRV or NAPTR, Avaya SBC sends the REGISTER message to all servers resolved in the DNS response.

Register with Priority Server

To send a REGISTER message to the highest priority server as received in the DNS query response. Enable this option when using the DNS SRV for trunk registration feature.

If the highest priority server is non-functional on DNS TTL expiry, Avaya SBC sends the REGISTER message to the second highest priority server.

Register with Priority Server field is disabled if DNS query type is NONE/A.

Refresh Interval

Specifies the time, in seconds, after which Avaya SBC sends a REGISTER message to servers.

From URI

Specifies the source of the REGISTER message.

To URI

Specifies the destination of the REGISTER message.

Ping options

Name

Description

Enable Ping

Select this option to enable ping on the server connections.

Ping Interval

Specifies the amount of time, in seconds, between ping messages sent to the server.

Response Timeout

Specifies the time, in seconds, after which a ping message times out.

Advanced options

Name

Description

Enable DoS Protection

Indicates whether DoS protection is enabled for the SIP server.

  • When you select the Enable DoS Protection check box, the EMS server displays Next at the bottom of the page. When you click Next, the EMS server displays a second Edit Server Configuration Profile – Advanced page, prompting for the number of users on the Call Server.

  • When you configure the DoS protection for the SIP server, the EMS server displays two new tabs: DoS Whitelist and DoS Protection on the Server Configuration page.

The EMS server does not display this option for a Recording Server.

Enable Grooming

Indicates whether the same connection is used for the same subscriber or port. You must enable this field while using TCP or TLS. The Enable Grooming field is enabled by default.

If grooming changes are done on a production system, you must restart the application to clean up the old connections.

The Enable Grooming field is unavailable when the Server Type is Remote Branch Office.

Interworking Profile

Specifies the Interworking profile to be used for the SIP server.

Signaling Manipulation Script

Specifies the signaling manipulation script for the SIP server.

Specify a signaling manipulation script in this field in one of the following conditions:

  • One server flow is associated with the server.

  • All server flows associated with the server use the same signaling manipulation script.

Note:

If you select different scripts in the server configuration and the server flow, the EMS server uses the signaling manipulation script selected in the server flow. However, if you apply the manipulation as INBOUND and AFTER_NETWORK, the EMS server uses the script selected in the server configuration.

Securable

Specifies whether the server can be secured.

Avaya endpoints can display an end-to-end secure indicator for calls that use secure protocols for both halves of the call. Avaya SBC provides a Securable field on the Server Configuration page to indicate whether the server is securable. Avaya SBC uses the Securable field to determine whether the trunk and call server can use secure protocols, and sets appropriate values for the Av-Secure-Indication header.

Enable FGDN

Enables a Failover Group Domain Name (FGDN) that Avaya SBC uses to route SIP traffic through an alternate Session Manager when a Session Manager is unreachable.

TCP Failover Port

Specifies the TCP port used during failover to the FGDN.

This field is available only when you select the Enable FGDN check box.

TLS Failover Port

Specifies the TLS port used during failover to the FGDN.

This field is available only when you select the Enable FGDN check box.

Tolerant

Specifies whether the server processes both IPv4 and IPv6 addresses.

Traffic Type

Specifies the traffic type. The options are:

  • Trunk Traffic

  • Remote Users

  • Trunk Traffic and Remote Users

The EMS server displays this field only when you select the Enable DoS Protection field.

Max Concurrent Sessions

Specifies the maximum number of concurrent sessions. The default value is 1000.

The EMS server displays this field only when you select the Enable DoS Protection field.

Number of Remote Users

Specifies the number of remote users.

The EMS server displays this field only when you select the Enable DoS Protection field.

When you select the Remote Users or Trunk Traffic and Remote Users option, the EMS server enables the Number of Remote Users field.

URI Group

Select the URI group you want to use with this profile, if any.

NG911 Support

Select this option to enable NG911 support for NG911 CS trunks. This option is required for adhoc conference support.

DoS Whitelist window

Name

Description

URI/Domain

Specifies the URI or domain that is allowed from an external source.

The EMS server displays this tab only when you select the Enable DoS Protection check box on the Advanced tab.

DoS Protection

Name

Description

Traffic Type

The type of traffic.

Max Concurrent Sessions

The maximum number of concurrent sessions.

SIP Service

The SIP service affected by the DoS attack. The options are:

  • TOTAL

  • Registrations

  • Calls

  • Presence Updates

  • Subscriptions

  • Misc

SIP Method

The SIP Method of the SIP service. The options are:

  • All

  • REGISTER

  • INVITE

  • SUBSCRIBE

  • PUBLISH

  • OPTIONS

Initiated Threshold (per 10 seconds)

The maximum number of sessions that you can start within 10 seconds .

Pending Threshold

The maximum number of pending session initiations.

Failed Threshold (per 10 seconds)

The maximum number of failed session initiations.

Action

The action to be performed after any of the above thresholds are exceeded.

The options are :

  • Alert Only: An alert displays the DoS incident, but the call is not blocked.

  • Enforce Limit: The call is not blocked until the specified limit is reached.

  • Enforce Limit Response: The call is blocked, and the EMS server sends the specified response when the specified limit is reached.

  • SIP Challenge: To initiate authentication.

    Note:

    Do not select the SIP Challenge action for a DoS profile configuration because Avaya phones do not respond the second time when they are again authenticated by Avaya after being challenged by Avaya SBC.

  • Whitelist: The call is not blocked if the call originator exists in the Whitelist.