Find answers to your technical questions and learn how to use our products
Search suggestions:
Find answers to your technical questions and learn how to use our products
Search suggestions:
The Registration tab and Heartbeat tab are not available when the Server type is administered as Remote Branch Office.
Name |
Description |
|---|---|
Server Type |
The type of SIP server for which this profile is being defined. The options are:
|
SIP Domain |
The SIP domain that validates the host name in a certificate. You must specify a SIP Domain when:
To validate the extended host name, Avaya SBC first looks for custom host names configured in the TLS profile. If the custom host name is blank, Avaya SBC then looks for the SIP Domain specified in the server configuration. |
DNS Query Type |
The DNS query type that Avaya SBC sends to the DNS server. The options are:
Note:
|
Inbound Connection Reuse Policy |
The inbound connection reuse policy for the SIP server. The options are:
This field only applies to the following SIP server types:
Note:
Avaya SBC supports a maximum of 256 inbound SIP server connections. This includes incoming connections from the following server types:
|
TLS Client Profile |
The TLS Client profile to be used for the SIP server. The TLS Client Profile option is activated only when DNS Query Type is set to NAPTR. |
IP Address/FQDN |
The IP address or Fully Qualified Domain Name (FQDN) of the SIP server. You can add multiple IP addresses or FQDNs. While configuring a Remote Branch Office server, if the Remote Branch Office is:
|
IP Address / FQDN / CIDR Range |
The EMS server displays this field when the Server Type is Trunk Server. The IP address, Fully Qualified Domain Name (FQDN) or CIDR range of the SIP server. You can add multiple IP addresses, FQDNs or CIDR ranges. When you configure CIDR range in the SIP Server by default CIDRs will be configured as whitelist entries. So Avaya SBC enables inbound calls from all IP addresses within the CIDR range. However, the CIDR will not be used for routing outbound calls. For example, in the case of Microsoft Direct Routing, inbound calls to the Avaya SBC can originate from any of the IP addresses within the CIDR blocks 52.112.0.0/14 and 52.120.0.0/14. By configuring these CIDRs along with the Direct Routing Server FQDNs, the Avaya SBC will no longer reject inbound calls from any IP address within the CIDR block. Outbound calls will still route to the resolved FQDN addresses. |
Verify TLS Common Name |
The EMS server displays this field when the Server Type is Remote Branch Office. The option for specifying whether the TLS common name must be verified during the TLS handshake. |
TLS Common Name |
The string used to verify whether the TLS connection from the IPO is valid. If the TLS Common Name configured in the server configuration does not match the TLS Common Name provided by the IPO, Avaya SBC rejects the TLS connection. Use one of the following values for the TLS Common Name field:
The EMS server displays this field only when the Server Type is Remote Branch Office. |
Port |
The port number. The Port field is not active when the Server Type is Remote Branch Office. |
Transport |
The type of transport protocols for the SIP server. The options are:
The Transport field is set to TLS when the Server Type is Remote Branch Office. |
Whitelist |
The call is not blocked if the call originator exists in the Whitelist. |
Avaya SBC supports the following secure digest algorithms for authentication challenge responses:
MD5 (Message digest)
SHA-256 (Secure Hash)
SHA-512
Secure digest algorithm is a simple challenge-response mechanism that allows a server (service provider) to challenge a client (Avaya SBC) request and allows a client (Avaya SBC) to provide authentication information in response to that challenge.
SHA-256 and SHA-512 are more secure and strong algorithms than the default algorithm, MD5.
For JITC deployments, Avaya SBC uses the algorithms in the following priority order (high to low):
SHA-512
SHA-256
For Non-JITC deployments Avaya SBC uses the algorithms in the following priority order (high to low):
SHA-512
SHA-256
MD5
Name |
Description |
|---|---|
Enable Authentication |
The field to indicate whether the SIP server requires authentication. If selected, authentication is required and the remaining fields are activated. If cleared, authentication is not required and the remaining fields remain inactivate. |
User Name |
The user name required for authentication. |
Realm |
The realm from which the legitimate authentication request is made. |
Password |
The password required for authentication. |
Confirm Password |
The password entered in the Password field. |
Name |
Description |
|---|---|
Enable Heartbeat |
Indicates whether a synchronization signal (heartbeat) is established between the Avaya SBC security device and the SIP server. Select this check box to indicate that a heartbeat is established and maintained and the remaining fields are activated. Clear the check box to indicate that no heartbeat is maintained and the remaining fields remain inactivated. |
Method |
Specifies the method by which the heartbeat is maintained. The options are:
|
Retry Timeout on Connection Failure |
Specifies the duration for which Avaya SBC pauses after raising the "Server down" incidence, and before sending the next heartbeat signal. The default value is 2 seconds. |
Frequency |
Specifies the frequency of sending the heartbeat signal. |
From URI |
Specifies the source of the heartbeat signal. |
To URI |
Specifies the destination of the heartbeat signal. |
Name |
Description |
|---|---|
Register with All Servers |
To send a REGISTER message to all servers.
|
Register with Priority Server |
To send a REGISTER message to the highest priority server as received in the DNS query response. Enable this option when using the DNS SRV for trunk registration feature. If the highest priority server is non-functional on DNS TTL expiry, Avaya SBC sends the REGISTER message to the second highest priority server. Register with Priority Server field is disabled if DNS query type is NONE/A. |
Refresh Interval |
Specifies the time, in seconds, after which Avaya SBC sends a REGISTER message to servers. |
From URI |
Specifies the source of the REGISTER message. |
To URI |
Specifies the destination of the REGISTER message. |
Name |
Description |
|---|---|
Enable Ping |
Select this option to enable ping on the server connections. |
Ping Interval |
Specifies the amount of time, in seconds, between ping messages sent to the server. |
Response Timeout |
Specifies the time, in seconds, after which a ping message times out. |
Name |
Description |
|---|---|
Enable DoS Protection |
Indicates whether DoS protection is enabled for the SIP server.
The EMS server does not display this option for a Recording Server. |
Enable Grooming |
Indicates whether the same connection is used for the same subscriber or port. You must enable this field while using TCP or TLS. The Enable Grooming field is enabled by default. If grooming changes are done on a production system, you must restart the application to clean up the old connections. The Enable Grooming field is unavailable when the Server Type is Remote Branch Office. |
Interworking Profile |
Specifies the Interworking profile to be used for the SIP server. |
Signaling Manipulation Script |
Specifies the signaling manipulation script for the SIP server. Specify a signaling manipulation script in this field in one of the following conditions:
Note:
If you select different scripts in the server configuration and the server flow, the EMS server uses the signaling manipulation script selected in the server flow. However, if you apply the manipulation as INBOUND and AFTER_NETWORK, the EMS server uses the script selected in the server configuration. |
Securable |
Specifies whether the server can be secured. Avaya endpoints can display an end-to-end secure indicator for calls that use secure protocols for both halves of the call. Avaya SBC provides a Securable field on the Server Configuration page to indicate whether the server is securable. Avaya SBC uses the Securable field to determine whether the trunk and call server can use secure protocols, and sets appropriate values for the Av-Secure-Indication header. |
Enable FGDN |
Enables a Failover Group Domain Name (FGDN) that Avaya SBC uses to route SIP traffic through an alternate Session Manager when a Session Manager is unreachable. |
TCP Failover Port |
Specifies the TCP port used during failover to the FGDN. This field is available only when you select the Enable FGDN check box. |
TLS Failover Port |
Specifies the TLS port used during failover to the FGDN. This field is available only when you select the Enable FGDN check box. |
Tolerant |
Specifies whether the server processes both IPv4 and IPv6 addresses. |
Traffic Type |
Specifies the traffic type. The options are:
The EMS server displays this field only when you select the Enable DoS Protection field. |
Max Concurrent Sessions |
Specifies the maximum number of concurrent sessions. The default value is 1000. The EMS server displays this field only when you select the Enable DoS Protection field. |
Number of Remote Users |
Specifies the number of remote users. The EMS server displays this field only when you select the Enable DoS Protection field. When you select the Remote Users or Trunk Traffic and Remote Users option, the EMS server enables the Number of Remote Users field. |
URI Group |
Select the URI group you want to use with this profile, if any. |
NG911 Support |
Select this option to enable NG911 support for NG911 CS trunks. This option is required for adhoc conference support. |
Name |
Description |
|---|---|
URI/Domain |
Specifies the URI or domain that is allowed from an external source. The EMS server displays this tab only when you select the Enable DoS Protection check box on the Advanced tab. |
Name |
Description |
|---|---|
Traffic Type |
The type of traffic. |
Max Concurrent Sessions |
The maximum number of concurrent sessions. |
SIP Service |
The SIP service affected by the DoS attack. The options are:
|
SIP Method |
The SIP Method of the SIP service. The options are:
|
Initiated Threshold (per 10 seconds) |
The maximum number of sessions that you can start within 10 seconds . |
Pending Threshold |
The maximum number of pending session initiations. |
Failed Threshold (per 10 seconds) |
The maximum number of failed session initiations. |
Action |
The action to be performed after any of the above thresholds are exceeded. The options are :
|