Collapse AllExpand All

14.5.5.5. Configuration Example OpenScape SBC Previous topic Parent topic Child topic Next topic

In this chapter an example configuration for the OpenScape SBC with the Telekom Deutschland GmbH (TDG) - DeutschlandLAN SIP-Trunk is described. In this case the OpenScape SBC registers itself to the DeutschlandLAN SIP-Trunk instead of the OS4K gateway.
Further OpenScape SBC documentation (e. g. configuration of “Clustered Mode” for connecting multiple Gateways and/or multiple OS4Ks), please refer to the official OpenScape SBC Configuration Guide (such as OpenScape SBC, Configuration Guide, Administrator Documentation).
The configuration data needs to be taken from the Telekom letter:

Figure 262. Deutsche Telekom letter

telekom-2.png
1. DNS
It must be configured a DNS server which can resolve the Telekom DNS records configured in the Remote Endpoints:

Figure 263. 2. Quality of Service (QoS)

telekom1-2.jpg
Telekom has specified in their 1TR114 document QoS requirements which must be applied on OpenScape SBC:
telekom2-2.jpg
telekom3-2.jpg
3. Media Profile
Depending on whether the SIP trunk is encrypted via TLS or not, one of the two example Media Profiles in the screenshot need to be used:

Figure 264. For an unencrypted SIP trunk the Media Protocol RTP was used:

telekom4-2.jpg
telekom5-2.jpg
For an encrypted SIP trunk the Media Protocol SRTP and SDES to negotiate the cryptographic parameters was used. MIKEY may not be enabled because it’s not supported by Telekom.
telekom6-2.jpg
How to activate the defined Media Profile for the SIP trunk is described in the section Remote Endpoint below.
4. Remote Endpoint
On the OpenScape SBC must be activated Enable Remote Endpoints:
telekom7-2.jpg
When opening the Remote Endpoints window the SIP Service Provider Profile and the Remote Endpoint has to be configured:
telekom8-2.jpg
In the SIP Service Provider Profile window must be selected as default SSP profile DTAG/NGN Registration Mode. The registration interval has to be set to 480 seconds:
telekom9-2.jpg
telekom10-2.jpg
In the Remote Endpoint Configuration window the SIP Service Provider Profile shown above has to be selected:
telekom11-2.jpg
telekom12-2.jpg
If a NAT router is in between SBC and SIP Trunk Open external firewall pinhole must be enabled so OpenScape SBC will open the RTP port on the NAT router by sending UDP packets to let the NAT router pass RTP packets from a PSTN phone.
The figures below show the Remote Location Domain window for an unencrypted SIP trunk using TCP and RTP on the left and for an encrypted SIP trunk using TLS and SRTP on the right:
telekom13-2.jpg
5. Preparing and Installing TLS Certificates
For using TLS and SRTP over the SIP trunk uploading and configuration of the TLS certificates on OpenScape SBC is required:
INFO:
Please make sure that the certificates are still valid. In case they are expired or not available anymore, please contact Telekom Deutschland GmbH or use the ones from the public websites.
Because the OpenScape SBC supports only certificates in pem format the Telekom ‚Shared Business CA‘ certificate Shared_Business_CA4.der has to be converted
telekom14-2.jpg
Click on Convert Certificate and save the converted certificate with file extension .pem.
Create in the next step a chained certificate based on the certificates Deutsche Telekom Root CA 1 and Shared Business CA named e.g. dt-chain-ca.pem and copy the content of this certificate files into it in the following order:
Because the OpenScape SBC supports only certificates in pem format, the Telekom "Shared Business CA" certificate T-TeleSec_GlobalRoot_Class_2.cer has to be converted via Linux shell. For example, on the OpenScape SBC run the command:
openssl x509 -inform der -in T-TeleSec_GlobalRoot_Class_2.cer -out T-TeleSec_GlobalRoot_Class_2.cer.pem
INFO:
For more information, please refer to the OpenScape SBC V10 Configuration Guide.
Then upload this certificate via GUI at Security -> General -> Certificate Management into OpenScape SBC in the in section CA Certificates by selecting this certificate and clicking on Upload. Then the certificate appears in the CA certificates list:
telekom15-2.jpg
To replace the OpenScape SBC default certificates provided by installation execute the following steps:
In Certificate Creation section enter e.g. ossbc in the Name field an click on Create leaving Self signed as CA file unchanged:
telekom16-2.jpg
In the CA certificates, X.509 Certificates and Key files windows appears now the new certificates:

Figure 265. In the Certificate Profiles section click on Add:

telekom17-2.jpg

Figure 266. Create a new Certificate Profile selecting the certificates created before:

telekom18-2.jpg
telekom19-2.jpg
Finally the created Certificate Profile has to be configured in the Remote Location Domain window:
6.Configuration of VOIP Settings towards OS4K

Figure 267. Configuration of VOIP Settings towards OS4K

telekom20-2.jpg
(Example is using Non-Secure TCP, in case of Secure TLS please adapt accordingly e. g. 5061)
sip_provider14-2.png
sip_provider15-2.png
sip_provider16-2.png
7. OS4K Gateway configuration (OpenScape SBC Core IP = 172.29.179.80) (Example is using Non-Secure TCP, in case of Secure TLS please adapt accordingly to use TLS Ports etc)
sip_provider17-2.png