There are several SBC solution concepts in an OpenScape 4000 environment,
e. g. usage of OpenScape SBC, Hosted OpenScape SBC (hSBC) or other 3rd-Party
SBC. Independent of that the OpenScape 4000 components (Gateways) provide
a “Built-in SBC” function that is always automatically active
when VoIP connections have to be transmitted via an Internet telephony
service provider (ITSP). This Built-in SBC functionality is not related
to the Hosted OpenScape SBC (hSBC) Feature of OS4K V8. The Hosted
OpenScape SBC Feature must be activated separately, when needed. The
activation of the appropriate built-in SBC function is done automatically
and is always active within OpenScape 4000. An explicit configuration
is not necessary and therefore not provided in the Administration Portals
(WBM).
Figure 256. OpenScape 4000 built-in SBC function
The Built-in SBC function is also activated in case of:
- Secure Remote Subscriber HFA/SIP (@Home)
OpenScape 4000 does not necessarily require the connection of a dedicated
external SBC. Nevertheless the OpenScape 4000 V8 has been extended with
the new feature of a Hosted OpenScape SBC (hSBC), which can of course
be used in addition to the Built-in SBC.
In case of usage with more than 120 ITSP connections/channels, the
use of an OpenScape SBC for Load Balancing between OS4K Gateways (max.
120 b-channels) or even between several OS4K locations will be necessary.
INFO:
OpenScape 4000 ITSP certifications are primarily done using the
Built-in SBC function. In some cases – e. g. Telekom DeutschlandLAN
SIP-Trunk – the certification has been invoked in addition also with
an OpenScape SBC.
- Security Offloading
-
In OpenScape 4000 the transport protocols UDP, TCP and TLS are supported.
For the media transport RTP and SRTP is supported. For SRTP the transcoding
function is applied as described within the paragraph
Transcoding.
As default UDP / TCP and RTP are used. In case that the TLS transport
protocol is offered by an ITSP, the ITSP configuration can be used together
with the Signaling- and Payload Encryption (SPE) of OpenScape 4000.
The built-in SBC function provides additional security features such
as:
- Network overload protection
- Address filtering with Whitelisting and Registration Blacklist
The address filter settings are derived from the configuration data for
stations and ITSP connection details (i. a. Inbound Proxy of SIP Provider
Profile). There are no other specific configurations required.
- Media Pinholing
-
The built-in SBC function ensures enabling of UDP ports in the Internet
router for transmitting media data. For this purpose, no specific configuration
is necessary.
- Transcoding
-
The built-in SBC function is implemented as a "Routing Engine". Therefore
the IP addresses and UDP ports are adjusted in the RTP packets accordingly,
but the RTP data itself remains unchanged.
If requested, the RTP transcoding is provided by different gateway
configurations within OpenScape 4000. For this purpose the different
gateway codecs need to be configured per gateway.
All available OpenScape 4000 codecs are supported if transcoding is
used:
- G711
- G729A
- G729AB
- G722
- OPUS
-
- Protocol Translation
-
OpenScape 4000 supports the connection of IP devices with different
protocols (HFA, SIP, etc.) and various IP lines with SIPQ and / or native
SIP protocol. The built-in SBC function automatically performs all the
necessary conversions of the protocols for a seamless data flow between
the different interfaces.
- Header Manipulation
-
The built-in SBC function adjusts all the necessary protocol elements
such as IP addresses in SIP and SDP and the number formats in all SIP
header fields.
All ITSP specific header parameters are stored in profiles, which
are defined in the certification of the respective provider. Deviating
configurations are possible by means of profile changes.
- Media Anchoring
-
The built-in SBC function terminates all media streams of the ITSP.
Doing so allows connections to internal endpoints via Network Address
Translation. Only one RTP stream is supported per connection. Therefore,
video connections are not supported via the built-in SBC function.
The port range for the RTP stream is preset but can be changed if
necessary.