Use this procedure to add SIP devices and register their credentials for secure authentication on the MBG (set-side) and the ICP-side. Credentials for MBG (set-side) and the ICP (icp-side) do not have to be the same.
Note that SIP device access is always restricted to authorized users. Clients must pass a registration at the MBG server before being passed through to the ICP for approval.
To add a SIP device:
On the MBG main page, click the Service configuration tab and then click SIP devices.
Click the + sign.
Update the device options as required and then click Save.
Field |
Description |
Notes |
Enabled |
Select to enable the set and allow it to connect to the ICP. Clear the check box to disable access.
|
|
Configured ICP |
Select the ICP to which this device will connect. |
|
Set-side username |
Enter the set-side (MBG side) user name for the SIP client you want to authorize. |
For example, smithj. Note: In Auchan mode, MiVoice Border Gateway usernames must always be associated with a PNI. MiVoice Border Gateway maps between PNI+DN (set-side username) and DN (ICP-side username). In case of duplicate DNs, MiVoice Border Gateway will not allow new user creation. |
Enter the set-side password for the SIP client you want to authorize. For security reasons, the password field is always blank. |
Choose a secure password that is not trivial. Ensure that it contains letters, numbers, and punctuation. (For example, Mitel*Server1!) If you attempt to configure a weak password, you will receive a warning or be prevented from preceding (depending on whether Permit Weak Passwords is enabled). Whenever you update the username, you can either enter a new password or continue to use the existing password. Note that the password field is always blank. |
|
Confirm set-side password |
Re-enter the set-side password for confirmation. |
|
ICP-side username |
Enter the Username that this SIP client uses to access the ICP. |
Leaving these fields blanks causes the ICP-side credentials to default to the same values as set-side credentials. If you have configured a non-trivial set-side password, this will not match the password configured in the ICP and connections for this set will be denied. We recommend that you enter both credentials for more secure authentication. Note: In Auchan mode, MiVoice Border Gateway usernames must always be associated with a PNI. MiVoice Border Gateway maps between PNI+DN (set-side username) and DN (ICP-side username). In case of duplicate DNs, MiVoice Border Gateway will not allow new user creation. |
ICP-side password |
Enter the password that this SIP client uses to access the ICP. |
|
Confirm ICP-side password |
Re-enter the ICP-side password for confirmation. |
|
This option controls whether the "Provisional Response ACKnowledgement" (PRACK) method is used between MBG and the device.
For example, if the PRACK option is globally disabled on MBG and the peer but enabled on the SIP device, then MBG will support PRACK only on calls between itself and the device. Alternatively, if the PRACK option is globally enabled on MBG but disabled on the device, then MBG will use PRACK only between itself and the peer but not with the device. |
Default is Use master setting. Most peers now support PRACK, which can be useful in interoperability scenarios with the PSTN (see RFC 3262). If the remote SIP device supports PRACK, this option should be enabled.
|
|
This option controls whether SIP "OPTIONS" messages are sent to the SIP device as a keepalive mechanism.
|
Default is Use master setting. Gap register and Send options can be used together or separately. |
|
Heartbeat interval |
If "Options keepalives" is enabled, this is the interval at which keep-alive messages are sent. This setting overrides the "Options interval" programmed on the Settings screen. |
|
Challenge methods |
Use this setting to specify the challenge methods MBG will use to authenticate the remote SIP device. When an incoming request includes one of these methods, MBG will issue a "401 Authorization Required" response. The device must then retry the request with credentials contained within the message. To specify methods for the selected device:
To use the method(s) programmed on the Settings screen, click Use master setting. |
Default is Use master setting. The ACK and CANCEL methods cannot be challenged. REGISTER is always challenged. |
This option controls whether the Secure Real-time Transport Protocol (SRTP) is required to provide encryption, message authentication and integrity for the media stream on the set side of MBG.
Note: To implement end-to-end security, enable STRP on both the PBX and MBG. MBG will then facilitate secure communication between remote and local devices. |
Default is Use master setting. |
|
Description |
Enter a description for this SIP client/device. |
For example, JSmith |
This option controls whether the Secure Real-time Transport Protocol (SRTP) should be used as the preferred protocol on the ICP side of MBG.
Note: To implement end-to-end security, enable STRP on both the PBX and MBG. MBG will then facilitate secure communication between remote and local devices. |
Default is Use master setting |
|
Select the SIP device/client availability:
|
Default is Everywhere |
|
Select an option:
|
Default is Use master setting. |
|
At times, it may be necessary to increase log verbosity for specific troubleshooting purposes. Select Normal, Very Quiet, Quiet, Verbose, Very Verbose, or Use master setting to use the Log Verbosity setting programmed on the Settings screen. |
Default is Use master setting. |
|
If you are doing secure call recording and the 3rd-party call recording equipment (CRE) only supports G.711a, G.711u and G.729a, you can restrict MBG to using those codecs. If you are not operating under these limitations, you should allow MBG to use an unrestricted range of codecs. :
|
Default is Use master setting. |
|
Similar to log verbosity, this field controls the jitter log.
|
Default is Use master setting. |
|
This setting overrides the default value requested by the ICP or SIP peer request. It should be changed only if your system has specific requirements. For more information about RTP frame size, see the Engineering Guidelines.
|
Default is Use master setting.
|
|
Tone Injection |
With this option enabled, a configurable tone will be injected into all calls. See Tone Injection for details.
Note: To disable the tone, clear the Enabled option and select Use master. |
Default is Use master setting. |
To edit a SIP device:
On the MBG main page, click the Service configuration tab and then click SIP devices.
In
the device listing, locate the device you want edit and click .
Edit device information as required.
Click Save.
To delete a SIP device:
On the MBG main page, click the Service configuration tab and then click SIP devices.
In
the device listing, locate the device you want to delete and click
.
Click Delete. The deletion is confirmed.