CHAPTER 16 Services
Mediant 4000 SBC | User's Manual
Parameter
Description
'Upstream TLS Context'
upstream-tls-
context
[TcpUdpServer_
UpstreamTLSContext]
Assigns a TLS Context for the TLS connection with the HTTP
location. To configure TLS Contexts, see
Note:
■
The parameter is applicable only if the 'Upstream Side SSL'
parameter is configured to
Enable
(see above).
■
The NGINX directives for this parameter are "proxy_ssl_
certificate", "proxy_ssl_certificate_key", "proxy_ssl_
ciphers", "proxy_ssl_protocols", and "proxy_ssl_password_
file".
'Upstream Verify
Certificate'
upstream-verify-
cert
[TcpUdpServer_
UpstreamVerifyCertificate]
Enables TLS certificate verification of the Upstream Host on
outgoing connection requests to the Upstream Group, when the
connection is SSL.
■
[0]
No
= (Default) No certificate verification is done.
■
[1]
Yes
= The device verifies the authentication of the
certificate received from the host. The device authenticates
the certificate against the trusted root certificate store
associated with the assigned TLS Context (see 'Upstream
TLS Context' parameter above) and if ok, allows
communication with the host. If authentication fails, the
device denies communication (i.e., handshake fails). The
device can also authenticate the certificate by querying with
an Online Certificate Status Protocol (OCSP) server whether
the certificate has been revoked. This is also configured for
the associated TLS Context.
Note:
■
The parameter is applicable only if the 'Upstream Side SSL'
parameter is configured to
Enable
(see above).
■
The NGINX directive for this parameter is "proxy_ssl_
verify".
Configuring Upstream Groups
The Upstream Groups table lets you configure up to 10 Upstream Groups. Once configured, you
can configure Upstream Hosts for the Upstream Group (see
page 274).
An Upstream Group is a set of one or more hosts (
Upstream Host
) that can serve a particular set of
data. The HTTP Proxy distributes the requests among the members (hosts) of the Upstream Group
according to the specified load balancing mode.
The Upstream Group may be made up of one or more primary hosts and zero or more backup hosts.
HTTP requests for the Upstream Group are distributed among all the primary hosts. Backup hosts
do not receive requests unless all the primary hosts are down.
The following procedure describes how to configure Upstream Groups through the Web interface.
You can also configure it through ini file [UpstreamGroup] or CLI (
configure
network
>
http-proxy > upstream-group
).
➢
To configure an Upstream Group:
1.
Open the Upstream Groups table (
Setup
menu >
IP Network
tab >
HTTP Proxy
folder >
Upstream Groups
).
- 272 -
Summary of Contents for Mediant 4000 SBC
Page 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Page 40: ...Part I Getting Started with Initial Connectivity...
Page 48: ...Part II Management Tools...
Page 113: ...Part III General System Settings...
Page 118: ...Part IV General VoIP Configuration...
Page 525: ...Part V Session Border Controller Application...
Page 654: ...Part VI Cloud Resilience Package...
Page 663: ...Part VII High Availability System...
Page 685: ...Part VIII Maintenance...
Page 759: ...Part IX Status Performance Monitoring and Reporting...
Page 844: ...Part X Diagnostics...
Page 888: ...Part XI Appendix...