TLS server profile checklist for client side TURN configuration
Perform the tasks outlined in this checklist to create a TLS server profile that is used if media
tunneling requires better readability through firewalls.
No.
Task
Notes
1
Create a certificate signing request.
on page 135.
Use the following options:
• For
Common Name
, use the TURN media
FQDN. For example:
turnmedia.company.com
.
• For
Subject Alternative Name
, use the
TURN media FQDN. For example:
DNS:turnmedia.company.com
.
2
Download and save the
created
.KEY
and
.CSR
files.
3
Send the
.CSR
file to a public CA
for signing.
4
Install the signed certificate and the
key on the Avaya SBCE.
Installing a certificate and a key
page 138.
When installing the certificate, use a
descriptive name. For example:
turnmediaCert
.
5
Create a TLS server profile using
the installed certificate.
page 141.
When creating a profile, use the certificate
installed on the Avaya SBCE in the previous
step.
Provide a descriptive name for the profile. For
example:
turnmediaTlsProfile
.
Firewall configuration
External firewall rules
Port
Protocol
Decription
443
TLS
For TLS TURN. For traffic that runs from the internet to Avaya
SBCE on the B interface.
This option is only required if you are using TLS TURN and it
provides better readability through firewalls.
3478
TCP and UDP
For UDP media. For traffic that runs from the internet to Avaya
SBCE on the B interface.
Table continues…
External client access configuration
October 2018
Deploying the Avaya Aura
®
Web Gateway
125