background image

_____________________________________________________________________________________ 

 www.support.avaya.com,

                                                   Page: 3                                                    11/4/2009 

Avaya Inc. – Proprietary.

 Use pursuant to Company Instructions. 

_____________________________________________________________________________________

 

 

1. I

ntroduction.  

_____________________________________________________________________________________ 
 

 

These Application Notes describe the steps to configure the Nortel Contivity 1100 VPN Router to support IPSec 
Tunnel termination using Local Credential authentication for Avaya 96xx series IP Phone. 
 
Avaya 96xx series IP Phone has software based IPSec Virtual Private Network (VPN) client integrated into the 
firmware of an Avaya 96XX Series IP Telephone. This capability allows Avaya IP Telephone to be plugged in 
and used over a secure IPSec VPN from any broadband Internet connection. End users experience the same IP 
telephone features as if they were using the telephone in the office. Avaya IP Telephone models supporting the 
Avaya 96xx series IP Phone firmware include the 9620, 9620C, 9620L, 9630, 9640, 9650, 9650C and 9670. 
Please Note that 9610 does not support VPN. Please Note that VPN feature is supported in H.323 based IP 
phones and not SIP based. Also Spice 3.1 H.323 phones are supported in Avaya Communication Manager 3.1, 
Build 4.0+. 
 
Release 3.1 of the Avaya 96xx series IP Phone firmware, used in these Application Notes, extends the support 
of head-end VPN gateways to include Nortel VPN Router (formerly known as Nortel Contivity) platforms. The 
configuration steps described in these Application Notes utilize a Nortel VPN Router 1100.  
 
The Avaya 96xx series IP Phone utilizes the Internet Key Exchange (IKE) Protocol for IPSec tunnel 
establishment and authentication with the Nortel VPN Router.  
 
 
 
 

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

C

HAPTER

 1. 

_________________________________________________________________________ 

Содержание Contivity 110

Страница 1: ...ny Instructions _____________________________________________________________________________________ Avaya CAD SV Configuring Nortel Contivity 1100 VPN Router to Support Avaya 96xx series IP Phones I...

Страница 2: ...__________________________________________________________________ 1 Introduction 3 1 NETWORK TOPOLOGY 4 2 EQUIPMENT AND SOFTWARE VALIDATED 6 3 NORTEL VPN ROUTER 1100 CONFIGURATION 7 4 AVAYA 96XX SERI...

Страница 3: ...broadband Internet connection End users experience the same IP telephone features as if they were using the telephone in the office Avaya IP Telephone models supporting the Avaya 96xx series IP Phone...

Страница 4: ..._____ The below Figure 1 describes the general test setup diagram to configure the 96xx series IP phone with the Nortel vpn gateway Figure 1 High level test diagram for Implementation of 96xx series a...

Страница 5: ...Phones are located in the public network and configured to establish an IPSec tunnel to the Public IP address of the Nortel VPN Router The Nortel VPN Router will assign IP addresses to the 96xx series...

Страница 6: ...ATED _________________________________________________________________________ Table 1 lists the equipment and software firmware versions used in the sample configuration provided Equipment Software V...

Страница 7: ...and is connected into the network The Nortel VPN Router 1100 depicted in Figure 2 has been configured with IP address 192 168 14 2 as its Management IP address 1 From a web browser enter the URL of th...

Страница 8: ...____________________________________________________ 3 Select SERVICES AVAILABLE from the left panel menu Make sure IPsec is enabled default for at least the public interface 4 The screen capture belo...

Страница 9: ..._______________________ www support avaya com Page 9 11 4 2009 Avaya Inc Proprietary Use pursuant to Company Instructions ______________________________________________________________________________...

Страница 10: ...roprietary Use pursuant to Company Instructions _____________________________________________________________________________________ 6 The abbreviated screen capture below shows the IPsec configurati...

Страница 11: ...Use pursuant to Company Instructions _____________________________________________________________________________________ series IP Phones setting in Section 5 2 7 Create new users by selecting PROF...

Страница 12: ...y Use pursuant to Company Instructions _____________________________________________________________________________________ 8 The following abbreviated screen capture shows the values used for a user...

Страница 13: ..._________________________________________________________________________________ 9 Select SERVERS USER IP ADDR from the left panel menu to define a DHCP scope to be assigned to Avaya 96xx series IP P...

Страница 14: ...__________________________________________________ www support avaya com Page 14 11 4 2009 Avaya Inc Proprietary Use pursuant to Company Instructions __________________________________________________...

Страница 15: ...hone firmware includes 3_1 in the name This allows for easy identification of firmware versions incorporating VPN capabilities 4 2 Configuring Avaya 96xx series IP Phone The Avaya 96xx series IP Phone...

Страница 16: ...VPNPROC parameter is set to 2 To do this open the upload directory of file server open the file 46xxsettings txt file and append it with SET VPNPROC 2 and upload this new 46xxsettings txt file into t...

Страница 17: ...Network 0 0 0 0 0 25 IKE Over TCP Never B While phone is operational in vpn enabled Mode Press Mute button procpswd to enter the craft procedures and follow the above steps to program the vpn enabled...

Страница 18: ...ation Type 1 Local credentials 2 Radius Credentials 3 Radius SecureID 4 Radius Axent SET NVVPNAUTHTYPE 1 VPN User Type 1 Any 2 User SET NVVPNUSERTYPE 2 VPN User name SET NVVPNUSER vpn1 Password Type 1...

Страница 19: ...NCALG 0 IKE Auth algo 0 Any 1 MD5 2 SHA 1 SET NVIKEP1AUTHALG 0 IKE Config Mode 0 Enabled 1 Disabled SET NVIKECONFIGMODE 0 IPsec PFS DH group SET NVPFSDHGRP 1 IPsec Encryption Algo 1 AES 128 2 3DES 3 D...

Страница 20: ...1 4 2009 Avaya Inc Proprietary Use pursuant to Company Instructions _____________________________________________________________________________________ SET VPNPROC 2 Call Server address SET MCIPADD...

Страница 21: ..._______________________________________ 5 VERIFICATION _________________________________________________________________________ The active VPN sessions to the Nortel VPN Router can be viewed by selec...

Страница 22: ...ponse If we given user name are incorrect we will get VPN Tunnel Failure Message VPN tunnel failure Retry Details Sleep If we press Retry Soft key again it will retry to establish the tunnel If we pre...

Страница 23: ...d soft key on the phone and it will go to IKE Phase 2 Screen here check the IKE Phase 2 Screen Settings is correct or not 6 3 Phone displaying connecting This issue can be resolved by the administrato...

Страница 24: ...RENCES _________________________________________________________________________ Avaya Solution Interoperability Test Lab Configuring Nortel VPN Router to Support Avaya VPNremote Phones Issue 1 0 Avay...

Отзывы: