ZyXEL Communications ISG50-ISDN Скачать руководство пользователя страница 65

65 

 

Goal to achieve:   

Build up the IPSec VPN tunnel between ISG located in the main office and USG located in the home office. 

 

Condition:   

ISG as a Centralized multisite VPN and VoIP connectivity 

ISG50 (Main Office): 

WAN IP: 59.124.163.156 

LAN IP: 10.5.5.1 

Local subnet: 10.5.5.0/24 

USG (Home Office): 

WAN IP: 59.124.163.151 

Local subnet: 192.168.2.0/24 

 

IPSec VPN 

Phase 1: 

Authentication: 1234567890 

Negotiation mode: Main 

Encryption Algorithm: 3DES 

Authentication Algorithm: MD5 

Key Group: DH1 

Phase 2: 

Active Protocol: ESP 

Encapsulation Mode: Tunnel 

Encryption Algorithm: DES 

Authentication Algorithm: SHA1 

Perfect Forward Secrecy (PFS): None 

 

 

 

 

 
 

Содержание ISG50-ISDN

Страница 1: ...1 ISG50 ISDN ISG50 PSTN Application Note Version 2 0 June 2012...

Страница 2: ...l 12 Firewall Setting 14 QoS 15 2 How to Manage Extensions as Business Needs Grow 16 Auto Provision 16 SIP Server SIP account Password 17 Phone book 19 Feature Key 20 Firmware Upgrade 22 3 How to Deve...

Страница 3: ...erprise class Calling Features to Increase Business Productivity 93 Auto Attendant 93 Hunt Group 100 Three way Conference 102 How to perform a three way conference on ZyXEL Reach 103 How to perform th...

Страница 4: ...istory 118 How to check QoS of each call in RTCP 120 Back up CDR file 122 10 How do UC Server and UC Client Work with ISG50 123 Preparation for TAPI Service 124 TAPI Driver Installation 126 UC Server...

Страница 5: ...ing departments In order to allow road warriors to register with the ISG50 using their smart phones during business trips the network administrator needs to define the firewall rules since the ISG50 w...

Страница 6: ...6 First add authority groups for departments Create two authority groups and fill in Marketing and Sales as the authority group names...

Страница 7: ...7...

Страница 8: ...Here we add multiple SIP peers Define the start number and the amount of extensions Here we set 3100 as the start number The passwords for these SIP peers are the same as the extension numbers In orde...

Страница 9: ...xtensions have been created Double click the extension number to check and modify the setting of the extension For security reasons you can modify the Web VM PIN code and the password for each extensi...

Страница 10: ...g for each extension Goal to achieve Configure call forwarding for extension 1006 Condition Extension 1006 Double click the extension in the Authority Group list to configure call forwarding and call...

Страница 11: ...ion of Busy is that Call Waiting is disabled No Answer Forward A caller dials 1006 but 1006 doesn t answer the phone This caller will be redirected to a pre configured extension or voice mail when the...

Страница 12: ...to receive voicemail notification with the voice file in the email box Condition Extension 1006 Go to CONFIGURATION PBX Global E Mail to fill in the mail server information and email account Specify t...

Страница 13: ...the attached file in the notification mail If the voice message is not attached in the notification mail you can dial the feature code and the extension number to hear the voice message The default fe...

Страница 14: ...r from the WAN interface Condition Activate the firewall rule PBX_SERVICE Enable Firewall checked By default ISG50 doesn t allow SIP clients to register from the WAN interface You have to activate the...

Страница 15: ...administrator would like to let VoIP service has the highest priority over other traffic Condition Enable Highest Bandwidth Priority for PBX Traffic checked Check this box to ensure VoIP traffic rece...

Страница 16: ...visioning feature allows administrators to configure VoIP related settings on the V310 snom SIP clients from a central location A configuration file associated with the SIP extension on the ISG50 can...

Страница 17: ...17 SIP Server SIP account Password Goal to achieve Configure SIP accounts on snom and V310 directly from ISG50 Condition V310 Snom Extension 1005 Extension 1007...

Страница 18: ...18 Fill in the MAC address of the IP phone and select the model name from the product list that receives configuration settings from the ISG50 for this extension Snom V310...

Страница 19: ...19 Phone book Goal to achieve Download the phonebook on snom and V310 from ISG50 Condition Extension number 1005 1012 2000 2001 Snom V310...

Страница 20: ...Agent Login Agent Pause Voicemail Group Pickup Call Transfer Mobile Extension On Mobile Extension Off Mobile Extension Auto Call Recording on Demand Followme On Followme Off Line Configure the featur...

Страница 21: ...21 The setting of feature keys is downloaded from ISG50 Here key P k of ISG50 is mapped to key P k 1 of Snom phone k is from 0 to 11...

Страница 22: ...24 163 151 FW snom370 8 4 32 SIP f bin V310 http 10 59 1 37 V310_1 00AABT 0B5 Snom Configure firmware upgrade URLs for the Snom 370 Visit http wiki snom com Firmware to find the latest firmware versio...

Страница 23: ...23 Please note that snom phones only support HTTP firmware update so the URL link must be in the format of http IP_address FW_version bin...

Страница 24: ...24 You can log into the GUI of Snom 370 to check if the firmware has been upgraded to target version...

Страница 25: ...25 V310 Fill in the firmware download URL...

Страница 26: ...26 V310 will receive the firmware upgrade path through auto provision Blanks in Auto Configuration and Firmware Upgrade tabs will be automatically filled with an HTTP IP address...

Страница 27: ...y can connect up to two ISPs via Ethernet or PPPoE connections to avoid VoIP service breakdowns In addition the ISG50 not only offers voice services through the ITSP by a SIP trunk but also via a PSTN...

Страница 28: ...marily through WAN1 In case WAN1 is down it will go out via WAN2 Condition Primary WAN1 Backup WAN2 Add WAN trunk for VoIP traffic Set WAN1 as Active mode and set WAN2 as Passive mode Configuration Ne...

Страница 29: ...29 Apply this new trunk in Default Trunk Selection for System Service Traffic Use SYSTEM_DEFAULT_WAN_TRUNK to do load balancing for data traffic...

Страница 30: ...nk SIP trunk Secondary trunk BRI trunk In the LCR move multiple outbound line groups to the Selected column for making calls out Use the Up and Down buttons to specify the priority of the outbound lin...

Страница 31: ...31 DDNS Goal to achieve IP Phone and mobile client can register to ISG50 with the domain name in case the IP of WAN1 is dynamic Condition DDNS service provider DynDNS DDNS interface WAN1...

Страница 32: ...32 Fill in DDNS account information Activate DDNS...

Страница 33: ...other more easily the administrator needs to establish a trusted peer between two ISGs located in two offices Furthermore to reduce the cost of outbound line deployments in the remote offices the exte...

Страница 34: ...e ISG50 acts as a pure IP PBX to provide VoIP services IP phones from the Internet can register to ISG50 through USG s WAN IP Condition USG WAN IP 59 124 163 156 SIP server IP ISG50 172 16 1 10 ISG50...

Страница 35: ...35 Step 2 Assume ISG50 s WAN port is connected to DMZ port 5 of USG Configure an IP for this interface...

Страница 36: ...type to let USG do packet forwarding Fill in the Original IP WAN IP address Fill in the Mapped IP ISG s IP address Configure the Original Port and the Mapped Port here we set the SIP signaling port 50...

Страница 37: ...37 Step 4 The user can create an address object for ISG50 for further configuration usage Click Create new object for this function...

Страница 38: ...38 Step 5 Click CONFIGURATION Network Firewall to open the firewall configuration screen Click on the Add button to create a firewall rule to enable the VoIP service to pass from the WAN to DMZ...

Страница 39: ...39 Step 6 Disable SIP ALG...

Страница 40: ...40 ISG50 Step 1 Set the WAN IP of USG in the Fake IP field...

Страница 41: ...41 Step 2 Make sure the SIP signaling port and the RTP port range are the same as those you configured in the port forwarding in USG...

Страница 42: ...42 Step 3 Disable the firewall in ISG50 since USG acts as firewall...

Страница 43: ...een two ISGs located in the main office and the remote office so that the extensions of two offices can make call to each other Furthermore extensions of remote office can make call out through BRI tr...

Страница 44: ...the remote office 49 ISG50 2 Remote Office WAN IP 59 124 163 147 Extension format 4 digit Prefix number before dialing to the main office 48 In outbound trunk setting add a new trust peer in each ISG5...

Страница 45: ...45 ISG50 1 Main Office ISG50 2 Remote Office...

Страница 46: ...46 Add a SIP trunk in ISG50 1 Main Office The account information is provided by your ITSP...

Страница 47: ...47 You can check if the registration status is online through MONITOR PBX SIP Trunk...

Страница 48: ...48 Add BRI trunk in ISG50 1 Main Office Go to CONFIGURATION PBX Outbound Line Management Outbound Trunk Group BRI Settings Here we use DDI DID as the AA option...

Страница 49: ...Office make call to each other over Trusted Peer In this example for extensions in ISG50 1 Main Office they need to dial 49XXXX to reach extensions in ISG50 2 Remote Office For extensions in ISG50 2 R...

Страница 50: ...50 Configure Group Management in both ISG50 1 Main Office and ISG50 2 Remote Office Associate AGs with LCR...

Страница 51: ...sion of ISG50 2 Remote Office over trusted peer Configure LCR in ISG50 2 Remote Office Here since the call not only reaches the extension of ISG50 1 Main Office but also goes out through the BRI trunk...

Страница 52: ...52 Configure the Group management in ISG50 2 Remote Office...

Страница 53: ...53 In ISG50 1 Main Office to let extensions of ISG50 2 Remote Office make call out through ISG50 1 Main Office s BRI trunk we need to associate the outbound line trusted peer with the LCR...

Страница 54: ...54 In ISG50 1 Main Office to let the incoming call on BRI trunk reach the extension of ISG50 2 Remote Office over trusted peer we need to associate the outbound line BRI trunk with the LCR...

Страница 55: ...s for data and voice communications across the Internet This allows employees in the branch offices or home offices to access the company s network in the same secure way as those who work in the main...

Страница 56: ...59 124 163 156 LAN IP 10 5 5 1 Local subnet 10 5 5 0 24 ISG50 2 Remote Office WAN IP 59 124 163 147 LAN IP 192 168 2 1 Local subnet 192 168 2 0 24 IPsec VPN Phase 1 Pre Shared Key 11111111 Negotiation...

Страница 57: ...57 ISG50 1 Main Office Add a VPN gateway rule...

Страница 58: ...58...

Страница 59: ...59 Click CONFIGURATION VPN IPsec VPN VPN Connection to configure the phase 2 rule...

Страница 60: ...60...

Страница 61: ...61 ISG50 2 Remote Office Add a VPN gateway rule...

Страница 62: ...62...

Страница 63: ...63 Click CONFIGURATION VPN IPsec VPN VPN Connection to configure the phase 2 rule...

Страница 64: ...64...

Страница 65: ...WAN IP 59 124 163 156 LAN IP 10 5 5 1 Local subnet 10 5 5 0 24 USG Home Office WAN IP 59 124 163 151 Local subnet 192 168 2 0 24 IPSec VPN Phase 1 Authentication 1234567890 Negotiation mode Main Encr...

Страница 66: ...le the user needs to fill in the following information VPN gateway name Gateway address My Address ISG50 s IP and Peer Gateway Address USG s IP Authentication setting Shared Key ID Type setting Local...

Страница 67: ...67...

Страница 68: ...68...

Страница 69: ...URATION VPN IPsec VPN VPN Connection to configure the phase 2 rule To configure the phase 2 rule the user needs to fill in the following VPN connection name VPN gateway selection Policy for Phase 2 Se...

Страница 70: ...70...

Страница 71: ...71 Click the Connect button to establish the VPN link Once the tunnel is established a connected icon will be displayed in front of the rule...

Страница 72: ...le user needs to fill in VPN gateway name Gateway address My Address USG s IP and Peer Gateway Address ISG50 s IP Authentication setting Shared Key ID Type setting Local and Peer side Phase 1 setting...

Страница 73: ...73...

Страница 74: ...74 Configure the phase 2 rule To configure the phase 2 rule user needs to fill in VPN connection name VPN gateway selection Policy for Phase 2 Settings...

Страница 75: ...75 Active protocol...

Страница 76: ...76 Before configuring Remote Policy the user can create a specific object for the VPN subnet...

Страница 77: ...onnected icon will be displayed in front of the rule When the VPN tunnel is established the user can find the SA information on MONITOR VPN MONITOR IPsec ISG50 Main Office USG Home Office Clients in t...

Страница 78: ...on ISG50 1 Main Office LAN IP 192 168 2 1 ISG50 2 Remote Office LAN IP 10 5 5 1 The configuration for IPsec VPN is the same as that in site to site IPsec VPN In outbound trunk setting add a new trust...

Страница 79: ...time 60 minutes Default number of failed access 3 Blocked extension 1001 Below are the CLI commands to enable disable this feature Enable pbx attack prevent web login activate pbx attack prevent sip a...

Страница 80: ...n pbx attack prevent sip block time 1 1440 min Below are the CLI commands to change the configuration for number of failed access attempts The default value is 3 pbx attack prevent web login fail acce...

Страница 81: ...81 Unlock a certain blocked extension or all blocked extensions pbx attack prevent web login unlock all NUMBER pbx attack prevent sip unlock all NUMBER Example...

Страница 82: ...bile SIP client and reduces phone bills by routing all calls to the IP network In addition with the mobile extension feature the ISG50 rings the employee s office extension and his mobile phone number...

Страница 83: ...83 Install the mobile softphone APP ZyXEL Reach on your smart phone It supports both iPhone and Android platform Enter your SIP account password and the domain of ISG to register an extension on ISG...

Страница 84: ...84 You can also add multiple SIP accounts...

Страница 85: ...85 Personal settings Select the connection type Call recording settings...

Страница 86: ...86 Dial the phone number from the keypad Check the call history...

Страница 87: ...87 View the packet trace...

Страница 88: ...ys get calls of his extension All settings can be done on the ZyXEL Reach by the employee himself so it is not required to change any configuration on the ISG50 Goal to achieve When there is an incomi...

Страница 89: ...89 Use web extension as the username For extension 1011 set web1011 as the username Then go to Advanced settings to configure the Auth User Name and Caller ID which are the same as the extension...

Страница 90: ...there is an incoming call on the extension 1007 of the employee both of his extension 1007 on the IP phone in the office and his mobile phone 0912345678 can ring at the same time Condition Extension 1...

Страница 91: ...o Configure your mobile extension settings You can select to Manually turn on and off this feature or select Force Enable to always turn on this feature Fill in a mobile phone number or an extension n...

Страница 92: ...92 When the Manually option is selected you have to dial the pre defined feature code to turn this feature on and off...

Страница 93: ...reduce the cost of business communications and operations Auto Attendant Goal to achieve Record the customized audio file by extension to auto attendant system Design a customized auto attendant for o...

Страница 94: ...94 Configuration for customized Auto Attendant...

Страница 95: ...er the extension of the record peer is picked up you can start recording with this extension Set the record peer For example we set extension 1003 as the record peer You will use this extension to rec...

Страница 96: ...ss the options key codes and go straight to the specified extension In this example we allow incoming calls to follow the option keys Besides the incoming call can also dial the extension number if th...

Страница 97: ...d for the operator and can t be configured as other option keys ISG50 supports up to 10 levels of sub menus In the sub menu click the button Add Child to edit the options and Edit to upload the audio...

Страница 98: ...98 You can also enable Night Service to perform different AA directions outside of office hours based on the office hour setting...

Страница 99: ...e time must be in 24 hr format with a start time and an end time Ex 08 00 12 00 13 00 17 30 You can also set specific days as holidays according to your own country or company policy Enter a date in m...

Страница 100: ...3 for the sales department Condition Hunt Group Number 3333 Members 1006 1007 and 1008 Ring Strategy Random Associate Hunt Group number with extensions and decide the ring strategy and timeout action...

Страница 101: ...re routed to first 1 is the highest priority while 5 is the lowest priority When an incoming call comes in this hunt group this call will be routed to priority 1 first along with the ring strategy If...

Страница 102: ...extensions 1011 1010 and 3200 would like to set up a three way conference call Condition V310 3200 calls ZyXEL Reach 1010 Then ZyXEL Reach 1010 puts the call with V310 3200 on hold calls another V310...

Страница 103: ...re dialing to extension 1011 press the hold key and go back to the keypad 2 Then dial 1011 and press 3 After the call with 1011 is established press the join key to set up the three way conference Bef...

Страница 104: ...104 4 Three way conference has been established If you want to separate the activated three way conference into two individual connections one is on line the other is on hold press the split key...

Страница 105: ...310 3200 uses LINE 1 to talk with ZyXEL Reach 1010 2 Press the HOLD key to put this call on hold and then press LINE 2 to make a call to extension 1011 3 When the call with extension 1011 is active pr...

Страница 106: ...106 In order to put a present call on hold and answer a new call make sure these extensions are selected into the Enabled Extension list in Call Waiting...

Страница 107: ...onference number Configure the conference number PIN number and the maximum number of attendees For users calling from internal extensions just dial the conference number to access the conference room...

Страница 108: ...in English 2 You can refer to the Text English column and the filename column 3 Translate the sentences into the designated language 4 Record your own voice prompts All audio files must follow the 16...

Страница 109: ...109 7 Upload the zip file to the system...

Страница 110: ...110 8 Select the uploaded language and apply it as the system sounds...

Страница 111: ...s are working efficiently while recording conference calls for writing meeting minutes The call recording feature allows the network administrator to record conversations to or from specific extension...

Страница 112: ...h FAT32 or EXT3 file systems are supported for connection to the USB port of ISG50 Also you have to set a disk full warning limit to stop recording once the storage space is less than this criterion W...

Страница 113: ...chieve The administrator would like to record all calls on the FXO trunk and the extensions 1007 1008 and 1009 Condition Recorded Trunk Port1_pabx FXO trunk Recorded Peer 1007 1008 and 1009 Select fro...

Страница 114: ...Feature code for Call Recording On demand 88 On demand recording is only used by internal extensions Dial the feature code to enable disable on demand recording The default feature code is 88 However...

Страница 115: ...st 24 hours Condition Recorded Time Last 24 hours Peer Type All Peer Name All In Recorded Time you can search for call recordings from the past day week or month Furthermore you can also specify an ex...

Страница 116: ...116 This screen lists the call recordings that matched the specified criteria You can download individual call recordings and play back the files with any audio software which supports WAV format...

Страница 117: ...achieve Search for the call history for any calls including internal calls and external calls in the past 24 hours Condition Search period Last 24 hours Direction all directions The ISG50 has a built...

Страница 118: ...er items to generate your own CDR report For example you can select the time period for your query ISG50 provides time range Start time specify the time period for your query Direction Specify the typ...

Страница 119: ...119 After configuring query conditions and displayed items click the Search button to view your CDR query result...

Страница 120: ...20 How to check QoS of each call in RTCP To view the RTCP information select Enable RTCP Support By default RTCP Support is enabled You can select RTCP to display the RTCP information in the CDR repor...

Страница 121: ...each call Recommended value of RTCP for good quality loss 1 If packet loss 3 call quality will degrade audibly Jitter 10 ms The meaning of the jitter value depends greatly on the jitter buffers involv...

Страница 122: ...ve Backup call records to administrator s email Condition Backup email emily chiang zyxel com tw Click the Backup Now button to back up the CDR file You can also send the backup file to the administra...

Страница 123: ...ephone calls The employees can use the UC client to make terminate reject transfer and redirect calls by one simple click on the UC client In addition using the presence feature employees can be aware...

Страница 124: ...ture is enabled when the license ISG50 CTI is applied In the configuration set the username and password for the administrator ISG50 can support up to 2 administrator accounts for TAPI service The acc...

Страница 125: ...125 Select the extensions that administrator can control and determine which extensions can use the TAPI service...

Страница 126: ...l TAPI driver on the PC Condition ISG server IP address 59 124 163 156 TAPI Server user name admin TAPI line 1005 1016 The TAPI driver must be installed on the same PC as the UC server installed Downl...

Страница 127: ...127 Configure the ISG server Fill in the IP address of ISG and log in with the administrator account Then click the Connect button...

Страница 128: ...128 Check if the state is connected TAPI lines that administrator can control...

Страница 129: ...and assign an extension number from the server TAPI lines in ISG50 for each user Condition Administrator s account for access UC server ucisg Download the trial version of UC server from the website o...

Страница 130: ...130 Install ProCall4 0 UC Server UCServer_uk msi on the PC For detailed of configuration of the UC server please refer to the document ESTOS_UCServer_ENG pdf...

Страница 131: ...art to install ESTOS UC server Keep on pressing Next to finish the installation Create a username and password for the UC server The administrator has to use this account to log in and manage the UC s...

Страница 132: ...untry and the area code For example we select Taiwan as the country region and set 3 as the area code If Location has a phone system is unchecked all dialed digits will be treated as internal If this...

Страница 133: ...133 These are the extensions which are configured in the Server TAPI Lines in ISG50 Click on Accept to apply the new settings on the server...

Страница 134: ...134 Create new users on the UC server Configure the user name for the new account on UC server...

Страница 135: ...135 Configure the password for this new user Assign an extension number for this user You can click the button to choose from the Server TAPI Lines...

Страница 136: ...136 Select an extension number for the new user from the Server TAPI Lines Select the services for this user...

Страница 137: ...137 After the users are created the administrator can monitor if the user is online or offline...

Страница 138: ...138 The administrator can press F5 to get the most updated status of all users...

Страница 139: ...the UC client to make a call hang up a call reject a call transfer a call redirect a call and check the status of other extensions Condition UC Server User corresponding extension barbara 1010 emily...

Страница 140: ...t to install ESTOS UC client ProCall Keep on pressing Next to finish the installation In this scenario the ISG TAPI driver is installed on the UC server Hence select Do not install a Tapi driver in th...

Страница 141: ...141 Click on Find Server to select the UC Server you are connecting to Find your UC Server and click OK to confirm...

Страница 142: ...142 Click Next to proceed to the next step ESTOS UC client has been successfully installed Check the box to confgire ProCall workstation...

Страница 143: ...143 Configure the username and the password This is one of the accounts configured in the User list on UC server Fill in the user s personal information...

Страница 144: ...144 Fill in detailed information of this user Click the Select button to associate a phone number to this user...

Страница 145: ...145 Select the corresponding phone number for this user The phone number is configured...

Страница 146: ...146 Launch the ESTOS ProCall application Log in with the username and password Click on the Display monitor button to monitor all users Here is the list of all users...

Страница 147: ...roCall users into Contacts Presence The status button shows the status of the user In Contacts you can check the status of each user The presence can let you know if the user you d like to call is ava...

Страница 148: ...ntacts or by typing a phone number in the blank In this example barbara is making a call to tina When tina gets the incoming call a notification window will pop up and the status button will flash Whe...

Страница 149: ...149 When barbara is taking with tina on the phone the presence is Busy and the status of tina is In conversation...

Страница 150: ...150 Hang up a call Click on the button to hang up the call Reject a call Click on the Reject button to reject a call...

Страница 151: ...n Ctrl W to transfer an existing call Type a phone number in the blank or click on the phone number in the list to blind transfer the call to this number In this example barbara gets a call from exten...

Страница 152: ...n Ctrl R to transfer an existing call Type a phone number in the blank or click on the phone number in the list to consultant transfer the call to this number In this example barbara gets a call from...

Страница 153: ...to redirect the incoming call to another extension Type a phone number in the blank or click on the phone number in the list to consultant transfer the call to this number In this example barbara get...

Отзывы: