Hi all,
First post here. Finally signed up and hopefully I can provide some assistance here as well. It's a great community that has helped me many times in the past.
Anyway, I have a general query around IPO, ASBCE and remote workers please.
In terms of certificates, the Avaya documentation is clear as mud. I've also raised a ticket with Avaya for certificate clarity and they haven't really offered much by way of clarity. They actually directed me to an Aura document on the subject. So I have 2 SBC's, not configured as HA. 2 IP office systems also. Our "primary" SBC is configured for IP Office failover. e.g. B1 address routes through to primary IPO, and B2 to secondary. We will then use the secondary SBC if/when the primary SBC goes down, and this also has 2 routes configured in the same way for IP office failover. So if SBC A goes down, we need to try and weigh the public DNS so that our FQDNs uses the secondary SBC B1 and B2 address respectively for IPO1 and IPO2.
I'm trying to figure out what certificates I need to use here. I have the A side working with IP Office root installed on SBC and client. SBC ID cert on SBC, and IP Office ID cert on IPO. Is the only cert needed on the client the IPO root? It seems to be as I'm registering with presence perfectly fine. If I register to the secondary - while not failed over - I do not get presence. This may be an internal DNS thing, but I fear my certs are messed up.
On the SBC and IPO ID certs should I just put every possible FQDN and IP address in the SAN?
Does anyone know how to setup public DNS to weight the resolution of addresses using DNS Srv and A records?
Apologies for the long winded post. Hope I'm being clear. Thanks in advance.
MrFink.
First post here. Finally signed up and hopefully I can provide some assistance here as well. It's a great community that has helped me many times in the past.
Anyway, I have a general query around IPO, ASBCE and remote workers please.
In terms of certificates, the Avaya documentation is clear as mud. I've also raised a ticket with Avaya for certificate clarity and they haven't really offered much by way of clarity. They actually directed me to an Aura document on the subject. So I have 2 SBC's, not configured as HA. 2 IP office systems also. Our "primary" SBC is configured for IP Office failover. e.g. B1 address routes through to primary IPO, and B2 to secondary. We will then use the secondary SBC if/when the primary SBC goes down, and this also has 2 routes configured in the same way for IP office failover. So if SBC A goes down, we need to try and weigh the public DNS so that our FQDNs uses the secondary SBC B1 and B2 address respectively for IPO1 and IPO2.
I'm trying to figure out what certificates I need to use here. I have the A side working with IP Office root installed on SBC and client. SBC ID cert on SBC, and IP Office ID cert on IPO. Is the only cert needed on the client the IPO root? It seems to be as I'm registering with presence perfectly fine. If I register to the secondary - while not failed over - I do not get presence. This may be an internal DNS thing, but I fear my certs are messed up.
On the SBC and IPO ID certs should I just put every possible FQDN and IP address in the SAN?
Does anyone know how to setup public DNS to weight the resolution of addresses using DNS Srv and A records?
Apologies for the long winded post. Hope I'm being clear. Thanks in advance.
MrFink.