This page was last edited on May 3, 2018, at 21:26.
Comments or questions about this documentation? Contact us for support!
Secure data transfer using TLS is now supported between SIP Server and Active-Active Resource Managers in a deployment where SIP Server high-availability is configured using the F5 Networks BIG-IP LTM. TLS is also supported between SIP Server and all SIP devices in this deployment, including SBCs, Media Gateways, and SIP phones. BIG-IP LTM is not a TLS peer as are other elements in the environment; there is no TLS negotiation between BIG-IP LTM and other components.
The integration solution described in this section makes the following assumptions:
See Deployment Architecture Example.
To support TLS data transfer in a SIP Server deployment with an Active-Active RM pair and a BIG-IP LTM used for the SIP Server HA, complete the following procedures:
To configure TLS data transfer between Genesys Media Server components, refer to the ''Genesys Media Server 8.1 Deployment Guide''.
Before starting the TLS-specific configuration of BIG-IP LTM, complete the configuration procedures.
To configure a health monitor:
To configure a server pool:
To add server pool members:
To configure a Virtual Server:
At this point, the BIG-IP LTM is configured for handling communications over different protocols: UDP, TCP, and TLS. If TLS is mandatory for security reasons, Genesys strongly recommends disabling virtual servers for insecure protocols, such as UDP and TCP.
To disable Virtual Servers for UDP and TCP:
This completes configuring BIG-IP LTM.