Installation and Maintenance Guide Release 1.0
NOTICE The information contained in this document is believed to be accurate in all respects but is not warranted by Mitel Networks Corporation (MITEL ). The information is subject to change without notice and should not be construed in any way as a commitment by Mitel or any of its affiliates or subsidiaries. Mitel and its affiliates and subsidiaries assume no responsibility for any errors or omissions in this document. Revisions of this document or new editions of it may be issued to incorporate such changes. No part of this document can be reproduced or transmitted in any form or by any means - electronic or mechanical - for any purpose without written permission from Mitel Networks Corporation. TRADEMARKS Mitel is a trademark of Mitel Networks Corporation. Windows and Microsoft are trademarks of Microsoft Corporation. Other product names mentioned in this document may be trademarks of their respective companies and are hereby acknowledged. Secure Recording Connector Installation and Maintenance Guide Release 1.0 October 2007, Trademark of Mitel Networks Corporation Copyright 2007, Mitel Networks Corporation All rights reserved
TABLE OF CONTENTS OVERVIEW...1 Glossary... 1 Installation Checklist... 2 REQUIREMENTS...3 Hardware... 3 Software... 3 IP Phones... 3 Licenses... 3 Co-residency... 3 Firewall Requirements... 4 DHCP... 4 INSTALL SRC...5 Pre-installation Tasks... 5 Installing the Blade... 5 CONFIGURATION...6 ENROLLMENT...6 Handling Certificate Requests... 6 DIAGNOSTICS...6 SERVER RESILIENCY...7 UPGRADING SOFTWARE AND LICENSES...7 Upgrading SRC Software... 7 Upgrading SRC Licenses... 7 SUPPORTING DOCUMENTATION...8
Overview Mitel Secure Recording Connector (SRC) is a software solution that facilitates the recording of Mitel encrypted voice streams by third-party call recording equipment (CRE). SRC uses the Mitel Standard Linux (MSL) operating system as its base and is positioned on the LAN between the ICP and the sets to be recorded. It accepts requests from an authorized CRE to establish taps in the voice stream. These taps are separate (mirrored) streams from the SRC to the CRE. Glossary Term AMC Blade Device/Set/Phone MSL Tap Definition Applications Management Center A software package, downloadable from the AMC via the Internet, or installed from CD, that runs on the MSL platform A physical endpoint. All endpoints have a non-varying serial number called MAC address Mitel Standard Linux operating system A tap is a stream of RTP that is forked from the original stream between two endpoints. It constitutes one half of the conversation, either transmit or receive. When used in a licensing reference, the term refers to any two-way conversation on a given set. 1
Installation Checklist Successful deployment of the Secure Recording Connector consists of the following steps: Read the SRC Release Notes available at Mitel OnLine Ensure that your site meets SRC requirements (page 3) Install SRC software (page 5) Configure software and DHCP server (if required) using SRC online help Enroll the SRC to establish security credentials (page 6) Install and configure CRE using manufacturer s instructions Enroll the CRE with SRC to obtain security credentials (page 6) 2
Requirements This section contains software, hardware, and connectivity/network requirements necessary to support SRC. Hardware The following table lists generic hardware. Please refer to the Qualified Hardware List for MSL (available at Mitel OnLine) for hardware combinations that have been tested in Mitel's labs. Item Requirement CPU Pentium 4 - At least 1.6 GHz (See Note 1) RAM CD-ROM 512 Mb (minimum) Yes Software MSL Item Requirement Release 8.2 running SRC Release 1.0 software blade IP Phones Compatible Sets Platform Release 5020 5215 5220 DM 5215/ 5220 5235 5212 5224 Navigator 5330 5340 5560 IPT 2 3300 ICP 7.0 Yes Yes Yes Yes Yes Yes Yes 1 No 7.1 Yes Yes Yes Yes Yes Yes Yes Yes 3 8.0 Yes Yes Yes Yes Yes Yes Yes Yes 1. Release 7.0 UR2 or later 2. 5560 IPT Release 1.0 sets count as two devices when provisioning 3. Release 7.1 UR2 or later Note: YA and Contact Center softphones are not supported. Licenses SRC licenses are available in a base kit of 5 and upgrade kits of 1, 10, or 50 taps each. You need a license quantity equal to the total number of concurrent recording ports you will use. (A port corresponds to the recording of a two-party or multi-party conversation.) Table 1 on page 7 lists SRC part numbers. Co-residency The SRC application cannot be co-resident with the Teleworker application. 3
Firewall Requirements The following connections must be configured: Port Range Direction Purpose and Details TCP22 (SSH) Server Internet AMC communications. Allow outbound packets (and replies) on TCP port 22 between MSL and the Internet to enable server registration, software and license key downloads, alerts and reporting. UDP53 Server Internet DNS. Allow outbound packets (and replies) on UDP port 53 between MSL and the Internet to enable domain name registration/recognition. DHCP DHCP setups vary according to the percentage of total sets that you want to record. To record A small percentage of total sets All sets A large percentage of total sets You can use this DHCP setup Configure the phones manually as Teleworker phones and enter the IP address of the SRC when prompted for the Teleworker Gateway IP address. For more information, refer to the Teleworker Remote Phone Configuration Guide available at Mitel OnLine. Configure the DHCP server in your 3300 ICP to supply the IP address of the SRC server to the phones as their ICP and TFTP addresses. OR Enable the pre-configured DHCP server supplied with the MSL server. A possible setup for this scenario is to deploy the recorded group on a different subnet from the non-recorded phones. You can use the 3300 ICP as the DHCP server for the nonrecorded phones and the MSL server as the DHCP server for the recorded phones subnet. Recorded phones will then receive the IP address of the SRC server as their TFTP server and ICP addresses. For more information about configuring DHCP in the MSL server, refer to the Mitel Standard Linux Installation and Administration Guide. 4
Install SRC Installing the SRC standalone application consists of the following steps: Completing the Pre-installation Tasks Installing the SRC software blade Pre-installation Tasks Pre-installation tasks must be completed before you can use the MSL server to install the SRC blade. Task Notes 1. Order the SRC products If you have not already done so, place your order with Mitel Customer Services for the SRC starter kit and licenses. Customer Services adds the ordered products to your AMC license account. 2. Create an Application Record for this MSL installation In your AMC account, create a new Application Record for this MSL installation and assign the SRC starter kit and licenses that you ordered in Step 1. (Click the Help link in your AMC license account for more information.) 3. Install and configure MSL Download MSL 8.2 software from Mitel OnLine and follow the instructions in the Mitel Standard Linux Installation and Administration Guide to install and configure in server-only mode. 4. Activate the MSL Server (if Log in to the server and click Status in the left-hand menu. you haven t already done so In the Service Account ID field, enter the Application Record during MSL configuration) ID number you created in Step 2 and click Activate. The AMC synchs with the server and the SRC blade is delivered. 5. Install the Blade Follow the instructions under Installing the Blade. Installing the Blade After successful activation and synchronization, the SRC blade is delivered to your MSL server. To install the blade: 1. In the Server Manager, under ServiceLink, click Blades. 2. Click Update List to ensure the most recent view. 3. Click the install link associated with the SRC blade. The SRC license agreement appears. 4. Click Read text to read the license terms for all software applications. If you agree with the license terms, click Accept all licenses, or click Cancel to exit the blade installation. After you accept all licenses, a progress indicator appears. 5. To refresh the page, use the Click here to update the page. link. 6. When installation is complete, an overview of installed components appears. Click Clear this report to return to the Blades panel. 7. Refresh the browser. The SRC navigation link appears under Applications. 8. Under ServiceLink, click Status. Scroll down and click Sync to synchronize with the AMC and deliver your ordered licenses. 9. Under Applications, click Secure recording connector. The SRC web interface opens. 5
Configuration For SRC configuration instructions, click Help in the upper right corner of the SRC interface. For installation and configuration of Call Recording Equipment, refer to the documentation supplied by the manufacturer. Enrollment Both the SRC application and the CRE equipment require a one-time enrollment to establish proper trust relationships. After the SRC blade has been installed and started, but before the CRE is installed, the administrator must complete the blade enrollment by approving the certificate request using the instructions provided in Handling Certificate Requests. After the CRE has been installed, the administrator must again complete its enrollment by approving the request from the CRE using the same instructions. In this way, both the SRC and the CRE have certificates signed by the same Certificate Authority. Handling Certificate Requests 1. Access the server manager 2. Under Security, click Certificate Management. Certificate requests waiting for approval appear under the heading Queued CSRs. 3. Click the Certificate ID link. 4. After confirming the requester, do one of the following: Click Approve to approve the CSR and allow the requester to establish taps. Click Reject to reject the CSR. The requester will be notified of the rejection and will not be able to establish taps. Click Cancel to return to the Certificate Management main screen without approving/rejecting the request. Notes: It can take up to two minutes for certificate approval to appear. To refresh the view, under Security, click Certificate Management again. Most errors that occur during approval are due to duplicate certificate IDs. Check the Certificate Management panel for duplicates. If the duplicate existing certificate is not correct, revoke it and repeat your certificate request. For more information about Certificate Management, see the Mitel Standard Linux Installation and Administration Guide available at Mitel OnLine. Diagnostics The self-diagnostic tool emulates a CRE connection and tests addition, removal, and query of taps. For information about using the diagnostic tool, refer to the Diagnostics topic in the SRC online help. 6
Server Resiliency In the case of an SRC server failure, a second SRC server can provide a resilient backup solution. Although titled "primary" and "secondary", the servers are equal peers, both of which can supply full-featured call recording service with no need to re-home when service is restored. Administrators must designate a secondary server and then keep data synchronized between the two servers to provide set support at failover. For more information about SRC resiliency, refer to the Configure Resiliency topic in the SRC online help. Upgrading Software and Licenses Upgrading SRC Software Upgrade versions of the SRC blade are available for download through the MSL Blades panel when you have a current ServiceLink contract. The previous version of the software is automatically removed after the upgrade is complete. To upgrade the SRC blade: 1. In the MSL server manager, under Applications, click SRC. 2. On the Main tab, click Disable SRC. 3. In the server manager, under ServiceLink, click Blades. 4. Click the upgrade link beside the new SRC version. The new version is downloaded. 5. When the download is complete, in the server manager, under Applications, click SRC. 6. On the Main tab, select Enabled. Upgrading SRC Licenses To purchase additional user or compression licenses: 1. Contact Mitel Customer Services (or your Distributor) and place your order using the part numbers in Table 1. 2. In your AMC account, access the Application Record that applies to this 3. MSL installation. Assign the upgrade products from your License account to the Application Record. The AMC updates your licenses on its regularly scheduled synchronization. You can force an immediate synchronization by clicking the Sync button on the Status page of the MSL server manager. Table 1. SRC Part Numbers Part Number Description Notes 54003181 SRC Base Kit Every SRC must have this base level of service. Includes: SRC software blade 5 tap licenses 1-year ServiceLink contract 54003182 SRC Upgrade 1 additional tap license 54003183 SRC Upgrade 10 additional tap licenses 54003184 SRC Upgrade 50 additional tap licenses 7
Part Number Description Notes 54003185 SRC Support (Software) A support extension is required to renew the ServiceLink contract for another year. (See Note.) Includes: AMC monitoring services including synchronization and alerts access to all SRC updates - including security patches, bug fixes, new features ability to order additional licenses for your existing SRC 54003231 SRC 5-port Compression 5-port compression license NOTE: If your ServiceLink subscription expires, your synchronization to the AMC also expires and you will no longer have access to the software for reinstallation, if required. Supporting Documentation To access Product and Technical Documentation 1. Log on to Mitel OnLine. 2. Click Technical Support. 3. Select Product Documentation. 4. To access IP Phone documentation, click the User Guide or Installation Guide links at the top of the page. 5. To access SRC documentation, scroll the left-hand navigation pane to Applications and Solutions. Click SRC. To access Mitel Knowledge Base articles 1. Log on to Mitel OnLine. 2. Click Technical Support. 3. Click Knowledge Base. The Knowledge Base search engine opens. 4. From the Product list, select SRC and click Search. To download MSL software from Mitel OnLine 1. Log on to Mitel OnLine. 2. Click Technical Support. 3. Select Software Downloads. 4. Select Mitel Standard Linux software. 5. Click the links to download Release Notes and software. 8