Akixi Installation Requirements (Siemens HiPath 3000) Introduction This document describes the required activities that should be completed by the Reseller before the deployment of Akixi hosted services at a Customer site. Please complete the tasks specified in this document as follows: Read this document. Complete all configuration & information collection tasks specified by this document. Note that sub-sections which require completion or information to be provided are marked with a character. Complete the checklist below. Sign and return this document to Akixi at least 5 working days prior to the deployment of Akixi hosted services at the Customer site. Checklist Activity Completed () A B C D E F Customer contact details and user information specified. Public & internal IP addresses of the Customer site s internet router & telephone system provided, and I can confirm that the Customer has a statically assigned IP address on the public side of their internet router. The device configuration list of the Customer s telephone system has been provided, and I agree that I will notify Akixi immediately of any subsequent device configuration changes. Customer s telephone system and HG 1500 card configured. Customer s internet router configured. The Voice Network Provider has enabled CLI/CallerID receipt. Signature I agree that I have read this document in its entirety and I have completed the checklist as marked above, and that any additional works necessary as a consequence of non-task completion may delay the deployment of Akixi hosted services at the Customer site. Signed (Reseller): Print Name: Dated: Document Version: 1.0.0.6, Page 1 Of 8
A. Customer Contact Details & User Information Site Details Primary Contact Name: Company Name: Address 1: Address 2: Address 3: Postcode: Tel No.: Number Of Akixi Licenses Required Akixi 1000: Akixi 2000: Required Akixi Application User List E-mail Address Licenses Akixi 1000 () Akixi 2000 () Contact Name Internal Station (Call no) Tel / DDI No. Document Version: 1.0.0.6, Page 2 Of 8
B. Required Public & Internal IP Addresses Static Public IP Address Required Note that Customer must have a statically assigned IP address on the public side of their router. Required IP Addresses Please specify the following IP addresses: Customer s Public Router IP Address: Customer s Internal Router IP Address: HiPath 3000 HG 1500 Card: HiPath 3000 Main LAN Interface: If not known directly, the public IP address of the Customer s router may be obtained by browsing to one of the following free internet sites when connected to the internal side of the Customer s local area network: http://www.whatsmyip.org/ http://whatismyipaddress.com/ http://www.myipaddress.com/ http://www.ip-adress.com/ C. Provide Device Configuration Of Customer s Telephone System A comprehensive list of the Customer s telephone system s device configuration is required as follows: Entity/Device Type Normal Stations Virtual Stations / Pilot Numbers Voice Mail / IVM Ports Trunk Devices Hunt Groups / IVM Groups UCD Groups Required Information All normal stations, IP extensions, and POT/analogue devices: Call no. Device Name. All devices used as pilot numbers for routing calls: Call no. Device Name. All voice mail devices. Call no. Device Name. All trunk devices including IP trunk devices: Code value, which normally starts from 7801. Route Name. All normal hunt groups including MULAP / RNA / etc. group types and also all IVM / voice mail hunt groups: Call no, which normally starts from 350. Device Name. Hunt group member station list per group. All configured UCD Extensions / Stations /ACD groups: Call no, which normally starts from 440. Note that these must be assigned using the last 60 Group Index position(s), which is 741 & above for the HiPath 35x0/37x0, and position(s) 91 & above for the HiPath 33x0. Device Name against Call no. Assigned ID member list per UCD group. Document Version: 1.0.0.6, Page 3 Of 8
Additionally, whenever the device configuration of the Customer s telephone system is subsequently changed, Akixi needs to be notified immediately so that the Akixi hosted service s configuration can also be appropriately changed in order for it to monitor the telephone system correctly. D. Configure Customer s Telephone System & HG 1500 Card Overview Since most of the required telephone system configuration is network-related, the subsequent diagram illustrates how the Akixi hosted service monitors the Customer s telephone system via a remote CSTA connection using the following hypothetical HiPath & router IP address configuration: Customer s Public Router IP Address: 1.1.1.1 Customer s Internal Router IP Address: 192.168.1.254 HiPath 3000 HG 1500 Card: 192.168.1.199 HiPath 3000 Main LAN Interface: 192.168.1.200 Configure Telephone System For Remote CSTA Connection Enable the telephone system to accept CSTA connections from the Akixi Hosted Service as follows: Configure Default Gateway In HG 1500 Card Document Version: 1.0.0.6, Page 4 Of 8
1. Ensure that the Customer s internal router IP address (192.168.1.254 in the example above) is set as the HG 1500 card s default gateway under Explorers Routing IP Routing Default Router, which is indicated as item 1 in the screenshot of the HG 1500 web-based configuration tool shown below: Enable LAN Interface & HIP Forwarding 2. Verify that HIP forwarding is enabled in the Basic Settings tab under Network.. within the HiPath 3000 Manager tool. 3. Also ensure that the IP address of the HiPath s main (CPU) LAN address is set in the Basic Settings tab under Network.. within the HiPath 3000 Manager tool. Enable Routing Entry For Akixi Hosted Service 4. Create a routing table entry for the assigned IP address of the Akixi Hosted Service for the corresponding Customer (a 79.x.x.x address provided to you in a separate e- mail), specifically setting its route to the IP address of the HG 1500 card. LIM Module Support The use of the LIM module instead of the HG 1500 card is also supported for Akixi service connectivity in customer environments with up to 50 extensions and a maximum usage capacity of 150 call attempts per hour. When deploying with the LIM module, follow the same instructions as per the HG 1500 card installation with the following exceptions: Configure Default Gateway In HG 1500 Card This configuration step isn t necessary. Document Version: 1.0.0.6, Page 5 Of 8
Enable LAN Interface & HIP Forwarding Select the LIM Protocol setting option instead. Enable Routing Entry For Akixi Hosted Service The routing table entry should be created with the Gateway option set to the internal address of the customer s internet router (e.g. 192.168.1.254 in the previous example). Other Required Telephone System Complete the following non-network related telephone system configuration: For security purposes unless specifically required, restrict (prohibit) all stations from making international & premium rate calls. Set on (check) the CSTA application active flag within the Plus Product Flags tab under System parameters... within the HiPath 3000 Manager tool. Unset (uncheck) the Direction prefix sent via CSTA flag within the Plus Product Flags tab under System parameters... within the HiPath 3000 Manager tool. Set on (check) the Silent monitoring flag against all stations assigned to Akixi application users within the Stationview screen of the HiPath 3000 Manager tool. E. Configure Customer s Internet Router NAT / Port Redirection Arrange for the Customer s internet router / firewall to have a NAT / port redirection entry created for TCP port 7001, which maps to the internal IP address of the HiPath s main LAN interface. This basically maps TCP port 7001 on the public side of the router to the HiPath CPU s IP address and allows inbound access for the CSTA protocol. For example, using the previously specified hypothetical HiPath & router IP address configuration: Protocol: Example NAT / Port Redirection Mapping Entry TCP Public / WAN IP Address: Any or 1.1.1.1 Public Port: 7001 Mapped / Private IP Address: 192.168.1.200 Private Port: 7001 Firewall Filter Rules Arrange for the Customer s internet router / firewall to have the appropriate firewall rules to specifically only allow the Akixi Hosted Service inbound access over TCP 7001. Typically on most firewall configurations, this can be achieved using two individual firewall rules in a chain: the first that allows inbound access on TCP port 7001 from the Akixi Hosted Service, and then a second rule, which blocks any other IP addresses accessing TCP port 7001. For example: Action: Direction: Protocol: Source IP Address: Example Firewall Chain Entry 1 Pass/Allow Immediately, Then Exit Rules Chain Inbound (WAN/Public Private) TCP Source Subnet Mask: 255.255.255.255 (/32) Source Port: 79.x.x.x (Assigned IP Address Of Akixi Service) Any Document Version: 1.0.0.6, Page 6 Of 8
Destination IP Address: Any Destination Port: 7001 Example Firewall Chain Entry 2 Action: Block / Prohibit Immediately Direction: Inbound (WAN/Public Private) Protocol: TCP Source IP Address: Any Source Port: Any Destination IP Address: Any Destination Port: 7001 Router Rules Shown Graphically For further illustration, implementation of the NAT & firewall entries explained above is also shown graphically: Both non-akixi servers on IP addresses 10.10.10.10 and 20.20.20.20 are blocked by the 2 nd firewall chain entry from inbound access on TCP port 7001. The Akixi Server is allowed inbound access by the first firewall chain entry, and then the NAT / port redirection rule also maps the inbound connection attempt to the main LAN interface of the HiPath 3000 telephone system. Document Version: 1.0.0.6, Page 7 Of 8
F. Enable CLI/CallerID Receipt Verify with the Customer s Voice Network Provider that CLI/CallerID information is being transmitted on inbound calls received via all voice network trunk devices. Document Version: 1.0.0.6, Page 8 Of 8