Cisco Unified Border Element Configuration Guide Through Cisco IOS XE 17.5
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
- Overview of Cisco Unified Border Element
- Virtual CUBE
- Dial-Peer Matching
- DTMF Relay
- Introduction to Codecs
- Basic SIP Configuration
- Matching Inbound Dial Peers by URI
- Multiple Pattern Support on a Voice Dial Peer
- Outbound Dial-Peer Group as an Inbound Dial-Peer Destination
- ENUM Enhancement per Kaplan Draft RFC
- Support for Multi-VRF
- Configuring Multi-Tenants on SIP Trunks
- Codec Support and Restrictions
- Codec Preference Lists
- Video Suppression
- Network-Based Recording
- SIPREC (SIP Recording)
- Third-Party GUID Capture for Correlation Between Calls and SIP-based Recording
- Cisco Unified Communications Gateway Services—Extended Media Forking
- Passing Headers Unsupported by CUBE
- Copying SIP Headers
- Delayed-Offer to Early-Offer
- H.323-to-H.323 Interworking on CUBE
- ICE-Lite Support on CUBE
- Mid-call Signaling Consumption
- Early Dialog UPDATE Block
- Consumption of Forked 18x Responses with SDP During Early Dialog
- Support for Pass-Through of Unsupported Content Types in SIP INFO Messages
- Support for PAID PPID Privacy PCPID and PAURI Headers on the Cisco Unified Border Element
- Dynamic Refer Handling
- SIP TLS Support on CUBE
- CUBE Call Quality Statistics Enhancement
- Voice Quality Monitoring
Book Title
Cisco Unified Border Element Configuration Guide Through Cisco IOS XE 17.5
Overview of Cisco Unified Border Element
View with Adobe Reader on a variety of devices
Results
Chapter: Overview of Cisco Unified Border Element
Overview of Cisco Unified Border Element
Cisco Unified Border Element (CUBE) bridges voice and video connectivity between two separate VoIP networks. It is similar to a traditional voice gateway, except for the replacement of physical voice trunks with an IP connection. Traditional gateways connect VoIP networks to telephone companies using a circuit-switched connection, such as PRI. The CUBE connects VoIP networks to other VoIP networks and is often used to connect enterprise networks to Internet telephony service providers (ITSPs).
Information About Cisco Unified Border Element
Cisco Unified Border Element (CUBE) can terminate and originate signaling (H.323 and Session Initiation Protocol [SIP]) and media streams (Real-Time Transport Protocol [RTP] and RTP Control Protocol [RTCP]).
CUBE extends the functionality provided by conventional session border controllers (SBCs) in terms of protocol interworking, especially on the enterprise side. As shown in the chart below, the CUBE provides the following additional features:
Figure 1. Cisco Unified Border Element—More Than an SBC
The CUBE provides a network-to-network interface point for:
Signaling interworking—H.323 and SIP.
Media interworking—dual-tone multifrequency (DTMF), fax, modem, and codec transcoding.
Address and port translations—privacy and topology hiding.
Billing and call detail record (CDR) normalization.
Quality-of-service (QoS) and bandwidth management—QoS marking using differentiated services code point (DSCP) or type of service (ToS), bandwidth enforcement using Resource Reservation Protocol (RSVP), and codec filtering.
CUBE functionality is implemented on devices using a special IOS feature set, which allows CUBE to route a call from one VoIP dial peer to another.
Protocol interworking is possible for the following combinations:
The CUBE provides a network-to-network demarcation interface for signaling interworking, media interworking, address and port translations, billing, security, quality of service, call admission control, and bandwidth management.
The CUBE is used by enterprise and small and medium-sized organizations to interconnect SIP PSTN access with SIP and H.323 enterprise unified communications networks.
A CUBE interoperates with several different network elements including voice gateways, IP phones, and call-control servers in many different application environments, from advanced enterprise voice and/or video services with Cisco Unified Communications Manager or Cisco Unified Communications Manager Express, as well as simpler toll bypass and voice over IP (VoIP) transport applications. The CUBE provides organizations with all the border controller functions integrated into the network layer to interconnect unified communications voice and video enterprise-to-service-provider architectures.
Figure 2. Why Does an Enterprise Need the CUBE? 
If an enterprise subscribes to VoIP services offered by an ITSP, connecting the enterprise CUCM through a CUBE provides network demarcation capabilities, such as security, topology hiding, transcoding, call admission control, protocol normalization and SIP registration, none of which is possible if CUCM connects directly to the ITSP. Another use case involves mergers or acquisitions in an enterprise and the need to integrate voice equipment, such as CUCMs, IP PBXs, VM servers, and so on. If the networks in the two organizations have overlapping IP addresses, CUBE can be used to connect the two distinct networks until the acquired organization can be migrated into the enterprise addressing plan.
SIP/H.323 Trunking
H.323 protocol is no longer supported from Cisco IOS XE Bengaluru 17.6.1a onwards. Consider using SIP for multimedia applications.
The Session Initiation Protocol (SIP) is a signaling communications protocol, widely used for controlling multimedia communication sessions such as voice and video calls over IP networks. SIP (or H.323) trunking is the use of VoIP to facilitate the connection of PBX to other VoIP endpoints across the Internet. To use SIP trunking, an enterprise must have a PBX (internal VoIP system) that connects to all internal end users, an Internet telephony service provider (ITSP), and a gateway that serves as the interface between the PBX and the ITSP. One of the most significant advantages of SIP and H.323 trunking is the ability to combine data, voice, and video in a single line, eliminating the need for separate physical media for each mode.
Figure 3. SIP/H.323 Trunking 
SIP trunking overcomes TDM barriers, in that it:
Improves efficiency of interconnection between networks
Simplifies PSTN interconnection with IP end-to-end
Enables rich media services to employees, customers, and partners
Carries converged voice, video, and data traffic
For Cisco IOS XE Gibraltar 16.11.1a and later releases, the SIP processes are initiated only when either of the following CLIs is configured:
Voice dial-peer with session protocol as SIP.
voice register global
In the releases before Cisco IOS XE Gibraltar 16.11.1a, the following commands initiated the SIP processes:
dial-peer voice (any)
max-dn under call-manager-fallback
ds0-group 0 timeslots 1 type e&m-wink-start
Typical Deployment Scenarios for CUBE
CUBE in an enterprise environment serves two main purposes:
- External Connections—CUBE is the demarcation point within a unified communications network and provides interconnectivity with external networks. This includes H.323 and SIP voice and video connections.
- Internal Connections—When used within a VoIP network, CUBE increases flexibility and interoperability between devices.
How to Configure Basic CUBE Features
Consider a scenario where XYZ corporation uses a VoIP network to provide phone services and uses a PRI connection for telecommunications services, and the PRI trunk is controlled by MGCP. Migration from MGCP PRI to SIP trunk is provided by ITSP telecommunications. CUCM sends the telephone number, as 10 digits, to CUBE. CUCM may send only the extension (4 digits) to the CUBE. When the call is diverted (using call-forward), the requirement of the ITSP is that they need the full 10-digit number in the SIP Diversion field.
Figure 6. CUBE Configuration Workflow
The following sections describe the basic setup of CUBE through the steps involved in migrating the XYZ corporation to CUBE using a SIP trunk.
Enabling the CUBE Application on a Device
SUMMARY STEPS
- enable
- configure terminal
- voice service voip
- mode border-element license [ capacity sessions | periodicity < mins value | hours value | days value >]
- allow-connections from-type to to-type
- end
DETAILED STEPS
Example:
Enables privileged EXEC mode. Enter your password if prompted.
Example:
Enters global configuration mode.
voice service voip
Example:
Enters global VoIP configuration mode.
mode border-element license [ capacity sessions | periodicity < mins value | hours value | days value >]
Example:
Enables CUBE configuration and configures the number of licenses (capacity).
-
Effective from Cisco IOS XE Amsterdam 17.2.1r , the capacity keyword and sessions argument are deprecated. However, the keyword and argument are available in the Command Line Interface (CLI). If you try to configure license capacity using CLI, the following error message is displayed:
Effective from Cisco IOS XE Amsterdam 17.2.1r , the periodicity keyword and [ mins | hours | days ] argument are introduced. The periodicity keyword configures periodicity interval for license entitlement requests for CUBE . If you do not configure license periodicity, the default license period of 7 days is enabled.
We recommend you to configure interval in days. Configuring interval in minutes or hours increases the frequency of entitlement requests and thereby increases the processing load on Cisco Smart Software Manager (CSSM). License periodicity configuration of minutes or hours is recommended to be used only with Cisco Smart Software Manager On-Prem (formerly known as Cisco Smart Software Manager satellite) mode.
allow-connections from-type to to-type
Example:
Allows connections between specific types of endpoints in a VoIP network.
The two protocols (endpoints) refer to the VoIP protocols (SIP or H.323) on the two call legs.
Cisco cube что это

24 марта 2016 года можно считать праздником инженеров, поддерживающих Cisco CUBE, поскольку в этот день был выпущен релиз IOS 15.6.2T.
Начиная с этого релиза было введено понятие Tenant.
До этого времени настройка одновременной работы нескольких SIP провайдеров была самой настоящей головной болью:
Настройки параметров нескольких провайдеров должны были производиться только на глобальном уровне.
Логины/пароли для всех ITSP должны производиться только на уровне одного SIP-UA и часто перезаписывали и конфликтовали друг с другом.
В результате если настройка одного ITSP с одним номером была относительно несложна, то при необходимости настройки двух ITSP и более, начинались пляски с бубном и подчас всё упиралось в тупое перебирание комбинаций параметров номера, username, пароля и realm-а. Cisco же на полном серьёзе рекомендовала для второго провайдера устанавливать второй CUBE.
Этот факт вызывал как минимум недоумение у специалистов, знающих VoIP АТС от других производителей; а иногда заставлял заменять CUBE на отдельный хост Asterisk, способный вменяемо разруливать звонки между несколькими провайдерами.
И вот Cisco CUBE научился делать то, что от него так долго ждали:
Tenant позволяет настроить параметры каждого логина для каждого провайдера обособленно и независимо друг от друга, и затем подключать их на уровне Dial-peer.
Далее мы приведём пример реальной настройки Cisco CUBE + Tenants на примере подключения к ITSP Beeline в РФ.
Также в данном материале приведены рекомендуемые Cisco best practices для настроек SIP Voice Service, диалпиров и безопасности.
ВНИМАНИЕ
Доступ к статье ограничен, обращайтесь к автору: ciscomaster@mail.ru
ИТ База знаний
Полезно
— Онлайн генератор устойчивых паролей
— Онлайн калькулятор подсетей
— Руководство администратора FreePBX на русском языке
— Руководство администратора Cisco UCM/CME на русском языке
— Руководство администратора по Linux/Unix
Навигация
Серверные решения
Телефония
FreePBX и Asterisk
Настройка программных телефонов
Корпоративные сети
Протоколы и стандарты
Настройка SIP Forking на Cisco CUBE
Продвинутый курс по Asterisk
Концентрат редких знаний, для внедрения Asterisk в крупных предприятиях. Все это мы собрали в одном курсе для тебя.
В примере мы покажем, как настроить SIP Forking на CUBE для записи видео – звонков, например, для последующего анализа системой записи.
Что мы имеем
Интегрированное приложение Cisco Unified Border Element (далее CUBE) является частью программного обеспечения маршрутизатора CISCO2911, параметры которого приведены ниже:
Prerequisites
Перед началом нужно выполнить следующие условия:

Настройка
Для настройки CUBE необходимо подключится к серверу по протоколу Telnet и ввести следующие логин и пароль:
Переходим в режим конфигурации:
Создаем media profile recorder, в котором необходимо указать тэг dial – peer, который смотрит в сторону системы записи. Помимо этого, необходимо создать профиль для записи видео с опциями, которые указаны ниже. Оба профиля записи указываются в настройке media class:
Теперь, на входящем и исходящем dial – peer указываем созданный ранее media class:
Продвинутый курс по Asterisk
Концентрат редких знаний, для внедрения Asterisk в крупных предприятиях. Все это мы собрали в одном курсе для тебя.
Cisco Unified Border Element Version 14 Data Sheet
Available Languages
Download Options
Available Languages
Download Options
Table of Contents
Part of the Cisco ® Collaboration Edge Architecture, Cisco Unified Border Element (CUBE) version 14 is an enterprise-class Session Border Controller (SBC) solution that makes it possible to connect and interwork large, midsize, and small business unified communications networks with public and private IP communication services.
As a licensed feature set of Cisco IOS ® XE Software, CUBE has a wide range of capabilities that may be used to secure, monitor, and maintain business-critical connections and to ensure compliance with industry standards. Collectively, CUBE features provide exceptional flexibility when architecting highly available enterprise communications networks that save money and offer richer voice and video collaboration experiences to users.
As voice, video, and mobile communications systems converge to form more cost-effective, integrated collaboration solutions, the need to interwork diverse networks based on various protocols and security requirements increases. The CUBE SBC serves a critical role in linking these networks and provides a seamless experience for voice and video users.
CUBE is especially suited to facilitating:
● PSTN interconnect using Internet service provider SIP trunks, which allow rapid service delivery and the possibility of capacity pooling across locations.
● Migration from TDM to SIP public telephony trunk services. As a number of Cisco routers allow the concurrent use of voice gateway and CUBE features, a phased trunk migration is possible without requiring changes to the enterprise call control platform.
● Certified connection to Cisco and third-party cloud collaboration services, including Cisco Webex ® Cloud Connected Audio (CCA and CCA-SP), Webex Calling Local Gateway, Cisco Hosted Collaboration Solution (HCS) and Direct Routing for Microsoft Phone System (Microsoft Teams), with normalization to customer collaboration systems. CUBE supports high-capacity SIP media connectivity to the Cisco Webex cloud to replace expensive TDM audio connections to conferencing services.
● Business-to-business voice and video system interconnect.
● Multi-tenant solutions that require customer-dedicated SIP trunks on a common platform.
● Codec interworking through the control of midcall codec renegotiation or transcoding.
As CUBE terminates and re-originates signaling and media traffic, it is able to provide a secure demarcation between internal and external services, while interworking signaling protocols and encoded media streams between them. Further, CUBE provides a rich set of flexible session control features to secure and route traffic to different destinations and to apply policing and Quality-of-Service (QoS) policies.
Certain CUBE features may also be used with Cisco Communications Manager Express (CME) and Unified Survivable Remote Site Telephony (SRST) applications to connect with SIP trunk services.
Security and compliance
As networks become more interconnected, the need to secure information is of critical importance. Enterprises must comply with rapidly evolving industry standards for the proper handling and protection of sensitive and private information and for the proper auditing of commercial transactions. The comprehensive CUBE SBC feature set helps businesses achieve these requirements with:
● Flexible security rules that prohibit unauthorized connections.
● Behavior evaluation policies that can detect malicious call patterns, including Telephony Denial-of-Service (TDoS) attacks, and invoke an appropriate response – such as terminate, redirect, or record.
● Interworking of encrypted and non-encrypted communication streams.
● Replication of media streams for call recording solutions using either SIPREC or HTTP API.
Cloud communications services
Cloud call control products offer simple-to-provision-and-manage services. However, by their very nature, these services place a greater dependency on the wide-area connections required at customer sites. While additional bandwidth and redundant connectivity can mitigate this requirement, service providers can also use CUBE lineside features to ensure continued service delivery.
● CUBE registration proxy can manage periodic messaging from Cisco Multiplatform Phones (MPP) or third-party SIP endpoints, reducing demand on wide-area connections and permitting larger deployments of endpoints.
● Lineside survivability provides business continuity to SIP phones on a customer site should connectivity to the cloud service be interrupted.
Note: CUBE lineside features are offered for use with SIP-based, IP Centrex solutions (such as Cisco BroadCloud ® ). They cannot be used with Cisco Unified Communications Manager, where Expressway and Unified Survivable Remote Site Telephony products should be considered.
Contact center solutions
CUBE offers numerous features that may be used to architect and optimize fully featured contact center solutions. Examples include:
● Call Progress Analysis (CPA) for outbound calling campaigns
● Interactive Voice Response (IVR) solutions
● Media replication for call recording and analysis
Flexibility, Reliability, and Scale
Cisco offers industry-leading flexibility when it comes to deploying SBC functionality in almost any enterprise architecture. As CUBE is offered as part of Cisco IOS XE Software, it may be used concurrently with industry-leading IP networking, security, and QoS features. You can also choose from a wide range of host platforms to suit scale, performance, resiliency, and budget requirements (see Table 2).
In addition to physical hosts from Cisco Integrated Services Router (ISR), Cisco Catalyst ® Edge Routers and Aggregation Services Router (ASR) product families, CUBE features are available for virtualized environments with the Cisco Cloud Services Router (CSR) and Catalyst Edge Software.
Stateful high availability with active/standby redundant pairs and clustering with Cisco Unified SIP Proxy allows enterprises to build highly scalable, business-critical solutions.
The CUBE features described above are licensed to enable three principal use models:
● Trunking for service interconnect and protocol interworking. Trunk licenses are available for both standard (single node) and enhanced (high-availability and advanced features) network architectures to facilitate site-to-site and PSTN connectivity. Each trunk license enables a single call session in addition to a single forked media session for recording where required.
● Lineside to enhance the delivery of hosted SIP communications services. Previously only available for the Cisco 800 Series Routers through the NanoCUBE license, CUBE Lineside client licenses are now available for all platforms listed in Table 2. Each Lineside license enables registration proxy and survivability features for one local SIP endpoint.
● Media Proxy for advanced call recording and compliance solutions. Deployed independently from CUBE platforms configured for trunkside or lineside applications, CUBE Media Proxy allows corporate customers to meet compliance requirements by simultaneously recording or analyzing calls at up to five destinations simultaneously. Each Media Proxy license enables one forked media session in either standard or redundant configurations.
CUBE Smart Licenses allow for entitlement pooling and portability across all CUBE platforms registered to an organization’s Cisco Smart Licensing account. Providing further flexibility, Cisco Smart Licensing also allows the borrowing of higher-entitlement CUBE licenses if required.
Starting with CUBE version 12.5 (Cisco IOS XE 16.10.1a), all platforms must report license usage to a customer’s Cisco Smart Software Management service account. For more information regarding Smart Licensing, see: https://www.cisco.com/go/smartlicensing
CUBE feature support
CUBE supports a comprehensive range of session control, security, interworking, and demarcation SBC features, many of which are detailed in Table 1.
Table 1. Cisco Unified Border Element features
Cisco Unified Border Element Fundamentals and Basic Setup, Cisco IOS Release 15M&T
Book Title
Cisco Unified Border Element Fundamentals and Basic Setup, Cisco IOS Release 15M&T
Chapter Title
Overview of Cisco Unified Border Element
View with Adobe Reader on a variety of devices
View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Results
Chapter: Overview of Cisco Unified Border Element
Overview of Cisco Unified Border Element
Cisco Unified Border Element (CUBE) is a unified communications border element, providing voice and video connectivity between the enterprise IP network and service provider network. It is similar to a voice gateway, except for the replacement of physical voice trunks with an IP connection.
Information about Cisco Unified Border Element
Cisco Unified Border Element (CUBE) is network border element that can terminate and originate signaling (H.323 and Session Initiation Protocol [SIP]), media streams (Real-Time Transport Protocol [RTP] and RTP Control Protocol [RTCP]).
Session Border controller (SBC) was used by service providers (SP) to enable full billing capabilities within VoIP networks. CUBE provides the extended functionality of interconnecting VoIP networks, especially on the enterprise side.
CUBE functionality is implemented on devices using a special IOS feature set, which allows CUBE to route a call from one VoIP dial peer to another. As VoIP dial peers can be handled by either SIP or H.323, CUBE can be used to interconnect VoIP networks of different signaling protocols. VoIP internetworking is achieved by connecting an inbound dial peer with an outbound dial peer. A standard Cisco IOS gateway without CUBE functionality cannot allow VoIP-to-VoIP connections.
Protocol internetworking is possible for the following combinations:
CUBE is used by enterprise and small and medium-sized organizations to interconnect SIP PSTN access with SIP and H.323 enterprise unified communications networks.
A CUBE interoperates with several different network elements including voice gateways, IP phones, and call-control servers in many different application environments, from advanced enterprise voice and/or video services with Cisco Unified Communications Manager or Cisco Unified Communications Manager Express, as well as simpler toll bypass and voice over IP (VoIP) transport applications. The CUBE provides organizations with all the border controller functions integrated into the network layer to interconnect unified communications voice and video enterprise-to-service-provider architectures.
Figure 1. Cisco Unified Border Element—More than an SBC
SIP/H.323 Trunking
The Session Initiation Protocol (SIP) is a signaling communications protocol, widely used for controlling multimedia communication sessions such as voice and video calls over Internet Protocol (IP) networks. SIP (or H.323) trunking is the use of VoIP to facilitate the connection of a private branch exchange (PBX) to the Internet. To use SIP trunking, an enterprise must have a PBX that connects to all internal end users, an Internet telephony service provider (ITSP) and a gateway that serves as the interface between the PBX and the ITSP. One of the most significant advantages of SIP trunking is its ability to combine data, voice, and video in a single line, eliminating the need for separate physical media for each mode.
Figure 3. SIP/H.323 Trunking

SIP trunking overcomes TDM barriers, in that it:

Typical Deployment Scenarios for CUBE
CUBE in an enterprise environments serve two main purposes:


CUBE Deployment Modes
How to Configure Basic CUBE Tasks
Enabling the CUBE application on a Router
2. configure terminal
3. voice service voip
4. mode border-element license capacity sessions
5. allow-connections from-type to to-type
DETAILED STEPS
Enables privileged EXEC mode. Enter your password if prompted.
Enters global configuration mode.
Enters global VoIP configuration mode.
Enables the set of commands used in the CUBE.
Allows connections between specific types of endpoints in a VoIP network.
Returns to privileged EXEC mode.
Configuring a Trusted IP Address List for Toll-Fraud Prevention
2. configure terminal
3. voice service voip
4. ip address trusted list
5. ipv4 ipv4-address [ network-mask ]
DETAILED STEPS
Enables privileged EXEC mode.
Enters global configuration mode.
Enters voice service configuration mode.
Enters IP address trusted list mode and enables the addition of valid IP addresses.
Allows you to add up to 100 IPv4 addresses in the IP address trusted list. Duplicate IP addresses are not allowed.
Allows you to add IPv6 addresses to the trusted IP address list.
Cisco Unified Border Element Configuration Guide Through Cisco IOS XE 17.5
Book Title
Cisco Unified Border Element Configuration Guide Through Cisco IOS XE 17.5
Chapter Title
Overview of Cisco Unified Border Element
View with Adobe Reader on a variety of devices
Results
Chapter: Overview of Cisco Unified Border Element
Overview of Cisco Unified Border Element
Cisco Unified Border Element (CUBE) bridges voice and video connectivity between two separate VoIP networks. It is similar to a traditional voice gateway, except for the replacement of physical voice trunks with an IP connection. Traditional gateways connect VoIP networks to telephone companies using a circuit-switched connection, such as PRI. The CUBE connects VoIP networks to other VoIP networks and is often used to connect enterprise networks to Internet telephony service providers (ITSPs).
Information About Cisco Unified Border Element
Cisco Unified Border Element (CUBE) can terminate and originate signaling (H.323 and Session Initiation Protocol [SIP]) and media streams (Real-Time Transport Protocol [RTP] and RTP Control Protocol [RTCP]).
CUBE extends the functionality provided by conventional session border controllers (SBCs) in terms of protocol interworking, especially on the enterprise side. As shown in the chart below, the CUBE provides the following additional features:
Figure 1. Cisco Unified Border Element—More Than an SBC 
The CUBE provides a network-to-network interface point for:
Signaling interworking—H.323 and SIP.
Media interworking—dual-tone multifrequency (DTMF), fax, modem, and codec transcoding.
Address and port translations—privacy and topology hiding.
Billing and call detail record (CDR) normalization.
Quality-of-service (QoS) and bandwidth management—QoS marking using differentiated services code point (DSCP) or type of service (ToS), bandwidth enforcement using Resource Reservation Protocol (RSVP), and codec filtering.
CUBE functionality is implemented on devices using a special IOS feature set, which allows CUBE to route a call from one VoIP dial peer to another.
Protocol interworking is possible for the following combinations:
The CUBE provides a network-to-network demarcation interface for signaling interworking, media interworking, address and port translations, billing, security, quality of service, call admission control, and bandwidth management.
The CUBE is used by enterprise and small and medium-sized organizations to interconnect SIP PSTN access with SIP and H.323 enterprise unified communications networks.
A CUBE interoperates with several different network elements including voice gateways, IP phones, and call-control servers in many different application environments, from advanced enterprise voice and/or video services with Cisco Unified Communications Manager or Cisco Unified Communications Manager Express, as well as simpler toll bypass and voice over IP (VoIP) transport applications. The CUBE provides organizations with all the border controller functions integrated into the network layer to interconnect unified communications voice and video enterprise-to-service-provider architectures.
Figure 2. Why Does an Enterprise Need the CUBE? 
If an enterprise subscribes to VoIP services offered by an ITSP, connecting the enterprise CUCM through a CUBE provides network demarcation capabilities, such as security, topology hiding, transcoding, call admission control, protocol normalization and SIP registration, none of which is possible if CUCM connects directly to the ITSP. Another use case involves mergers or acquisitions in an enterprise and the need to integrate voice equipment, such as CUCMs, IP PBXs, VM servers, and so on. If the networks in the two organizations have overlapping IP addresses, CUBE can be used to connect the two distinct networks until the acquired organization can be migrated into the enterprise addressing plan.
SIP/H.323 Trunking
H.323 protocol is no longer supported from Cisco IOS XE Bengaluru 17.6.1a onwards. Consider using SIP for multimedia applications.
The Session Initiation Protocol (SIP) is a signaling communications protocol, widely used for controlling multimedia communication sessions such as voice and video calls over IP networks. SIP (or H.323) trunking is the use of VoIP to facilitate the connection of PBX to other VoIP endpoints across the Internet. To use SIP trunking, an enterprise must have a PBX (internal VoIP system) that connects to all internal end users, an Internet telephony service provider (ITSP), and a gateway that serves as the interface between the PBX and the ITSP. One of the most significant advantages of SIP and H.323 trunking is the ability to combine data, voice, and video in a single line, eliminating the need for separate physical media for each mode.
Figure 3. SIP/H.323 Trunking 
SIP trunking overcomes TDM barriers, in that it:
Improves efficiency of interconnection between networks
Simplifies PSTN interconnection with IP end-to-end
Enables rich media services to employees, customers, and partners
Carries converged voice, video, and data traffic
For Cisco IOS XE Gibraltar 16.11.1a and later releases, the SIP processes are initiated only when either of the following CLIs is configured:
Voice dial-peer with session protocol as SIP.
voice register global
In the releases before Cisco IOS XE Gibraltar 16.11.1a, the following commands initiated the SIP processes:
dial-peer voice (any)
max-dn under call-manager-fallback
ds0-group 0 timeslots 1 type e&m-wink-start
Typical Deployment Scenarios for CUBE
CUBE in an enterprise environment serves two main purposes:
How to Configure Basic CUBE Features
Consider a scenario where XYZ corporation uses a VoIP network to provide phone services and uses a PRI connection for telecommunications services, and the PRI trunk is controlled by MGCP. Migration from MGCP PRI to SIP trunk is provided by ITSP telecommunications. CUCM sends the telephone number, as 10 digits, to CUBE. CUCM may send only the extension (4 digits) to the CUBE. When the call is diverted (using call-forward), the requirement of the ITSP is that they need the full 10-digit number in the SIP Diversion field.
Figure 6. CUBE Configuration Workflow 
The following sections describe the basic setup of CUBE through the steps involved in migrating the XYZ corporation to CUBE using a SIP trunk.
Enabling the CUBE Application on a Device
SUMMARY STEPS
DETAILED STEPS
Example:
Enables privileged EXEC mode. Enter your password if prompted.
Example:
Enters global configuration mode.
voice service voip
Example:
Enters global VoIP configuration mode.
mode border-element license [ capacity sessions | periodicity ]
Example:
Enables CUBE configuration and configures the number of licenses (capacity).
We recommend you to configure interval in days. Configuring interval in minutes or hours increases the frequency of entitlement requests and thereby increases the processing load on Cisco Smart Software Manager (CSSM). License periodicity configuration of minutes or hours is recommended to be used only with Cisco Smart Software Manager On-Prem (formerly known as Cisco Smart Software Manager satellite) mode.
allow-connections from-type to to-type
Example:
Allows connections between specific types of endpoints in a VoIP network.
The two protocols (endpoints) refer to the VoIP protocols (SIP or H.323) on the two call legs.
Call Manager & Skype connect через CUBE
В предыдущем топике я описал как сделать звонки из CCM в Skype Connect. На что было справедливо указано, что для таких целей нужно использовать Cisco CUBE. Пришо время и память, что бы превратить старую 2811 в кубик и сделать кошерную интеграцию.
Предположим, что деньги на скайпе уже есть. SIP account создан и мы знаем логин и пароль для SIP.
Настройки на 2811.
voice service voip
ip address trusted list
ipv4 0.0.0.0 0.0.0.0
allow-connections sip to sip
sip
registrar server
ip address trusted list — нужен для Toll-Fraud Prevention. Иначе будет 403 ошибка на все звонки.
В случае если транк должен создаватся с определённого интерфейса то нужно прописать
voice service voip
sip
bind control source-interface bla-bla-bla
bind media source-interface bla-bla-bla
Настройки SIP. Можно скопировать заменив 99XXXXXXXXXXXX и 7 YYY на ваш SIP логин и пароль.
sip-ua
credentials username 99XXXXXXXXXXXX password 7 YYY realm sip.skype.com
keepalive target dns:sip.skype.com
authentication username 99XXXXXXXXXXXX password 7 YYY realm sip.skype.com
no remote-party-id
max-forwards 10
retry invite 1
retry response 1
retry bye 1
retry cancel 1
retry register 10
timers trying 250
timers expires 60000
timers connect 250
timers disconnect 250
mwi-server dns:sip.skype.com expires 3600 port 5060 transport udp unsolicited
registrar dns:sip.skype.com expires 3600
sip-server dns:sip.skype.com
no suspend-resume
connection-reuse
host-registrar
handle-replaces
Проверям регистрацию
show sip-ua register status
Line peer expires(sec) registered P-Associ-URI
================================ ========== ===========
99XXXXXXXXXXXX -1 50 yes
Если нет — курим debug ccsip messages. У меня завелось сразу. Могут быть проблемы с firewall и NAT. На firewall у меня только обычный dynamic nat, ни каких static. Ну и UDP для CUBE выше 1024 порта разрешены.
voice class codec 1
codec preference 1 g711ulaw
codec preference 2 g711alaw
codec preference 3 g729r8
Без «voice class codec» выдавались ошибки Media Type(s) Unavailable и Resource unavailable, unspecified
dial-peer voice 10 voip
session protocol sipv2
session target dns:sip.skype.com
incoming called-number 1…
voice-class codec 1
dtmf-relay rtp-nte
no vad
!
dial-peer voice 20 voip
destination-pattern 1…
session protocol sipv2
session target ipv4:ccm
voice-class codec 1
dtmf-relay rtp-nte
no vad
!
dial-peer voice 30 voip
destination-pattern .T
session protocol sipv2
session target dns:sip.skype.com
voice-class codec 1
dtmf-relay rtp-nte
no vad
!
dial-peer voice 40 voip
session protocol sipv2
session target ipv4:ccm
incoming called-number .T
voice-class codec 1
dtmf-relay rtp-nte
no vad
dial-peer 10 — Принимающий от skype. Трёхзначный номер с 1
dial-peer 20 — Peer на ccm.
dial-peer 30 — Peer на skype для исходящих звонков
dial-peer 40 — Принимающий от ccm
SIP Trunk на CCM по дефолту за исключением Caller ID DN, куда надо поставить логин из SIP Profile.
в Skype Manager добавляем skype account, прописываем для него внутренний номер и пробуем звонить. У меня завелось сразу.
Ну и в CCM делаем Route Patterns на наш trunk.
Из короткого теста выяснилось, что звонки из skype доходят не все: skype гудит, но на cisco нет ни чего. Качество связи на 4.
Cisco CUBE (ISR) guide for secure transcoding to SIP-Encrypt
A Cisco CUBE or “Cisco Unity Border Element” is the name given to a IP router that is running voice features. Specifically the Cisco IOS software is configured to route VoIP calls.
The Cisco Call Manager IP-PBX makes use of ISR routers as a platform for services that require treatment by Digital Signal Processors. Example of which are media termination points, audio transcoding, conferencing, bridging to ISDN and so on. A CUBE is configured when a VoIP call enters and leaves the device where both call legs are VoIP calls. A licence from Cisco may be needed. A CUBE supports both H323 and SIP, and has extensive interoperability with other vendor systems, so can be used to protect many non Cisco solutions.
There is also a software only version of the CUBE that runs as a Virtual Machine.
To convert from unencrypted VoIP calls to encrypted VoIP calls, an ISR CUBE is first configured to host a secure transcoder. This uses DSP resources and DSP resources are provided withing a CUBE with a PVDM module. A PDVM sizing tool called DSP Calculator is available on cisco.com under support / other tools.
The CUBE is configured to accept an incoming call from an IP-PBX and to onward route the call to somewhere else. The call routing logic is normally dealt with using inbound and outbound dial-peer configuration. If the call routing requires a shift from non-secure to secure, or vice versa then the secure transcoder is invoked to enable the audio conversion.