BrightStack
BrightStack
Service Board Login

news-events-header

Tuesday, 01 November 2011

November/December 2011 Newsletter

November/December 2011

Implementing a Business Continuity and Disaster Recovery solution using ShoreTel

ShoreTel is a single image solution.This means, all sites, users, switches, phones and licenses are all managed through a central interface (called Director) and distributed to users at locations distributed across an organizations footprint.Some organizations are single site with all users at one location and some remote users who access the system while travelling or working from home.Other organizations have multiple locations which are connected together through a Wide Area Network (using such technologies as Internet VPN, MPLS, Metro Ethernet, etc).

Whether single site or multiple location, it is easy to add a Business Continuity/Disaster Recovery site to ShoreTel.The following is a high level overview of the components required and some suggestions and alternatives.Please contact me directly to discuss further.brightstack offers a hosted ShoreTel service where we can host your Business Continuity and Disaster Recovery (BC/DR) site as part of a Managed Services offering.Some companies realize that the BC/DR site effectively becomes a Hosted ShoreTel solution, and they decide to move production to the BC/DR site and have “built-in disaster recover and business continuity” in their Headquarters Site now in the datacenter.They then carry voice traffic over the private network to the locations (sites with higher user counts often deploy PRI’s at the local site).

Add the site in Director

Select the location of the BC/DR site.If you already have a BC/DR datacenter in place, and it is networking withyour primary location, this step is pretty easy.You would simply need to acquire equipment and add the location as a site within Director.You will need a site license for this site.

Establish the Network

You will need a private network between the BC/DR site and your remote locations.If you contract with a carrier to provide network services for your entire organization, it may make sense to use one of their Datacenters as your BC/DR site and hang their datacenter off your network as another site.Also make sure you have some access to the Public Internet at the BC/DR site, this will be helpful for backup Internet VPN’s, as well as third party SIP trunking (more on that below).You may also want to deploy a VPN concentrator for VPN phones at remote locations, or a SSL VPN for VPN clients for things such as SoftPhones.Some customers, and brightstack includes this in our offering, use Remote Desktop through Microsoft RDC, Citrix or VMWare View to access Communicator remotely.

Deploy equipment in the BC/DR site

In the BC/DR site, you will need a backup Director in an active/passive configuration (known as a DVS) and voice switch.We recommend deploying a small switch just for voice control (such as an SG30) and a T1K for PRI trunking.The DVS will replicate with Director and contain a copy of your configuration.If you already have a BC/DR site up for your data operations and are running Virtual Hosts on Physical Servers using VMWare, you can use your VMWare infrastructure to host the DVS in the BC/DR site.

Provision the circuits

If your BC/DR site is within a carrier datacenter, you can easily get a PRI cross connect with no local loop charges, only port and usage charges.Additionally, there are third party Internet based SIP providers who can also deliver dial tone to your ShoreTel solution using SIP.You will need to create trunk groups and trunks.These trunks will have their own set of numbers associated with the trunk group.When you provision circuits, make sure you have enough capacity to support External Assignment.Meaning, you will need 1 trunk to connect with the externally assigned user and another trunk for the incoming or outgoing call itself.

Establish forwarding of your numbers

You should plan well ahead of time how numbers will forward to the BC/DR so calls will come into the ShoreTel system in your BC/DR site.Many carriers offer a service called Direct Trunk Overflow.Using DTO, you can automatically forward calls on a failed circuit (such as a location that is lost in the event of a disaster) to another circuit or lead number in a hunt group.You should also plan for usage charges if you are forwarding calls from one carrier to another.If your BC/DR site is on the same network as the carrier who provides services to the failed location, they should be able to point call paths from the failed circuit to the circuit at the BC/DR location.Once a disaster is declared and calls are forwarded to the BC/DR site, they can be answered by an operator (who is located anywhere and accessing the ShoreTel system through one of the mobility options) who is directing calls, an auto attendant or even by DID.

Provide users access

User access is very easy, they shouldn’t miss a beat.The following mechanisms can ensure end user access to the BC/DR site.brightstack includes all of these options in our offering:

  1. Smply login to office anywhere and assign extension to last known external assignment;
  2. Softphone access using VPN Client;
  3. VPN Phone with using VPN Concentrator;
  4. Mobility device (iPhone, Android, Blackberry) using WiFi through the Mobility Router;
  5. Mobile Call Manager (which is really a GUI to office anywhere);

Using any of these solutions, users will be able to access calls.I suggest testing and preparing ahead of time, especially for the operator.As a use case the following scenario may play out in a disaster:

  1. Disaster is declared;
  2. Users move to their assigned recovery location (which may be their home, other office, etc)
  3. User accesses remote desktop
  4. Communicator is launched
  5. Extension is assigned to External Assignment or user logs in to VPN phone
  6. Communicator now controls extension

Test everything, run fire drills

Make sure your users have a set of instructions and are trained on how to use the BC/DR site.You should also test your BC/DR plan on a routine basis.

Use Cases

Empire Capital has a single image ShoreTel solution installed in their NY office.  They also have a Business Continuity and Disaster Recovery site in NJ.The ShoreTel system is designed to be resilient, highly available and redundant and provide N+1 redundancy across key components.  Additionally, Empire Capital  has deployed an MPLS network between locations and deployed Voice services from their carrier at both locations.

New York

Empire Capital’s main location is NY.  The director server is in NY, along with 1 SG120 and 1 PRI switches. 

The following are points of failure, with an assessment of Empire’s risk at this location per point of failure and a recommendation to mitigate the risk.

  1. NY connects to the datacenter via MPLS.  Redundancy for the MPLS network is an Internet based VPN should the MPLS fail.
  2. NY has 2 PRI’swith 2 PRI switches in place.  This will provide N+1 redundancy should one of the PRI’s fail, although users will operatein a degraded state during the outage, since 50% of the trunks are down.
  3. If one of the PRI’s in NY fails, the inbound calls on the DID’s on the failed PRI should automatically, or with manual intervention, route to the channels on the operational PRI.This needs to be programmed and implemented by the carrier. 
  4. If both PRI’s fail, the inbound calls on the DID’s on the NY PRI’s should automatically, or with manual intervention, route to channels on a PRI in the NJ datacenter.  Calls can then be routed back to NY over the MPLS Network, or be handled by an operator in external assignment out of the NJ datacenter if the NY MPLS connection goes down.   
  5. Inbound calls on the failed PRI can also point to the lead number of the backup POTs hunt group in NY. 
  6. If both PRI’s fail in NY, outbound calls will continue to route over the NJ Datacenter’s PRI’s. 
  7. If the voice switch in NY fails, phones will register with the N+1 switch in the datacenter.
  8. There are 2 emergency phones powered by Telco should a power outage occur.
  9. NY uses the Director server for Voicemail.  If the Director server fails, the system will still operate, but pc call manager control, auto attendant and voicemail will not function.  brightstack recommended deploying a DVS in NY, moving the mailboxes onto the DVS for the NY users.  If the DVS fails, the voicemails will be backed up by the Director server.
  10. In the event the NY office is not accessible, users should have instructions regarding accessing the system through Office Anywhere out of the NJ Datacenter.
  11. NY has POTs lines connected to the system for backup 911. These can also be used should both PRI’s fail as describe above.  As a tertiary trunking mechanism, internet based SIP trunks can be implemented.
  12. Operators in Office Anywhere, External Assignment or through Mobility can service all the locations should a failure occur.
 

Register for an event! To see what events are upcoming, please visit our event page here

brightstack is hiring! To view our job openings, please visit our job center here

 

 

breaker line

spacer line

Wireless Device Acceptable Use Policy

(This is an example Acceptable Use Policy.  Please consult with an attorney before using this.) 

 

Summary

Objective

The organization’s Cell Phone & PDA Policy exists to control costs, secure organization data and protect mobile devices from theft.

Audience

Every officer, manager, employee, contractor, temporary worker, authorized agent and volunteer is subject to the terms of the organization’s Cell Phone & PDA Policy.

Violation of Policy

Any violation of the Cell Phone & PDA Policy must be immediately reported to the Information Technology department manager.

Violating the Cell Phone & PDA Policy, or any of its tenets, could result in disciplinary action leading up to and including termination of employment and civil and/or criminal prosecution under local, state and federal laws.

The organization will provide cellular telephones (complete with PDA features and monthly voice and data service) for all employees at and above the level of Director. Employees below Director level may request organization-provided cellular telephones (without PDA features) and monthly voice service with the written consent and approval of their manager.

When circumstances require, managers may request cellular telephones with PDA features and monthly voice and data service for employees. In such cases the manager must identify the business justification for the purchase and service requirements in a written request to the Information Technology department manager.

The Information Technology department manager is only responsible for identifying compatible PDA platforms, purchasing equipment and supporting organization-provided cellular telephones and authorized PDAs. The Information Technology department manager is not responsible for determining employee eligibility or allocating funds to pay for cellular telephones and PDAs, accessories and/or service fees; the requesting manager must allocate funds from his/her department’s operating budget to cover costs arising from the cellular telephone/PDA request.

Organization-provided cellular telephones and PDAs are only to be used for fulfilling business responsibilities. No organization-provided cellular telephone and PDA devices are to be used for personal reasons; employees are prohibited from incurring any fees or charges as a result of personal use of organization-provided cellular telephone and/or PDAs and subsequently billing those fees and charges to the organization. If cellular telephone, PDA, accessory and/or service fees or charges result from personal use of organization-provided equipment, the employee is responsible for making payment for those fees and charges and any related billing costs.

Employees are prohibited from installing unapproved and unauthorized software on organization-provided cellular telephones and PDAs. Employees shall refrain from downloading additional software and services, including distinctive ring tones, games and other messaging services, to organization-provided cellular telephones and PDAs.

No employee may connect, dock or otherwise synchronize any unapproved cellular telephone or PDA, whether owned personally by the employee or provided by the organization, with any organization computer, laptop, server, system or network, without the prior written consent of the Information Technology department manager.

Employees awarded organization-provided cellular telephones and PDAs are responsible for the security of those devices. Employees are to keep the devices on their person at all times when traveling. Employees are responsible for replacing lost or stolen cellular telephones and PDAs; all organization-provided cellular telephones, PDAs and accessories remain the property of the organization.

No sensitive, proprietary or confidential information is to be stored on cellular telephones and PDAs at any time. In the event an organization-provided cellular telephone or PDA is lost, stolen or misplaced, the Information Technology department manager should be notified immediately (regardless of time of day) so that appropriate steps can be taken to remotely trigger the timely deletion of all contact and calendar information contained on the cellular telephone/PDA.

 

An employee who uses a company-supplied device or a company-supplied vehicle is prohibited from using a cell phone, hands on or hands off, or similar device while driving, whether the business conducted is personal or company-related. This prohibition includes receiving or placing calls, text messaging, surfing the Internet, receiving or responding to email, checking for phone messages, or any other purpose related to your employment; the business; our customers; our vendors; volunteer activities, meetings, or civic responsibilities performed for or attended in the name of the company; or any other company or personally related activities not named here while driving. Use of company owned vehicles or devices for personal business is discouraged. 

Acknowledgment of Cell Phone & PDA Policy

This form is used to acknowledge receipt of, and compliance with, the Cell Phone & PDA Policy. 

Procedure 
Complete the following steps: 

Read the Cell Phone & PDA Policy.

Sign and date in the spaces provided below.

Return a copy of this signed document to the Information Technology department manager.

 

Signature

Your signature attests that you agree to the following terms:

 

(i) I have received and read a copy of the Cell Phone & PDA Policy and understand and agree to the same;

(ii) I understand and agree that I will not use any organization-provided cellular telephone or PDA for any activities other than those necessary for fulfilling the organization’s business activities;

(iii) I understand and agree that I will not incur any costs or charges resulting from personal use of organization-provided cellular telephones and/or PDAs without reimbursing the organization for those costs;

(iv) I understand and agree that no cellular telephones and/or PDAs are to be connected to organization-provided computers, laptops, servers, systems or networks without the prior written authorization of the Information Technology department manager;

(v) I understand and agree that no sensitive, proprietary or confidential data is to be stored on cellular telephones and/or PDA at any time;

(vi) I understand and agree that the security and replacement of any organization-provided cellular telephone and/or PDA awarded to me becomes my responsibility and that organization-provided cellular telephones and PDAs remain the property of the organization;

(vii) I understand and agree that any violation of the Cell Phone & PDA Policy could result in termination of my employment and civil and criminal penalties.

 

 

______________________________________

 

Employee Signature

 

 

______________________________________

 

Employee Name

 

 

______________________________________

 

Employee Title

 

 

______________________________________

 

Date

 

 

______________________________________

 

Department/Location

 

 
spacer line
 

managed-services

brightstack offers a full-suite of Managed Services ideal for organizations that don’t want to maintain an internal IT department or are looking for a trusted partner to help augment internal resources.

Upcoming Events

There are no upcoming events.

BrightStack

Sign up for our FREE seminars to learn more about putting technology to work for your orgaization. We look forward to seeing you!

BrightStack

Contact brightstack today to learn how our innovative technology solutions and world-class customer service can benefit your business.

GET A CONSULTATION NOW »

Upcoming Events

There are no upcoming events.