Initial data Integration of the ECSS-10 Class 5 software switch (SSW) on 1 physical server with support for SIP with the following parameters per load:
|
According to the technical specification, it is required to determine the hardware platform.
Example of drafting hardware requirements
Device | Required resource | Hardware product series | |
|---|---|---|---|
MCL | MUL | ||
Server 1 | 2500 | 15000 | Heavy |
After determining the requirements of the project, create a preliminary network map.
An example of components allocation in the address space for a single node:
Server name (host) | Role | Interface | Address | Port |
|---|---|---|---|---|
Static addresses of the software switch | ||||
| ecss1 | Server address | net.10 (mgm) | 10.0.10.10/24 | - |
| ecss2 | Protocole adapter address | net.20 (voip) | 10.0.20.10/24 | - |
ecss1 | Gateway address | net.10 (mgm) | 10.0.10.1 | - |
ecss2 | DNS server addresses | net.10 (mgm) | 10.0.10.1, 8.8.8.8 | - |
Internal addresses of the software switch | ||||
| ecss1 | Core address (ecss-core) | lo | 127.0.0.1/24 | 5000 |
| ecss2 | Media server address (ecss-media-server (MSR)) | lo | 127.0.0.1/24 | 5040 |
The topology of connecting the server to the network to ensure redundancy is recommended to be done using 2 switches.

Figure 1 — Network connection diagram
Option 1. Active-backup
The switches are connected in erps ring.
All 4 physical network interfaces are connected into 1 aggregated link (bond). Server port aggregation is configured in active-backup mode, i.e. there is always only 1 network interface in operation. Server network interfaces are connected in pairs in switches, on which port aggregation (port-channel) is also configured in active-backup mode.
For example, eth0 and eth1 are connected in the first switch, and eth2 and eth3 are connected in the second.
Option 2. LACP
The switches are connected in a stack. The stack must logically operate as a single switch, capable of providing port aggregation between different physical switches in LACP mode. MES-3124 with specialized firmware can be an example.
All 4 physical network interfaces are connected into 1 aggregated link (bond). Server port aggregation is configured in 802.3ad mode. Network cards aggregated groups with same rate and duplex are created. With such a combination, the transmission uses all channels in active aggregation according to the IEEE 802.3ad standard. The choice on which interface to send a packet is determined by policy. By default, it is XOR policy, also xmit_hash policy can be used. For more information, see Netplan section.
Requirements:
Server network interfaces are also included in pairs in switches, on which port aggregation (port-channel) is configured in LACP mode. For example, eth0 and eth1 are included to first switch (port-channel 1), and eth2 and eth3 — to the second (port-channel 2).
Installation of ECSS-10 consists of two main parts:
This section describes the operating system installation, as well as required and optional packages. ECSS-10 version 3.18 runs on Ubuntu 22.04.
Preliminary requirements:
To install the OS, do the following:
|
An option for storing information in a file system on physical media for servers
| 1 | Operating system boot partition (created automatically) | boot | raid 1: hdd1, hdd2 | boot | /boot | ext4 | 1 GB | Primary |
| 2 | Operating system root partition | root | raid 1: hdd1, hdd2 | root | / | ext4 | 30 GB | Logical |
| 3 | Local database information | mnesia | raid 1: hdd1, hdd2 | mnesia | /var/lib/ecss | ext4 | 10 GB | Logical |
| 4 | Distributed database for storing media resources | glusterfs | raid 1: hdd1, hdd2 или hdd3 | glusterfs | /var/lib/ecss/restfs | ext4 | Max GB | Logical |
| 5 | OS subsystem operation logs | log | raid 1: hdd1, hdd2 или hdd3 | log | /var/log | ext4 | 20 GB | Logical |
| 6 | ECSS subsystem operation logs | ecss_log | raid 1: hdd1, hdd2 или hdd3 | ecss_log | /var/log/ecss | ext4 | 20 GB | Logical |
| 7 | Databases | ecss_db | raid 1: hdd1, hdd2 или hdd3 | ecss_db | /srv/ecss/ecss-postgres-bdr-ssw/ | ext4 | 100–400 GB* | Logical |
| 8 | User files | home | raid 1: hdd1, hdd2 или hdd3 | home | /home | ext4 | 10 GB | Logical |
* The recommended value for series Light, Light+, Midi is 100 GB. The recommended value for series Heavy is 200 GB, for Super Heavy is 400 GB. |
The system requires at least 256 GB of free space.
It is neccessary to configure "hostname" parameter on the system servers.
It is recommended to specify the same username (anything except ssw) on all servers in the system. The ECSS-10 license is linked to the eToken/ruToken key and the computer hostname. The system user ssw is created when installing the ecss-user package.
When installing the system in a cluster, the recommended value for the first server is ecss1. |
Install the software switch according to the parameters specified in the technical specification. In this example, it is assumed that the required operating system is already installed.
It is recommended to split traffic used for different purposes. For example, management traffic and VoIP traffic. To do this, 2 or more VLANs are created. In the minimum case and with a small load, one VLAN can be enough. Hovewer, it will cause inconvenience in the future at traffic dump and its analysis. According to the technical specification, host IP adresses, gateways, DNS, routing and other parameters are configured on VLAN.
According to the technical specification, the following addresses are used in a given example:
There is an address structure inside the server platform and internal addresses are used for interaction between subsystems (nodes) in the cluster. For example, the internal address for a cluster on one server is 127.0.0.1, while the kernel (ecss-core) interacts with the multimedia data processing server (ecss-media-server). Their interaction takes place using the same address, but each software part has its own transport port: ecss-core — 5000, ecss-msr — 5040.
A single address for accessing the MySQL database is defined for all cluster nodes, for example, the ecss-mysql address 127.0.0.1. Thus, the uniformity condition is fulfilled, in which all cluster nodes have completely identical data about the current state of the dynamic components of the software switch (for example, call history).
According to the technical specification, the system has 4 network interfaces. Information about their status can be viewed using the ifconfig or ip a command:
| eth0: flags=6211<UP,BROADCAST,RUNNING,SLAVE,MULTICAST> mtu 1500 ether 36:10:28:73:63:01 txqueuelen 1000 (Ethernet) eth1: flags=6211<UP,BROADCAST,RUNNING,SLAVE,MULTICAST> mtu 1500 ether 36:10:28:73:63:01 txqueuelen 1000 (Ethernet) eth2: flags=6211<UP,BROADCAST,RUNNING,SLAVE,MULTICAST> mtu 1500 ether be:77:ea:52:4d:39 txqueuelen 1000 (Ethernet) eth3: flags=6211<UP,BROADCAST,RUNNING,SLAVE,MULTICAST> mtu 1500 ether be:77:ea:52:4d:39 txqueuelen 1000 (Ethernet) lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 127.0.0.1 netmask 255.0.0.0 |
First, the network interfaces are configured. Ubuntu18 uses the netplan utility to configure.
This utility is meant for configuring the network and then uploading it to the system using the network manager networkd or NetworkManager.
sudo nano /etc/netplan/ecss_netplan.yaml |
The rest of files from this directory should be moved to another place or be romoved. |
In the configurations for each host, first of all, declare the ethernets section, which describes existing in the system Ethernet interfaces that will be used in the future. It is important to disable the use of dynamic address allocation (DHCP) for each interface.
Optionally, gateways for communication with the outside world and DNS server addresses are defined, as well as IP addresses for each interface.
Note that while editing netplan, you must follow the YAML markup rules:
→ Section |network → Subsection |_'_'bonds: → Subsection of the bonds section description |_'_'_'_'bonded_one: → etc. |_'_'_'_'...
|
Example of configuring ecss-netplan.yaml file for active-backup connection option:
# Netplan for the ecss1 host of the software switch
|
The following bond settings are required for the ECSS server to run correctly:
mode: active-backup - specifies the operating mode in which one link is selected as active, while the others remain in backup;
primary-reselect-policy: failure - specifies that a new active link should be selected only when the current active link fails. This avoids unnecessary switching;
gratuitous-arp: 5 - when the active link changes, five gratuitous ARP requests are sent to the switch to update its switching table. This facilitates faster switching;
all-slaves-active: true - forces incoming frames to be accepted on the backup interfaces. This ensures that traffic balancing on the MES does not interfere with operation. Data flows to the server from all links, and the server sends data only from the active link;
mii-monitor-interval: 100 - enables link monitoring via the MII interface and specifies a polling interval of 100 ms;
up-delay: 1000 - specifies that a connected interface should not be considered immediately available for operation, but rather a one-second delay should be applied after the interface has been connected. This is necessary to avoid unnecessary switching when the port repeatedly switches between the "on" and "off" states.
It is also recommended to check for any other files in the /etc/netplan/ directory. If other files are present, they should be moved to another directory or deleted. Otherwise, incorrect configuration of network interfaces and incorrect operation of SSW may occur. |
Apply parameters with the command:
sudo netplan apply |
It is neccessary to configure "hostname" parameter on the system servers.
It is recommended to specify the same username (anything except ssw) on all servers in the system. The ECSS-10 license is linked to the eToken/ruToken key and the computer hostname. The system user ssw is created when installing the ecss-user package.
When installing the system in a cluster, the recommended value for the first server is ecss1. Other host names are possible only upon project approval; this will be required to generate licenses. |
Specify hostname: ecss1 in file /etc/hostname:
sudo nano /etc/hostname |
Specify real IP address and host name (for example 10.0.20.41 ecss1) in file /etc/hosts:
127.0.0.1 localhost # Local loopback address, used by some ecss services 10.0.20.41 ecss1 # Host address |
Use cpufrequtils utility.
sudo apt install cpufrequtils |
By default, after installation, Ubuntu uses the "ondemand" mode (CPU performance is based on application requests, saving power, but lower performance):
cat /etc/init.d/cpufrequtils | grep GOVERNOR= |
In the system output message, the default operating mode after installation is "ondemand":
GOVERNOR="ondemand" |
Set the efficiency/performance mode - replace the value "ondemand" with "performance" in the file /etc/init.d/cpufrequtils.
sudo sed -i 's/GOVERNOR="ondemand"/GOVERNOR="performance"/g' /etc/init.d/cpufrequtils |
Restart the utility:
sudo /etc/init.d/cpufrequtils restart |
Then run the command:
sudo systemctl daemon-reload |
The Ubuntu SSW server operates in real time, so all necessary data must be in RAM. Using a swap file (/swap.img) can increase the processing time of ECSS10 SSW application calls, which is unacceptable. Disable swap.
Run three commands in sequence:
Disable swap:
sudo swapoff -a |
Delete swap.img file.
sudo rm /swap.img |
Comment out the line "/swap.img none swap sw 0 0" in the "/etc/fstab" file – change it to "# /swap.img none swap sw 0 0"
or delete this line (/swap.img none swap sw 0 0).
sudo nano /etc/fstab |
# /etc/fstab: static file system information. # # Use 'blkid' to print the universally unique identifier for a # device; this may be used with UUID= as a more robust way to name devices # that works even if disks are added and removed. See fstab(5). # # <file system> <mount point> <type> <options> <dump> <pass> # / was on /dev/sda2 during curtin installation /dev/disk/by-uuid/731728e2-4d6b-499a-afea-9362fd6726b2 / ext4 defaults 0 1 |
To check, run the command free -h:
free -h |
Swap size is 0 – that is, it is disabled
free -h
total used free shared buff/cache available
Mem: 3,9G 110M 3,2G 820K 535M 3,5G
Swap: 0B 0B 0B
|
When installing Ubuntu 22, it is not prompted to set a time zone (UTC is the default). One should set it manually (for the rating system, scheduled tasks, etc.) to function correctly. For example:
sudo timedatectl set-timezone Asia/Novosibirsk |
It is possible to improve the performance of high-load servers by increasing the open file limit.
To set the open file limit, follow these steps:
Check the current limit with the command:
ulimit -a |
Result:
eltex@ecss1:~$ ulimit -a core file size (blocks, -c) 0 data seg size (kbytes, -d) unlimited scheduling priority (-e) 0 file size (blocks, -f) unlimited pending signals (-i) 15515 max locked memory (kbytes, -l) 65536 max memory size (kbytes, -m) unlimited open files (-n) 1024 pipe size (512 bytes, -p) 8 POSIX message queues (bytes, -q) 819200 real-time priority (-r) 0 stack size (kbytes, -s) 8192 cpu time (seconds, -t) unlimited max user processes (-u) 15515 virtual memory (kbytes, -v) unlimited file locks (-x) unlimited |
This limit (open files 1024) is not enough for normal operation of high-load servers.
Set open file limit for each user:
sudo sed -i '55i\* soft nproc 65536\n* hard nproc 131072\n* soft nofile 65536\n* hard nofile 131072\nroot - memlock unlimited' /etc/security/limits.conf |
|
Installation of packages must be done NOT under the ssw system user. |
Add the ELTEX repository to install the ECSS-10 system:
sudo sh -c "echo 'deb [arch=amd64] http://archive.eltex.org/ssw/jammy/3.18 stable main extras external' > /etc/apt/sources.list.d/eltex-ecss10-stable.list" |
Next, import the key with the following command:
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 33CB2B750F8BB6A5 |
Before starting the installation, update the OS:
sudo apt update sudo apt upgrade |
In case the following system message is displayed
Run the following command:
|
sudo apt upgrade |
┌ ECSS software version. Currently, it is listed as version 3 in the certification application. | It is not changed until the next certification or │ the release of a fundamentally new version of the system. │ │ ┌ System Release Version. This is the common version for all components included in a specific release. | | It is changed centrally │ │ when decided to launch a new release. Releases are usually not compatible with each other. ┌─┴┐ ┌──┴─┐ ECSS.SysRel.SubMaj.SubMin └──┬─┘ └──┬─┘ │ └ Subsystem minor version. The minor version of a subsystem is set by the subsystem developer. | The minor version │ is changed when a patch is added. Minor versions within a single major version are generally │ compatible with each other and differ within specific patches. │ └ Subsystem major version. The major version is set by the subsystem developer. The major version of a subsystem must be updated when significant changes are made to the subsystem.The APT package installation utility analyzes package version from left to right. For example, if we have package 14.14.7.7, the repository contains packages: 14.14.7.8 If a specific situation requires upgrading from version 14.14.7.7 to version 14.14.7.9, the standard command → sudo apt upgrade will not help, since the newest package will be selected. In this situation, it is needed to explicitly specify which version of the package wanted to be installed. In this example, we should select the command → sudo apt install package name=14.14.7.9. This is usually necessary for testing a specific patch; for standard updates, it is enough to select the usual command to install/update the package. |
Install all the proposed packages:
sudo apt install ntp ntpdate tcpdump vlan dnsmasq aptitude atop ethtool htop iotop mc minicom mtr-tiny nmap pptpd pv screen ssh tftpd vim sngrep tshark cpanminus gnuplot libgraph-easy-perl debconf-utils |
List of mandatory service software:
List of recommended diagnostic and support software:
|
Before installing the ecss packages, it is needed to ensure that the network's bandwidth meets the requirements. To do this, run the command sudo ethtool <interface name> for all physical interfaces.
Check the following:
|
Run the following command:
sudo apt install -y ecss-dns-env |
The installer will suggest selecting sections for configuration, do not select anything, just press Enter.
Before installing
|
sudo apt install -y ecss-postgres-bdr-ssw |
When installing the ecss-postgres-bdr-ssw package, the following questions will be asked:
| Questions ecss-postgres-bdr-ssw | Replies for ecss1 | Пример |
|---|---|---|
| Current IP address of the network interface. | Select an IP address from the list to use with Postgres |
|
| Installing in a cluster? | No (needs to be selected) |
|
======================================================= ======================================================= ecss-postgres-bdr-ssw successfully installed/updated! ======================================================= ======================================================= ┏┓┏┓┏┓┏┳┓┏┓┳┓┏┓┏┓ ┳┓┳┓┳┓ ┏┓┏┓┓ ┏ ┃┃┃┃┗┓ ┃ ┃┓┣┫┣ ┗┓ ┣┫┃┃┣┫ ┗┓┗┓┃┃┃ ┣┛┗┛┗┛ ┻ ┗┛┛┗┗┛┗┛ ┻┛┻┛┛┗ ┗┛┗┛┗┻┛ |
Installation of the required ecss-node package includes installation and initial configuration of the main subsystems.
The ecss-postgres-bdr-ssw package should already be installed on the system. |
To install the ecss-node package, run the command:
sudo apt install -y ecss-node |
During package installation, the ssw user is created, under which all ecss* services are launched. The necessary directories are created, DNS is configured, and SSL certificates are configured.
During installation, the ecss-user package will also be installed. |
During installation, it will be prompted to configure the parameters necessary for generating configuration files. Examples of replies are below.
| ecss-user questions | Replies for ecss1 | Example | ||
|---|---|---|---|---|
| Do you want to use the default settings? | Yes (default) |
| ||
| ecss-node questions | Replies for ecss1 | Example | ||
| abf.test (needs to be entered)
|
| ||
Do you want to use the standard settings? | No (needs to be entered) |
| ||
Select the items you want to configure: | ntp + cookie (needs to be entered) |
| ||
Enter external NTP servers separated by a space: | ntp.ubuntu.com (default) |
| ||
NTP: Do you want to use the settings for the cluster? | No (needs to be entered) |
| ||
NTP: Do you want to manually define the networks that should have access to NTP? | Yes (default) |
| ||
NTP: Enter networks that should have access to NTP separated by a space: (in the example: 10.0.10.0|255.255.255.0 10.0.20.0|255.255.255.0) | 10.0.10.0|255.255.255.0 10.0.20.0|255.255.255.0 (needs to be entered) |
| ||
Cookie for the core node: (specify a unique cookie for the core, in the example: ecss-core-example) | ecss-core-example (needs to be entered) |
| ||
Cookie for ds node: (specify a unique cookie for the ds, in the example: ecss-ds-example) | ecss-ds-example (needs to be entered) |
| ||
Cookie for mediator node: (specify a unique cookie for the mediator, in the example: ecss-mediator-example) | ecss-mediator-example (needs to be entered) |
| ||
Cookie for mediator pa-sip: (specify a unique cookie for the pa-sip, in the example: ecss-pa-sip-example) | ecss-pa-sip-example (needs to be entered) |
| ||
Cookie for mycelium: (specify a unique cookie for the mycelium, in the example: ecss-mycelium-example) | ecss-mycelium-example (needs to be entered) |
| ||
Cookie for sorm: (specify a unique cookie for the sorm, in the example: ecss-sorm-example) | ecss-sorm-example (needs to be entered) |
| ||
| ecss-user questions | Replies for ecss1 | Example | ||
Maximum size of uncompressed dump in bytes. | 8G (default) |
| ||
| Maximum size of compressed dump in bytes. | 2G (default) |
| ||
The maximum size that the /var/lib/systemd/coredump directory can occupy is: | default (default) |
| ||
Minimum amount of free disk space in bytes. | 30G (default) |
| ||
Save to a safe place and delete the file /etc/ecss/ssl/ecss10root.key! | Ok (default) |
| ||
Check the status of services with the following command:
systemctl is-active ecss-core ecss-pa-sip ecss-ds ecss-mediator ecss-mycelium |
If the status is "active", continue; if the status is "inactive", run the command "sudo systemctl restart ecss-<package name>"
systemctl is-active ecss-core ecss-pa-sip ecss-ds ecss-mediator ecss-mycelium active active active active active |
To view information about the NTP synchronization status, the command "ntpq -p" is used. If the additional key "–n" is used, the IP address will be displayed instead of the server name:
ntpq -p
remote refid st t when poll reach delay offset jitter
==============================================================================
*185.125.190.56 17.253.28.253 2 u 45 64 1 83.893 +0.470 2.177 |
The ECSS-10 system uses the ELM licencing – the ECSS ecosystem's license distribution service, consisting of ecss-license-agent and ecss-license-provider.
|
To install the ecss-license-provider package, it is necessary to run the following command:
When installing the ecss-license-provider package, you will be asked the following questions:
The data is saved in a file — /etc/ecss/ecss-license-provider/config.env:
|
The ECSS-10 system uses the "License Provider" – the ECSS ecosystem's license distribution service, consisting of ecss-license-agent and ecss-license-provider.
LP configurationThe ecss-license-provider service uses two configuration files: /etc/ecss/ecss-license-provider/config.env and /etc/ecss/ecss-license-provider/config.yaml. The config.yaml file contains the basic settings for connecting to the ELM server, including where to obtain licenses, which licenses to use, and where to transfer them. All of this must be configured manually.
To enable system nodes to become operational, it is necessary to configure the system by specifying the names of the hosts on which the ecss services are deployed. Command in CoCon: /system/clusters/set [<host1>, <host2>, ... <hostN>]. In a single server configuration (hostname ecss1), run the command:
Connecting the SSW to the License ProviderConfigure the SSW connection to the LP using the following command in CoCon (in this example, the LP with IPadd host 10.0.10.51. The default port value from the /etc/ecss/ecss-license-provider/config.env file is 4321):
After completion, check the connection status with the command:
The host must have the alive=true status and be "current."
If the status off the LP host is shown as current, it is possible to send a request to download a license to the SSW using the command:
Depending on the selected license type for SSW: "type=elm" or "type=ecss_license", we will receive different output from the license viewing command:
or
|
Perform configuration for the Sip adapter by running the following command:
sudo systemctl edit ecss-pa-sip.service |
Add the following data to the configuration file:
[Service] LimitNOFILE=65536 |
These two lines need to be inserted in a specific location. (Starting with Ubuntu 22.04.2, there are a few important points. The file that opens is completely commented out, but the first few lines look like in the image below. Any edits you make should be between these two comment blocks). |

Reload the configuration
sudo systemctl daemon-reload |
Update the configuration file by rebooting the server:
sudo systemctl restart ecss-mycelium ecss-ds ecss-core ecss-pa-sip ecss-mediator |
Next, the ecss-restf packages are installed, followed by ecss-media-server, ecss-media-resources, ecss-web-conf and others in any order:
sudo apt install -y ecss-restfs |
Installing ecss-restfs. During installation, you'll be asked a series of questions to create the necessary configuration files. The installer will also prompt you to install and configure the Text2speech package from Yandex.
| ecss-restfs questions | Replies | Example |
|---|---|---|
| Do you want to use Text To Speeh (TTS service)? | No (default) |
|
| Do you want to configure phone book? | Yes (needs to be selected) |
|
| Do you want to configure carddav server? | No (default) |
|
Do you want to configure phone book (LDAP)? | No (default) |
|
| Do you want to configure phone book (SSW)? | No (default) |
|
| Do you want to configure speech recognition service? | No (default) |
|
| Do you want to configure phone book (POSTGRES)? | Yes (default) |
|
| POSTGRES: postgres service: | localhost (default) |
|
| POSTGRES: Connection port: | 5439 (default) |
|
| POSTGRES: Login: | postgres (default) |
|
| POSTGRES: Password: | postgres1 (default) |
|
| POSTGRES: database: | ecss_storekeeper_db (default) |
|
| Enter a domain to search: | test.domain (default) |
|
| POSTGRES: Number of contacts requested: | 10000 (default) |
|
| Do you want to enable transliteration for your phone book (LDAP)? | No (default) |
|
| Select the items you want to customize: | proxy-filter (needs to be selected) |
|
Enable whitelist for api/proxy? |
|
# ------------------------------------------------------------------- |
In case of successful proxying (200), the cache is stored for 28 days, therefore, to apply the filter configuration, in case of changes, the cache (/var/cache/ecss/restfs-api) should be deleted and the ecss-restfs service should be restarted. |
After installing the ecss-restfs package, check for the presence of auto-informer wav files in the /var/lib/ecss/restfs/system/sounds/ directory using the command:
ll /var/lib/ecss/restfs/system/sounds/ |
The presence of about 140 wav files in the directory specified above indicates that the ecss-restfs package was installed correctly.
The absence of wav files in the above directory indicates a problem installing the ecss-restfs package. To resolve this, run the following command:
and repeat the verification command:
|
Check the accessibility of these files from the outside. To do this, execute the command on the host ecss1 one by one:
wget http://ecss1:9990/system/sounds/ai_you.wav |
wget http://ecss1:9990/system/sounds/ai_you.wav --2023-12-18 17:43:29-- http://ecss1:9990/system/sounds/ai_you.wav Resolving ecss1 (ecss1)... 127.0.1.1, 10.0.10.11 Connecting to ecss1 (ecss1)|127.0.1.1|:9990... connected. HTTP request sent, awaiting response... 200 OK Length: 11670 (11K) [audio/x-wav] Saving to: ‘ai_you.wav’ ai_you.wav 100%[========================================================================================>] 11,40K --.-KB/s in 0s 2023-12-18 17:43:29 (301 MB/s) - ‘ai_you.wav’ saved [11670/11670] |
verification files can be deleted
rm ai_you.wav |
sudo apt install -y ecss-media-server |
For the media server (ecss-media-server/MSR), initial configuration is possible by writing parameters to a configuration file. To do this, configure transport bind-addr,mcc bind-addres:
| ecss-media-server questions | Replies for ecss1 |
|---|---|
| [ MSR SIP ] Enter bind-ip address | 10.0.20.41 (needs to be entered) |
| [MSR Control-Channel] Enter bind-ip address | 10.0.20.41 (needs to be entered) |
After creating the default configurations, perform a check:
cat /etc/ecss/ecss-media-server/config.xml |
The msr configuration is located inside: config.xml, and the default.xml configuration is in the conf.d directory.
Default.xml is an extension of config.xml that defines the accounts section. This is done to ensure that this configuration remains unchanged after package updates.
<?xml version="1.0" encoding="utf-8"?>
<config date="09:24:23 03.12.2025">
<general log-level="3" log-rotate="yes" max-calls="2148" max-vid-calls="100" max-in-group="512" load-sensor="media" load-delta="10" calls-delta="100" spool-dir-size="100M" log-name="msr.log" log-path="/var/log/ecss/media-server" use-srtp="disabled" enable-ice-transport="no" ice-update="no" aggressive-ice="yes" stun-server="" suspicious-mode="no"/>
<transport bind-addr="10.0.20.41" port="5040" transport="udp+tcp"/>
<!-- By default configured public TURN-server -->
<turn-server use-turn="no" host="numb.viagenie.ca" user="webrtc@live.com" password="muazkh"/>
<media mixer-clock-rate="8000" use-vad="no" cng-level="0" jb-size="60" rtcp-timeout="0" rtp-timeout="350" udp-src-check="no" cn-multiplier="3" port-start="12000" port-range="4496" tias-in-sdp="no" thread-cnt="2" vid-enc-threads="2" vid-dec-threads="2" video-conf-layout="evenly" keyframe-interval="1000" vid-decode-delay="100" silent-codec-switch="yes" silence-threshold="-30" dtmf-flash-disable="no" video-dscp="0" other-dscp="0" dummy-video-src="/usr/share/ecss-media-server/video/dummy_video.yuv" video-enc-width="640" video-enc-height="360" finalsilence="1000" rtcp-stat-dump="yes" dtmf-tg-fpc-loop="10" dtmf-tg-fit="1" dtmf-tg-fot="2" dtmf-tg-volume="12288"/>
<codec pcma="1" pcmu="2" ilbc="0" gsm="0" g722="3" g726="0" g729="0" speex="0" l16="0" g7221="0" opus="0" h264="1" h263-1998="2" t38="1" tel-event-pt="0"/>
<accounts>
<!-- <dynamic msr_name="msr.name"
realm="sip:127.0.0.1:5000"
dtmf_mode="rfc+inband+info"
auth_name="user"
auth_password="password" /> -->
</accounts>
<pbyte>
<mcc bind-addr="10.0.20.41" port="5700"/>
</pbyte>
<conf_dir path="/etc/ecss/ecss-media-server/conf.d"/>
<metrics enable="yes" use-pushgateway="yes" pushgateway-addr="127.0.0.1:9091" push-interval="5" port="8100" msr_name="msr2"/>
<rtp>
<auto addr-v4=""/>
</rtp>
</config> |
By default, after installation, ECSS-10 activates only the following codecs: pcma, pcmu, g722, h264, h263-1998, and t38. The rest have a status of 0 = off. If you want to activate other codecs, use the nano editor to change the priority from 0 to a priority number (the priority level should not be repeated for the audio/video/fax service).
sudo nano /etc/ecss/ecss-media-server/config.xml
To activate all codecs, change the line - <codec pcma="1" pcmu="2" ilbc="0" gsm="0" g722="3" g726="0" g729="0" speex="0" l16="0" g7221="0" opus="0" h264="1" h263-1998="2" t38="1" tel-event-pt="0"/> |
It's not allowed to specify the same priority for different codecs, for example, g722="5" g729="5". Otherwise, they will not work correctly or will be ignored. |
Consider the accounts section (default.xml file):
cat /etc/ecss/ecss-media-server/conf.d/default.xml |
Check the data for correctness.
<?xml version="1.0"?>
<config>
<accounts>
<dynamic msr_name="msr.ecss1" realm="sip:10.0.20.41:5000" dtmf_mode="rfc+inband+info" auth_name="user" auth_password="password">
<via dynamic-ifaces="no">
<iface name="net.20" ip="10.0.20.41"/>
</via>
</dynamic>
</accounts>
</config> |
It specifies the current settings used to register msr on core.
The main parameters here are msr_name and realm:
After changing the configuration files /etc/ecss/ecss-media-server/config.xml and /etc/ecss/ecss-media-server/conf.d/default.xml, restart the ecss-media-server for the changes to take effect, using the following command:
sudo systemctl restart ecss-media-server |
sudo apt install ecss-web-conf |
The web configurator makes system management more intuitive and convenient. Installing the web configurator is optional, but recommended.
Installing the ecss-web-conf package also automatically installs the ecss-subscriber-portal-ui package. The ECSS-10 Subscriber Portal application allows subscribers to independently manage services, view information on completed calls and active conferences, and configure their own IVR scripts for incoming calls.
| ecss-web-conf questions | Replies for both hosts | Example |
|---|---|---|
| Do you want to use the default settings? | Yes (default) |
|
Check the connectivity of the web interface http://10.0.20.41, user/password: admin/password. Not all functions are available at the moment, but the web interface should be working and the login successful.
Configure the SSH server:
sudo nano /etc/ssh/sshd_config |
Specify the port and address to which the server can be accessed in the configuration file:
| Configuring ssh for ecss1 (/etc/ssh/sshd_config) |
|---|
# This is the sshd server system-wide configuration file. See # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin # The strategy used for options in the default sshd_config shipped with Port 2000 <...> |
Restart ssh:
sudo systemctl restart ssh.service |
Installing all services specified in the license:
/cluster/storage/ds1/ss/install ds1@ecss1 ss_* |
Result:
/cluster/storage/ds1/ss/install ds1@ecss1 ss_* Successfully installed: /var/lib/ecss/ss/ss_dnd.xml Successfully installed: /var/lib/ecss/ss/ss_clir.xml . . . Successfully installed: /var/lib/ecss/ss/ss_chunt.xml |
It is recommended to use the latest available browser versions. Recommended browsers: Opera, Chrome.
To start configuring the system, go to the web configurator: http://<Ipadd SSW>.
To determine and register in the system, the following are planned:

Figure 1 — Log in to the web configurator (authorization window)
In the authorization window, enter the values defined during the installation of the web configurator.
Default values for authorization: Login: admin Password: password |
After logging in, the main workspace with application icons will be visible, as well as status bar with available options, in particular:

Figure 2 — View of the web configurator workspace
After authorization, in order to increase security during the operation of the software switch, it is recommended to create accounts for operators, as well as to change the password for the admin user.
To create a new operator account, use User manager application:

Figure 3 — Application view "User Manager"
Click the "Add" button
. In the window that opens, define a new account, for this:

Figure 4 — Operator account creation dialog box

Figure 5 — Application view with created operator account
To change the password, click the edit button next to the user name. In the dialog box that opens, enter:

Figure 6 — Edit user dialog box
To begin working with the media server immediately after its registration, it is necessary to activate the MSR network interfaces. The web configurator application "MSR registrars" is used to configure media resources.


Figure 7 — MSR registrars
Set the IP address for receiving connections from the media server, changing the value 0.0.0.0 to the actual MSR addresses:



Figure 8 — Setting the IP address of the MSR
To configure an interface, open the Clusters application.

Figure 9 — Clusters application view
To create a new IP address group (IP-set), select the SIP adapter cluster "sip1" and click on the Cluster Properties button (or double-click on the cluster icon with left mouse button).
In the dialog box that appears, go to the Transport tab. Next, click on Add button. New group will appear. To edit the fields, double-click the one you need:

Figure 12 — Clusters/Transport application view
Click Save to apply the settings.
Domain is a virtual PBX within our SSW. We can create as many of virtual PBXs as needed for a project.
To create a domain, log in to the Domains application. In the window that opens, create a domain:
1. Click the Add domain button:

Figure 11 — Adding domain to the system
2. The following settings are available in the dialog box that opens:
Enter the domain name, for example "test_domain";
3. Click Ok:

Figure 12 — Domain declare
4. Click the Update
button.
Created domain will be displayed in the current configuration:

Figure 13 — Displaying created domain
To edit current domain, it must be selected in the system. To switch to a domain, use the domain selection option (see point 2 in the figure View of the web configurator workspace).
After selecting the domain, according to the current system configuration, all applications will be available:

Figure 14 — Displaying applications in current system configuration
To link an address group to a domain, return to the "Domain" app, select the domain, and go to the settings by clicking the "Domain Properties" button or double-clicking the domain.
In the list settings, open the "SIP" branch, then "SIP Transport," then select the newly created address group in the IP set field. Click "Save" to apply the settings.

Figure 15 — SIP transport settings
Select the required services for the created domain that will be used (for example, for a subscriber domain, trunk services are not required, and vice versa for a transit domain. There is no need to specify services for the subscriber).

Figure 16 — After creating a new domain, there are no services
Save configuration.

Figure 17 — Selection of services for subscribers/trunks of the new domain

Figure 18 — List of services now available to subscribers of the new domain
0000000000000000000000000000000000000000000000000000000000000000000
When installing the package, the following data will be requested:
| Questions | Answers |
|---|---|
| Address mask for MySQL (IP pattern for MySQL permission) | 127.0.0.% |
| User login (Login for MySQL root) | root |
| MySQL user password (Password for MySQL root) | PASSWORD |
Changing the default path — agree to change the configuration file to enter the path to the ecss-mysql databases by entering "Y".
MySQL databases used by the ECSS-10 system will be stored under the path /var/lib/ecss-mysql after installation. Check for files in the folder:
ls -l /var/lib/ecss-mysql/ |
Check that the server is running:
sudo systemctl status mysql ● mysql.service - MySQL Community Server |
Installing the ecss-node package:
sudo apt install ecss-node |
During the package installation ssw user is created, on whose behalf all ecss services are launched*. The necessary directories are being created, DNS is being configured, SSL certificates are being configured. During the installation, 8 questions necessary for the formation of configuration files will be asked.
| Questions | Answers |
|---|---|
| Do you want to turn off apt-daily update? | Yes |
| Set DB config to default? | Yes |
| Set alarm true when MYSQL DB overloads | Yes |
| NTP: Do you want use settings for cluster? | No |
| External NTP servers through a space | ntp.ubuntu.com (by default). Enter one or more space-separated servers used on the site |
| NTP: Do you want use local server? | No |
| NTP: Addresses and Masks of Network, which must have access to the ntp through a space | 192.168.0.0|255.255.0.0 (by default) Enter a list of subnets from which this NTP server will be accessible, for example 10.10.0.0|255.255.255.0 |
| Install utilities for working with cdr | No |
To generate certificates, select manual method. All questions can be answered as suggested by default.
Next, ecss-media-server, ecss-media-resources, ecss-restf, ecss-web-conf and other packages are installed in any order:
sudo apt install ecss-media-server ecss-media-resources |
For the media server (ecss-media-server / MSR), initial configuration is possible with parameters recorded to the configuration file, it is required to perform the configuration without selecting any items:
| ecss-media-server questions | Answers for ecss1 |
|---|---|
| Set default settings | yes |
| Enter name (Enter) | msr.ecss1 |
| Enter address (Entrer) | 127.0.0.1 |
| Enter port (Entrer) | 5000 |
After forming the default configurations, go to the directory where the configurations are located and check them:
cd /etc/ecss/ecss-media-server/ cat config.xml cat conf.d/default.xml |
There is a configuration for msr: config.xml, the conf.d directory contains the configuration default.xml. At its core, default.xml is an addition to config.xml, which defines the accounts section. This is done in order for this configuration to remain unchanged after package updates.
Example of config.xml:
<?xml version="1.0" encoding="utf-8"?>
<config date="10:48:15 21.02.2022">
<general log-level="3" log-rotate="yes" max-calls="8192" max-in-group="512" load-sensor="media" load-delta="10" calls-delta="100" spool-dir-size="100M" log-name="msr.log" log-path="/var/log/ecss/media-server" use-srtp="disabled" suspicious-mode="no"/>
<transport bind-addr="192.168.2.21" port="5040" transport="udp+tcp"/>
<!-- By default configured public TURN-server -->
<turn-server use-turn="no" host="numb.viagenie.ca" user="webrtc@live.com" password="muazkh"/>
<media mixer-clock-rate="8000" use-vad="no" cng-level="0" jb-size="60" rtcp-timeout="0" rtp-timeout="350" udp-src-check="no" cn-multiplier="3" port-start="12000" port-range="2048" tias-in-sdp="no" thread-cnt="2" silence-threshold="-30" dtmf-flash-disable="no" video-dscp="0" other-dscp="0" dummy-video-src="/usr/share/ecss-media-server/video/dummy_video.yuv" video-enc-width="1280" video-enc-height="720" finalsilence="1000" rtcp-stat-dump="yes"/>
<codec pcma="1" pcmu="2" ilbc="0" gsm="0" g722="3" g729="0" speex="0" l16="0" g7221="0" opus="0" h264="1" h263-1998="2" t38="1" tel-event-pt="0"/>
<accounts>
<!-- <dynamic msr_name="msr.name"
realm="sip:127.0.0.1:5000"
dtmf_mode="rfc+inband+info"
auth_name="user"
auth_password="password" /> -->
</accounts>
<pbyte>
<mcc bind-addr="192.168.2.21" port="5700"/>
</pbyte>
<conf_dir path="/etc/ecss/ecss-media-server/conf.d"/>
<rtp>
<auto addr-v4=""/>
</rtp>
</config> |
Example of accounts section (default.xml file):
<?xml version="1.0"?>
<config>
<accounts>
<dynamic msr_name="msr.ecss1" realm="sip:127.0.0.1:5000" dtmf_mode="rfc+inband+info" auth_name="user" auth_password="password"/>
</accounts>
</config> |
It contains current settings according to which the msr is registered on core.
The main parameters are: msr_name and realm.
msr_name is a parameter that defines the name of the msr. (it is recommended to set the name of the msr. and the host to which it belongs, for example, msr.ecss1);
realm — defines the address for registration on the core. Default entry point: port 5000, address: 127.0.0.1.
sudo apt install ecss-restfs |
When installing, you will be prompted to set up the configuration:
| Questions | Answers |
|---|---|
Use TTS service | No |
Configure phone book | No |
Configure speech recognition service | No |
Choose nothing | Ok |
sudo apt install ecss-web-conf |
When installing, you will be prompted to set up the configuration:
| Questions | Answers |
|---|---|
| Input IP address or hostname of MySQL db for web-conf DB | 127.0.0.1 |
Input port of MySQL db for web-conf DB | 3306 |
Input IP address or hostname for ECSS-10 with http_terminal | 127.0.0.1 |
Input port SSW http_terminal | 9999 |
| Input login for SSW http_terminal | admin |
Input password for SSW http_terminal | password |
Configuring SSH server:
sudo nano /etc/ssh/sshd_config |
In the configuration file specify the port and address where you can access the server:
| Configuring ssh for ecss1(/etc/ssh/sshd_config) |
|---|
# This is the sshd server system-wide configuration file. See # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin # The strategy used for options in the default sshd_config shipped with Port 2000 <...> |
Restart ssh:
sudo systemctl restart ssh.service |
Start the necessary services.
Before starting, check Token availability in the system. |
Run the ecss-mycelium and ecss-ds packages on the first host:
sudo systemctl start ecss-mycelium sudo systemctl start ecss-ds |
Go to the CLI:
ssh admin@localhost -p 8023 password: password |
Check system status:
admin@mycelium1@ecss1$ system-status Checking... ┌─┬───────────────┬────────────────────────┬───────────────┬────────────┬──────┐ │ │ Node │ Release │ Erlang nodes │Mnesia nodes│Uptime│ ├─┼───────────────┼────────────────────────┼───────────────┼────────────┼──────┤ │ │ds1@ecss1 │ecss-ds-3.14.10.91 │ds1@ecss1 │ds1@ecss1 │8m 9s │ │ │mycelium1@ecss1│ecss-mycelium-3.14.10.91│mycelium1@ecss1│not running │8m 10s│ └─┴───────────────┴────────────────────────┴───────────────┴────────────┴──────┘ All services are started. |
Next, install passport and licenses to the system:
admin@[mycelium1@ecss1]:/$ cluster/storage/ds1/licence/set-passport <passport> admin@[mycelium1@ecss1]:/$ cluster/storage/ds1/licence/add <license> |
Exit the CoCon, reboot the ecss-mycelium and ecss-ds subsystems, and then connect the remaining subsystems in the following order: ecss-core, ecss-pa-sip, ecss-media-server, ecss-restfs, ecss-mediator, ecss-web-conf.
sudo systemctl start ecss-core ecss-pa-sip ecss-mediator ecss-media-server ecss-restfs ecss-web-conf |
Return to the CoCon.
After that, the MSR- and Core-subsystems are connected. To do this, use the following command:
admin@[mycelium1@ecss1]:/$ /system/media/resource/declare core1@ecss1 iface msr.ecss1 bond1_ecss1_pa default local true |
To check, run system-status command and see the output:
admin@mycelium1@ecss1$ system-status Checking... ┌─┬───────────────┬────────────────────────┬───────────────┬────────────┬──────┐ │ │ Node │ Release │ Erlang nodes │Mnesia nodes│Uptime│ ├─┼───────────────┼────────────────────────┼───────────────┼────────────┼──────┤ │ │core1@ecss1 │ecss-core-3.14.10.91 │core1@ecss1 │not running │1m 59s│ │ │ds1@ecss1 │ecss-ds-3.14.10.91 │ds1@ecss1 │ds1@ecss1 │4h │ │ │md1@ecss1 │ecss-mediator-3.14.10.91│md1@ecss1 │md1@ecss1 │1m 59s│ │ │mycelium1@ecss1│ecss-mycelium-3.14.10.91│mycelium1@ecss1│not running │4h │ │ │sip1@ecss1 │ecss-pa-sip-3.14.10.91 │sip1@ecss1 │sip1@ecss1 │1m 59s│ └─┴───────────────┴────────────────────────┴───────────────┴────────────┴──────┘ All services are started. Active media resource selected list specific: ┌─────────────┬───────────┬────────────┬───────────┬───────────┐ │ Node │ MSR │ MSR │ Cc-status │ Cc-uptime │ │ │ │ version │ │ │ ├─────────────┼───────────┼────────────┼───────────┼───────────┤ │ core1@ecss1 │ msr.ecss1 │ 3.14.10.42 │ connected │ 00:01:31 │ └─────────────┴───────────┴────────────┴───────────┴───────────┘ |
Configure the SIP adapter according to the technical specification. Define a group of IP addresses (IP-set):
admin@[mycelium1@ecss1]:/$ /cluster/adapter/sip1/sip/network/set ip_set test_set node-ip node = sip1@ecss1 ip = 10.0.3.238
Property "ip_set" successfully changed from:
to
test_set: no ports set
test_set: sip1@ecss1 10.0.3.238
test_set: dscp 0. |
Next, create a domain and assign to it the created group (IP-set) of the SIP adapter settings:
admin@[mycelium1@ecss1]:/$ domain/declare test_domain --add-domain-admin-privileges --add-domain-user-privileges
New domain test_domain is declared
domain/test_domain/sip/network/set ip_set [test_set] Property "ip_set" successfully changed from:
[] to ["test_set"]. |
After creating the domain, configure: