9.1 Call Permissions
Within Swyx, call permissions are defined for users and trunk groups.
For each user, these rights define
*where a call may be made to (e.g. local),
*with what public line access (e.g. private or business) and
*via which trunk group this call may go out.
The call permissions are defined using so-called profiles, which are then assigned to individual users or trunk groups.
Such a profile can be composed of several individual permissions. But each user and each trunk group has only precisely one call permission.
Various simple call permissions are offered in the standard installation (9.1.1 Call permissions in the standard installation.).
If there are specific call authorization requirements that the standard profiles do not meet, the Swyx administrator can define custom call authorizations that are specifically tailored to the installation's requirements.
To define call permissions in detail, see 9.1.2 Create Call Permission.
Call Permissions and Routing
The call permissions are independent of the routing (14 Routing). Routings define how a call leaves the system, i.e. how it can be forwarded depending on the trunk group and the time conditions. Routes are a property of the SwyxServer.
Call permissions are user and/or trunk group characteristics. They define which rights are granted to an incoming call, i.e. if and how a call will be transmitted.
Call permission of a user
A user's calling permissions determine which calling privileges that user has within Swyx. For example, he can have the right to make national calls, but not international ones. If a Swyx user forwards a call (e.g., using a script), the forwarded call inherits the user's permissions.
Example:
There is a Swyx installation with two servers, one in Dortmund and one in Berlin. The two SwyxServers are connected to each other over a SwyxLink.
The called user in London has the right to telephone via ISDN within London (locally), but not nationally:
Entry in the user's call permission:
Allow call +4420*; Trunk group "ISDN London"
The called user in London also has the right to make calls to Liverpool via a SwyxLink trunk "SwyxLink London-Liverpool":
Entry in the user's call permission:
Allow call +44151*; Trunk group "SwyxLinkLondon-Liverpool"
In its call permission, the trunk group "SwyxLink London-Liverpool" allows local calls via ISDN. (This is configured on the Liverpool side!):
Entry in the call permissions of the trunk group "SwyxLink London-Liverpool" on the Liverpool side:
Allow call +44151*; Trunk group "ISDN Liverpool"
If a Swyx user receives a call and call forwarding to the Berlin local network has been set up, a caller dialing from Dortmund will be routed via the SwyxLinktrunk to Berlin and then forwarded to the Berlin local network.
Call permission of a trunk group
A call permission is assigned to each trunk group. All calls that come in via a trunk group inherit the call permission of this trunk group.
Therefore, if an incoming call cannot be assigned to a user within the Swyx system, it must be routed out of the system (e.g., via another trunk group). For this forwarding, it receives the call permission of the trunk group via which it came into this system.
Example 1
There is a Swyx installation with two servers, one in Dortmund and one in Berlin. The two SwyxServers are connected to each other over a SIP trunk.
A call comes in from the public network via the ISDN trunk group to the London number 020 23456-888. Currently, this number is not assigned to any user within Swyx, but there is a call forwarding rule for the number range 0231 23456-88* via a SIP trunk group. In order for this call to be forwarded via this SIP trunk group, the corresponding permission must exist in the ISDN trunk group, which has received the call, i.e. the call that has been received by the trunk group must have the permission to leave the system via the SIP trunk:
Entry in the call permission of the ISDN trunk group:
Allow call +4420 23456-88*; Trunk group "SIP"
 
Example 2
There is a Swyx installation with two SwyxServer, one in Dortmund and one in Berlin. The two SwyxServers are connected to each other over a SwyxLink.
In order that calls to Liverpool can in principle go via this SwyxLink, a routing record must be set up on the server in London to forward all calls to Liverpool via the SwyxLink to Liverpool.
Routing record in London:
Allow call +44 151*; Trunk group "SwyxLink London-Liverpool"; Priority 900
A user has the location London (prefix: 020). In the first place he can make local calls in London via ISDN:
Entry in the user's call permission:
Allow call +44,20*; Trunk group "ISDN London"
He also has the right to make calls to Liverpool via a SwyxLink trunk "SwyxLink London-Liverpool":
Entry in the user's call permission:
Allow call +44151*; Trunk group "SwyxLinkLondon-Liverpool"
In its call permission, the trunk group "SwyxLink London-Liverpool" allows local calls via ISDN into the Liverpool local public network. (This is configured on the Liverpool side!):
Entry in the call permissions of the trunk group "SwyxLink London-Liverpool" on the Liverpool side:
Allow call +44 151*; Trunk group "ISDN Liverpool"
The user in London can thus call Liverpool via the SwyxLink, and there telephone locally via ISDN into the public telephone network.
Example 3:
There is a Swyx installation with two SwyxServer, one in Berlin and one in England. The two SwyxServers are connected to each other over a SwyxLink.
To be able to make calls to England via this SwyxLink, a routing record must be set up on the server in Liverpool to forward all calls to Germany (prefix +49) via the SwyxLink to Germany.
Routing record in Liverpool:
Allow call +49*; Trunk group "SwyxLink DE"; Priority 900
The user has the right at his Liverpool location to telephone internally.
Entry in the user's call permission:
Deny call +*; Trunk group "All"
Allow call *; Trunk group "All"
But he has the right to phone Germany (prefix 49) via SwyxLink:
Entry in the user's call permission:
Allow call +49*; Trunk group "SwyxLink DE"
In Germany the "SwyxLink DE" is configured in such a way that calls coming in via this trunk group have the right to initiate national calls via ISDN into the public network:
Entry in the call permission for SwyxLink DE in Germany:
Allow call +49*; Trunk group "ISDN DE"
The user in Liverpool is now able to call Germany via SwyxLink, and there to make calls into the entire national telephone network; but he cannot call locally in Liverpool.
Such a constellation could e. g. make sense for a support employee, who only makes phone calls to Germany.
For private calls, a further permission can be set up with a public line access for private calls. e. g.
Entry in the user's call permission:
Allow call +44151*; Trunk group "ISDN Liverpool"; Public line access 8 (private)
Call permission for SwyxLink trunk groups
SwyxLink-Trunk groups serve as the connection between two Swyx installations. Every SwyxLink trunk is configured on both sides, on one side locally and on the other side remotely (16 SIP Links).
A call routed through this connection inherits the calling privileges of the side from which it exits this trunk—or, in other words, it receives the calling privileges from the trunk group that routes the call into Swyx.
Example:
There are two Swyx installations in Dortmund and Berlin that are connected via a SwyxLink "Dortmund-Berlin" connection.
The SwyxLink "London-Liverpool" is managed locally in London and remotely in Liverpool.
In London there is a call permission for the relevant trunk group, allowing only internal calls:
Entry in the call permission of SwyxLink "London-Liverpool" in London:
Allow call *; Trunk group "All"
Deny call +*; Trunk group "All"
In Liverpool a profile was set up for the assigned trunk group, allowing calls via ISDN into the local network in Liverpool.
Entry in the call permission of SwyxLink "London-Liverpool" in Liverpool:
Allow call +44151*; Trunk group "ISDN Liverpool"
If a user from London now calls Liverpool via the SwyxLink "London-Liverpool", his call can be forwarded there into the Liverpool local network (call permission on the Liverpool side!).
On the other hand, if a user from Liverpool now calls London via the SwyxLink "London-Liverpool", his call can only be forwarded to an internal employee, and not into the Liverpool local network (call permission on the Liverpool side!).