Summary of Contents for Polycom Collaboration Server (RMX) 1500
Page 1
[Type the document title] Version July 2013 DOC2714A Polycom® RealPresence® Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Polycom Document Title...
Page 2
Every effort has been made to ensure that the information in this manual is accurate. Polycom, Inc., is not responsible for printing or clerical errors. Information in this document is subject to change without notice.
Connecting to the Default Management Network .......... 1-24 Product Activation ....................1-26 Modifying the Signaling Network Service and ISDN/PSTN Network Service Settings ........................... 1-28 Fast Configuration Wizard .................. 1-28 Procedure 4: Enable Ultra Secure Mode ................1-45 Connecting to the RMX ..................1-46 Polycom, Inc...
Page 4
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 5: Enable Secured Communication ..............1-47 Enabling Secure Mode ....................1-48 Purchasing a Certificate ..................1-48 Installing the Certificates .....................1-50 Installing the RMX Certificate ................1-50 Installing the CA Certificate(s) ................1-51 Certificate Revocation ..................1-53 Installing the CRL ....................1-54...
Page 5
Performing a Comprehensive Restore to Factory Defaults ......4-3 Emergency CRL (Certificate Revocation List) Update ..........4-10 Deploying a Polycom RMX™ Serial Gateway S4GW ....5-1 Network Infrastructure ......................5-1...
Page 6
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Single Serial Gateway .....................5-1 Multiple Serial Gateways ....................5-2 Guidelines ........................5-2 Configuring the RMX - Serial Gateway Connection ............5-4 Procedure 1: Initial Setup of the Serial Gateway ............5-4 Procedure 2: Configure a Network Service on the RMX for each of the Serial Gateways and Connect the Serial Gateways to the RMX .........5-8...
Gateway S4GW web site. If the flag value is set to NO (default) an external Internet Explorer browser is launched to display the RMX Serial Gateway S4GW web site. For more information see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments "ActiveX Bypass” on page 17-89.
Certificate Revocation List (CRL) distribution point for each Certificate Authority (CA) used in the configuration All systems that are part of the secure solution, whether IT infrastructure or Polycom devices, must be configured with the capability to resolve all other Polycom and other IT infrastructure device Host Names on the network.
Chapter 1-First Time Installation and Configuration information see Polycom® RMX® 1500/2000/4000 Administrator’s Guide for Maximum Security Environments "Certificate Configuration and Management” on page E-1. RMX Hardware Version N.0 requires that MPM+ cards are installed in the RMX. Installation and Configuration...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 1: Hardware Installation and Setup In a well ventilated area, mount the RMX 1500/RMX 2000/RMX4000 unit in a 19” rack. It is important to adhere to the Site Requirements as described in the RMX 2000/4000 Hardware Guides, "Site Requirements”...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-1 Rail Runners Kit Contents Item Item Part/Kit no. Item Item Sample Quantity RMX chassis Pan head screw - assembly kit M5*12mm Flat washer M5 Telescopic Rail Runner Assembly...
Page 13
Adjust the telescopic rack rail runner to the rack opening and mount it onto the marked position of the rear post as described in step 2. Figure 1-3 Detail of Rear RealPresence Collaboration Server (RMX) 1500/2000/4000 Rack Spacer Assembly Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Repeat steps 2 and 3 for the right rack rail runner. Install the flat head screw (item 5), flat washer (item 6) and nut spring (item 7) in the middle of the telescopic rack rail runner for added stability as shown in Figure 1-4.
Using the rack rail runners on the RMX 1500 — Install the telescopic rail runners, as described in "Installing the Telescopic Rail Runners on the Rack” on page 1-5. — Mount the Collaboration Server 1500 on top of the rail runners. Polycom, Inc.
Page 16
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments — Fasten the Collaboration Server to the rack spacers using the flat head screw (item 8) with flat washer (item 9) through the two holes in the Collaboration Server’s front mounting brackets.
The LAN 1*, LAN3, LAN4 and Modem ports are not be used and the plastic caps covering those ports should not be removed. * With Multiple network and LAN redundancy configurations, LAN 1 port is used. For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrators Guide, Multiple Services and LAN Redundancy. 1-11...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Installing the RMX 2000 For detailed instructions, precautions and requirements for installing the RMX 2000 refer to the Polycom RMX 2000 Hardware Guide. The following procedures have to be performed to install the RMX 2000 in your site: •...
Management; the other for Signaling & Media. Separation can be achieved either by two physical networks or by two virtual networks (VLANs). These separated networks will be used after Network Separation is performed. See "Procedure 7: Enable Network Separation (RMX 2000)” on page 1-59. 1-13 Polycom, Inc.
Page 20
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments • Power cable • On the RTM IP card connect the LAN cable to LAN 2 Port. • On the RTM LAN card connect the LAN cable to LAN 2.
Tighten the captive screws on each side of the rear panel of the card, securing the RTM ISDN card to the MCU. A Software License is included with the ISDN card. This license must be registered as part of the Product Registration and Product Activation process. 1-15 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Mounting the Collaboration Server 4000 in a Rack Either place the RMX 4000 on a hard, flat surface such as a desktop or mount it on a 19” rack.
RealPresence Collaboration Server (RMX) 4000 Hardware Guide. Ensure that the cables from the Main that supplies electricity to the DC power units are OFF or disconnected. Remove the transparent plastic caps on the terminal block. 1-17 Polycom, Inc.
Page 24
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Using the two wires of a 10 AWG cable running from the DC power distribution unit, connect the black wire into the -48VDC terminal block and the red wire to the RTN terminal block.
— Connect the LAN cable to LAN 1. LAN Connections to RTM LAN E1/T1 Connection to RTM ISDN Signaling Network Management Network Shelf Management Off/On switch Power Cables Figure 1-5 RMX 4000 Rear Panel View with AC Power and Communication Cables 1-19 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 2: Gather Network Equipment and Address Information IP Services The IP addresses and network parameters which enable communication between the Hardware Collaboration Server, its management application and the conferencing devices are...
Equipment Product Registration. Address Info Modifying the Factory Default Management Network Settings. First-time Power-up and Connection to MCU. First Entry Enable Network Separation (RMX 2000) Configuration Modifying the Default IP and ISDN/PSTN Service settings (Fast Configuration Wizard). 1-21 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Product Registration Before the Collaboration Server can be used, it is necessary to register the product and obtain an Activation Key. During first-time power-up, the Product Activation dialog box is displayed, requesting you to enter an Activation Key.
Page 29
In the Local Area Connection Status dialog box, click the Properties button. In the Local Area Connection Properties dialog box, select Internet Protocol [TCP/IP] > Properties. In the Internet Protocol (TCP/IP) Properties dialog box, select Use the following IP address. 1-23 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Enter the IP address, Subnet mask and Default gateway for the workstation. The workstation’s IP address should be in the same network neighborhood as the RMX’s Control Unit IP address.
Page 31
Management IP address in the browser’s address line and pressing Enter. 11 In the Collaboration Server Web Client Login screen, enter the default Username (POLYCOM) and Password (POLYCOM) and click the Login button. The Fast Configuration Wizard starts. Both IPv4 and IPv6 are supported. For IPv6 addressing information see the RMX 1500/2000/4000 System Administrator’s Guide for Maximum Security Environments "IP Network Services”...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments If this is the First Time Power-up or the Default IP Service has been deleted and the RMX has been reset, the following dialog box is displayed: 12 Enter the following parameters using the information supplied by your network administrator: —...
Page 33
18 In the Activation Key field, enter or paste the Product Activation Key obtained earlier. 19 Click OK. If you do not have an Activation Key, click Polycom Resource Center to access the Service & Support page of the Polycom website.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Modifying the Signaling Network Service and ISDN/PSTN Network Service Settings The Fast Configuration Wizard assists in configuring the Signaling Network Service. It starts automatically if no Signaling Network Service is defined. This happens during First Time Power-up, before the service has been defined or if the Signaling Service has been deleted, followed by an RMX restart.
Page 35
Enter the IP address of the default router. The default router is used IP Address whenever the defined static routers are not able to route packets to their destination. The default router is also used when host access is restricted to one default router. 1-29 Polycom, Inc.
Page 36
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click the Next button. Enter the required DNS information in the dialog box. Table 1-6 Signaling Network Service – DNS Field Description MCU Host Name DNS Enter the name of the MCU on the network.
Page 37
Enter the required Network Type information in the dialog box. Table 1-7 Signaling Network Service – IP Field Description IP Network Type Select a Network Type: • H.323 • • H.323&SIP Click the Next button. If you selected SIP only, go to Step 13. 1-31 Polycom, Inc.
Page 38
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 10 Enter the required Gatekeeper information in the dialog box. Table 1-8 Signaling Network Service – Gatekeeper Parameters Field Description Gatekeeper Select Specify to enable configuration of the gatekeeper IP address.
Page 39
12 If you selected H.323, click Save & Continue; otherwise click Next and go to Step 13. If you have selected Save and Continue, the IP Network Service is created and confirmed. — Go to Step 17. 13 Enter the required SIP Server information in the dialog box. 1-33 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-9 Fast Configuration Wizard – SIP Server Field Description SIP Server Select: • Specify – to manually configure SIP servers. • Off – if SIP servers are not present in the network.
Page 41
Password Enter the password the Collaboration Server will use to authenticate itself with the gatekeeper. This password must be defined in the gatekeeper. 16 Click Save & Continue. The IP Network Service is created and confirmed. 1-35 Polycom, Inc.
Page 42
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 17 Click OK. During the initial Collaboration Server setup, if the system detects the presence of the RTM ISDN card, the ISDN /PSTN Network Service definition screens of the Fast Configuration Wizard are enabled.
Page 43
Num Type is used to route the call to a specific PRI line. If you want the network to interpret the dialing digits for routing the call, select Unknown. Default: Unknown Note: For E1 spans, this parameter is set by the system. 1-37 Polycom, Inc.
Page 44
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-12 Fast Configuration Wizard – PRI Settings (Continued) Field Description Num Plan Select the type of signaling (Number Plan) from the list according to information given by the service provider.
Page 45
Note: For T1 configurations in Taiwan, Framing must be set to ESF and Line Coding to B8ZS. 23 Click Next. The Phones dialog box is displayed. 24 Click Add to define dial-in number ranges. The Add Phone Number dialog box is displayed. 1-39 Polycom, Inc.
Page 46
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 25 Define the following parameters: Table 1-14 Fast Configuration Wizard – Add Phone Numbers Field Description First Number The first number in the phone number range. Last Number The last number in the phone number range.
Page 47
PSTN Network Services > ISDN Properties > Spans tab in the RMX Web Client. Each ISDN RTM card can support either 7 E1 or 9 T1 PRI lines (E1 and T1 connections cannot be used simultaneously). 32 Click Next. 1-41 Polycom, Inc.
Page 48
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments The RMX Time dialog box is displayed. 33 Set the RMX Time using one of the three available options: setting the RMX Time manually, clicking the Retrieve Client Time button, or using the NTP Servers options.
Page 49
The Administrator User Name and Password are configured in Procedure 10, after Secured Communication has been enabled. • If the default POLYCOM user is defined in the RMX Web Client, an active alarm is displayed and the MCU status changes to Major until the administrator changes the default username and password.
Page 50
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-16 Signaling Network Service – System Flags Flag Description / Default Conference ID The number of digits of the Conference Length (MCU) ID to be assigned by the MCU.
42 When the Login screen is displayed, enter your Username and Password and click Login. On first entry, the default Username and Password are both POLYCOM. The system is now fully configured and if there are no System Errors, the green RDY LED on the CNTL module on the RMX’s front panel turns ON.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Refresh the browser periodically until the RMX Web Client – Terms of Usage screen is displayed. Connecting to the RMX If the error “Browser environment error. Please close all the browser sessions” appears, close all the browser sessions, and reconnect to the MCU.
RMX versions. An Active Alarm is created and a message is displayed requesting that a new TLS certificate be installed. • TLS private keys saved by the current version will be compatible with TLS private keys saved by future RMX versions. 1-47 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Enabling Secure Mode The following operations are required to switch the RMX to Secure Mode: • Purchase and install the necessary SSL/TLS certificates: — Certificate — CA Certificate(s) — CRL Certificates are managed using the Certification Repository dialog box accessed through the RMX Web Client / RMX Manager, Setup menu.
Page 55
Enter the full name of the unit (group or division) for which the certificate will be issued. Common Name (DNS/ Enter the DNS MCU Host Name. This MCU Host Name must also be configured in the Management Network Properties dialog box. 1-49 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-17 Create Certificate Request (Continued) Field Description Hash Method Select SHA-256 (in compliance with UC APL, FIPS 140-2). Click Send Details. The RMX creates a New Certificate Request and returns it to the Create Certificate Request dialog box along with the information the user submitted.
Send Certificate File Use this option if the ce rif ic ate has been received from the Certification Authority in file format. Option. Paste Certificate and Send Certificate After you have received the certificate from the Certificate Authority: 1-51 Polycom, Inc.
Page 58
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Copy (Ctrl + C) the certificate information from the Certificate Authority’s e-mail to the clipboard. Click Paste Certificate to paste the clipboard content into the Send Certificate dialog box.
Network, the OCSP_RESPONDER_TIMEOUT System Flag can be manually added to system.cfg and its value set to the number of seconds the RMX is to wait for an OCSP response from the OCSP Responder before failing the connection. Default: 3 (seconds) Range: 1-20 (seconds) 1-53 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Installing the CRL If CRL is the chosen method: CRL - Requires at least one CRL file be installed, failing which an error message, At least one CRL should be installed, is displayed.
The Management Network Properties dialog box is displayed. Select the Secured RMX Communication check box. Click OK. In the Reset Confirmation dialog box, click Yes. In the Please wait for system reset message box, click OK. System restart may take up to five minutes. 1-55 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Refresh the browser periodically until the RMX Web Client – Terms of Usage screen is displayed Procedure 6: Set System Configuration Flags Maximum Security Environments have additional System Flags that control: •...
Page 63
Determines the minimum length of a conference IN_LEN password. Default: 9 Range: 9-16 OCSP_RESPONDER_TIME The number of seconds the RMX is to wait for an OCSP response from the OCSP Responder before failing the connection. Default: 3 (seconds) Range: 1-20 (seconds) 1-57 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-18 System Flags and their default values Recommended Flag Description Value PASSWORD_EXPIRATION Determines the number of days that passwords _DAYS remain valid. Default: 60 Range: 7-90 PASSWORD_EXPIRATION Determines how many days before password...
Before plugging network cables in, ensure sure that the network infrastructure containing all the devices (including the RMX) has two different networks: one for Management; the other for Signaling & Media. Separation can be achieved either by two physical networks or by two virtual networks (VLANs). 1-59 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Enabling Network Separation LAN 2 Port - Signaling LAN 3 Port - Management IP Endpoints RMX Web Client / RMX Manager Management Sessions Figure 2 Signaling and Management Network Separation To enable network separation: On the RMX menu, click Setup >...
802.1x Authentication For each NIC, click the arrow to open the drop-down menu and select the 802.1x Authentication method: • EAP-TLS • PEAPv0 Note: EAP-MD5 and MSCHAPv2 are also available as options. Selecting Off disables 802.1x Authentication. 1-61 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 1-19 802.1x Authentication - Configuration Field Description User Enter the User name that the RMX will use to register with the 802.1x Authentication Server. This must be the RMX’s DNS name and can be up to 256 characters.
Page 69
Select the Enable Password messages. Set Dial-in to Request Password Set Dial-Out to Request Password Click the Roll Call tab. The Conference IVR Service Properties - Roll Call dialog box is displayed. Select Enable Roll Call. Click the OK button. 1-63 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 10: Optional. Modify Default Login and Main Screen Banner Text The Login and Main Screens of the RMX Web Client and the RMX Manager display warning text banners cautioning users to the terms and conditions under which they may log into and access the system.
The user must click the Accept button before the Login screen is displayed. Main Screen Banner The Main Screen banner is displayed at the bottom of the screen. It is intially blank and can be customized Banner 1-65 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Customizing Login and Main Screen Banners The Login and Main Screen banners can be customized when the RMX is in either Ultra Secure Mode or non-Ultra Secure Mode. To customize the banners: In the RMX menu, click Setup >...
Chapter 1-First Time Installation and Configuration Procedure 11: Rename the Default POLYCOM User To rename the default POLYCOM user: In the RMX Management pane, click the Users ( ) button. The Users pane is displayed. Select the POLYCOM user. Select Rename User in the menu.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click the OK button. Procedure 13: Configure White List Access For security reasons it is important that a list of devices permitted to connect to the RMX is configured. The White List contains the addresses of all IP devices permitted to connect to the RMX.
Page 75
— IPv4 addresses can be added as a range by substituting the 3rd and 4th dotted decimal numbers of the IP address with * characters, e.g. 11.10.*.* Add IP addresses to the White List: 1-69 Polycom, Inc.
Page 76
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments For each IP address to be added to the White List: In the Add IP Address field enter an IP address to be added to the White List and click the Add button to add the IP address to the White List.
Control Unit IP Address> and press the Enter key. https://< The RMX Web Client – Terms of Usage screen is displayed. Terms of Usage Banner Accept Button Click the Accept button to agree to the terms and conditions displayed in the banner. Polycom, Inc.
Page 78
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments The Login - Welcome screen is displayed: Enter your User Name. Enter your Password. Click Login. The RMX Web Client - Main Screen is displayed. The system can display a record of the last Login of the user. It is displayed in the Main Screen of the RMX Web Client or RMX Manager.
For more information, see the RMX 2000 Administrator’s Guide, "Users, Connections and Notes” on page 10-1. Conferences List List Address Book Management Conference Templates Status Bar Banner The main screen can be customized. For more information, see "Customizing the Main Screen” on page 2-10. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Viewing and System Functionality Permissions Viewing and System Functionality permissions for Administrators and Operators are summarized in Table 2-1: Table 2-1 Viewing and System Permissions Authorization Level Operator Administrator Viewing Permissions ...
Rarely Used – parameters configured during initial system set-up and rarely modified afterward. Status Bar The Status Bar at the bottom of the RMX Web Client contains System and Participant Alerts tabs as well as Port Usage Gauges and an MCU State indicator. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments System Alerts This is a list of system problems. The alert indicator flashes red when at least one system alert is active. The flashing continues until a user with Operator or Administrator permission reviews the list.
80% and it can be modified by the system administrator. For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "Setting the Port Usage Threshold” on page 14-60. MCU State The MCU State indicator displays one of the following: •...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments New Group Delete Participant Delete Group New Participant Import Address Book Export Address Book Click to hide Address Audio Participant Book Video Participant Quick Group Search Address Book entries are listed according to: •...
Hide the Conference Templates list pane by clicking the anchor pin ( ) button in the top right corner of the pane. The Conference Templates list pane closes and a tab appears in the top right corner of the screen. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Customizing the Main Screen You can customize the main screen according to your preferences. Pane sizes can be changed, column widths can be adjusted and data lists can be sorted.
In the RMX Management pane click and drag the icon of the item that you wish to move. An indicator line ( ) appears indicating the new position of the icon. Release the mouse button when the icon is in the desired position. The new position of the Networks icon List View 2-11 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Starting a Conference There are several ways to start a conference: • Clicking the New Conference button in the Conferences pane. For more information, see "Starting a Conference from the Conferences Pane” on page 2-12.
Page 89
You can use the New Conference - General dialog box to modify the conference parameters. If no defined participants are to be added to the conference, or you do not want to add additional information, click OK. 2-13 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments General Tab Define the following parameters: Table 2-2 New Conference – General Options Field Description Display Name The Display Name is the conferencing entity name in native language character sets to be displayed in the RMX Web Client.
Page 91
The Conference Profile includes the Conference line rate, media settings and general settings. For a detailed description of Conference Profiles, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "Conference Profiles” on page 1-1. Enter the unique-per-MCU conference ID. If left blank, the MCU automatically assigns a number once the conference is launched.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Participants Tab This procedure is optional. The Participants tab is used to add participants to the conference from the Address Book. It is also used to add defined dial-out participants to the conference. Defined dial-out participants are connected to the conference automatically when the conference is launched Click the Participants tab.
Page 93
• For dial-out connection, displays the IP address or phone number of the endpoint called by the Polycom® RMX™ 1800. • For dial-in connection, displays the participant’s IP address or phone number used to identify and route the participant to the appropriate conference.
Page 94
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments — Adding pre-defined participants from the Address Book by either selecting the participants from the list or dragging and dropping the participants from the Address Book to the Participants list.
If no participants were defined for the conference or as long as no participants are connected, the indication Empty and a warning icon ( ) appear in the Status column in the Conferences pane. The status changes when participants connect to the conference. 2-19 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments If no participant connects within the time specified in the Conference Profiles > Auto Terminate > Before First Joins field, the conference is automatically terminated by the system. Starting a Reservation...
To start an ongoing conference from a Template: In the Conference Templates list, select the Template you want to start as an ongoing conference. Click the Start Conference from Template button. Right-click and select Start Conference from Template. 2-21 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments The conference is started. If a Conference Template is assigned a dial-in number that is already assigned to an ongoing conference, Meeting Room, Entry Queue or Gateway Profile, when the template is used to start an ongoing conference or schedule a reservation it will not start.
If there is no gatekeeper defined for the network, H.323 participants dial the MCU’s signaling host IP address and the conference ID, separated by Example: MCU (Signaling Host) IP address 172.22.30.40 Conference ID 1001 >> The participant dials 172.22.30.40##1001 2-23 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Entry Queue Access Access via an Entry Queue allows all participants to dial the same entry point that acts as a routing lobby. Once in the Entry Queue, participants are guided to the conference according to the conference ID they enter.
2 x 2 video layout Saturn Room Tarney Adam Orion Room The displayed name is determined as follows: • The system displays the name that is defined at the endpoint. • If the endpoint does not send its name: 2-25 Polycom, Inc.
Page 102
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments — For a defined H.323 participant: • The system displays the name from the participant definition. — For an undefined H.323 participant: • Display the H.323 ID alias. Display the E.164 alias.
Text Indication can be disabled by adding a new flag to the System Configuration and setting its value to NO as follows: ENABLE_TEXTUAL_CONFERENCE_STATUS=NO. This setting is recommended for MCUs running Telepresence conferences. For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "System Configuration” on page...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Monitoring Ongoing Conferences Conference monitoring enables you to keep track of conferences and their participants: if all its participants are correctly connected and whether errors or faults have occurred.
Displays conference name and type of conference: • – Video Conference (including HD CP conferences). • – High Definition Video Conference running in Video Switching mode. • – The conference has been secured using the *71 DTMF code. 2-29 Polycom, Inc.
Page 106
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 2-5 Conferences – Monitoring Information (Continued) Field Description Status Displays the status of the ongoing conference. If there is no problem with the participant’s connection no indication is displayed.
Table 2-6 Participant Monitoring – Indicators and Properties Column Icon/Description Name Displays the name and type (icon) of the participant: Audio Participant – Connected via IP phone or ISDN/PSTN. Video Participant – Connected with audio and video channels. 2-31 Polycom, Inc.
Page 108
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 2-6 Participant Monitoring – Indicators and Properties (Continued) Column Icon/Description Status Displays the connection status (text and icon) of the participant. If there is no problem with the participant’s connection no indication is displayed.
For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "H.239” on page 2-12. For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "Participant Level Monitoring” on page 8-10.
Page 110
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments A conference’s Duration can be extended or shortened while it is running, by modifying its scheduled End Time. To extend or shorten a conference manually: In the Conference List pane, double-click the conference Name.
Saving an Ongoing Conference as a Template Any conference that is ongoing can be saved as a template. To save an ongoing conference as a template: In the Conferences List, select the conference you want to save as a Template. 2-35 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click the Save Conference button. Right-click and select Save Conference to Template. The conference is saved to a template whose name is taken from the ongoing conference Display Name.
Windows that are not assigned any participant display the current speaker and last speakers. To video force a participant to a window: In the Conference Properties dialog box, select the Video Settings tab. If Auto Layout check box is selected, clear it. 2-37 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Select the required video layout. In the window to which you want to force a participant, select the participant’s name from the list of conference participants. List of Conference...
Open the Address Book to select the participant for the conference. Participant For more information about the Address Book, see the RealPresence From Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Address Maximum Security Environments, "Address Book” on page 5-1. Book Connect Connect a disconnected defined dial-out participant to the conference.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 2-7 Participant Level Operations (Continued) Menu Button Description Option Abort To withdraw the Content Token from the participant back to the MCU for H.239 re-assignment. Session Change to Define the selected participant as the conference leader/chairperson.
Page 117
To cancel the Personal Video Forcing for a window without returning to the conference layout: In the Participant Properties – Media Sources dialog box, in the video layout window, select Auto in the Participants list. Click OK. Switching between participants is renewed and is audio activated. 2-41 Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Personal Layout Selection with Click&View Personal With the Click&View application, participants can change their Layouts via DTMF codes entered from their endpoints. This option is available only if the Click&View option is selected in the Conference IVR Service.
Permissions for DTMF actions to be performed by all conference participants or by chairperson only are configured in the Conference IVR Service assigned to the conference. For more information, see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "Defining a New Conference IVR Service”...
Page 120
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 2-9 Conference IVR Service Properties - DTMF Codes Operation DTMF String Permission Mute My Line Everyone Unmute My Line Everyone Increase Broadcast Volume Everyone Decrease Broadcast Volume Everyone...
Step 2: Reset the RMX. For a detailed description of this step see "Reset the RMX” on page 3-7. Step 3: Install the RMX Manager. For a detailed description of this step see "Install the RMX Manager:” on page 3-7. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 2 Use this procedure if the RMX Web Client cannot connect to the RMX after using Procedure 1. Step 1: Set the RMX to Non Secure Communication Mode - See "Set the RMX to Non Secure Communication Mode”...
Certificates can be created and issued using an Internal Certificate Authority. For more information see “Using an Internal Certificate Authority” on page 9. To create or purchase a certificate: In the RMX menu, click Setup > RMX Secured Communications > Certificate Repository. The Certificate Repository dialog box is displayed. Polycom, Inc.
Page 124
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click the Personal Certificates tab. Click Add. The Create Personal Certificate dialog box is displayed: Click Create Certificate Request. The Create Certificate Request details dialog box is displayed: Enter information in all the following fields:...
Page 125
The RMX creates a New Certificate Request and returns it to the Create Certificate Request dialog box along with the information the user submitted. Click Copy Request to copy the New Certificate Request to the workstation’s clipboard. Click Close. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 10 Connect to your preferred Certificate Authority’s website using the web browser. 11 Follow the purchasing instructions at the Certificate Authority’s website. Paste (Ctrl + V) the New Certificate Request as required by the Certificate Authority.
Click the Reset ( ) button. Install the RMX Manager: In the Login screen, click the link to the RMX Manager Installer at the top of the right edge of the screen. Click the Install RMX Manager link. Polycom, Inc.
Page 128
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments The installer verifies the application’s requirements on the workstation. The Install dialog box is displayed. Click Install. The installation proceeds. When the installation completes, the application loads and the RMX Manager – Welcome screen is displayed.
To add the Internal Certificate Authority as a trusted Certificate Authority: Navigate to the folder where the certificate (.cer) file is saved. Open the certificate file. Click the Detail tab. Click the Copy to File button. The Certificate Export Wizard is displayed. Polycom, Inc.
Page 130
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click the Next button. The Export File Format dialog box is displayed. Select Base-64 encoded X.509 (.CER). Click the Next button. The File to Export dialog box is displayed.
Page 131
Chapter 3-Installing RMX Manager for Secure Communication Mode Click the Next button. 10 The final Certificate Export Wizard dialog box is displayed. 11 Click the Finish button. The successful export message is displayed. 12 Click the OK button. 3-11 Polycom, Inc.
Page 132
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 3-12 Polycom, Inc.
When performing operations using a USB device, the following USB ports are used: • RMX 1500 - left most USB port on the front panel. • RMX 2000 - at the bottom right corner of the RTM IP card on the back panel. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments • RMX 4000 - at the bottom right corner of the RTM IP 4000 card on the back panel. Operations Performed Using a USB Device The USB port of an RMX in Ultra Secure Mode can be used to: •...
Step 1: Backup Configuration Files. These files will be used to restore the system in Step 10. Step 2: Configure a workstation for Direct Connection. Step 3: Connect to the RMX and the workstation using a LAN cable. Polycom, Inc.
Page 136
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Step 4: Into the RMX’s USB port, insert a USB key containing a file named RestoreToFactoryDefault.txt and also containing a lan.cfg file. Do not insert a USB key containing a file named RestoreToFactoryDefault.txt if the USB key does not also contain a lan.cfg file.
Page 137
On the Windows Start menu, select Settings > Network Connections. In the Network Connections window, double-click the Local Area Connection that has Connected status. Local Area Connected Status Connection In the Local Area Connection Status dialog box, click the Properties button. Polycom, Inc.
Page 138
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments In the Local Area Connection Properties dialog box, select Internet Protocol [TCP/IP] > Properties. In the Internet Protocol (TCP/IP) Properties dialog box, select Use the following IP address. Enter the IP address, Subnet mask and Default gateway for the workstation.
Page 139
Reserved IP Addresses Network Entity Alternate Network IP Address Control Unit Subnet Mask 255.255.240.0 Default Router IP Address 169.254.192.1 Shelf Management IP Address 169.254.192.16 Shelf Management Subnet Mask 255.255.240.0 Shelf Management Default Gateway 169.254.192.1 Click the OK button. Polycom, Inc.
Page 140
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Step 3: Connect the RMX to the Workstation The Alternate Management Network enables direct access to the RMX for support purposes. The Alternate Management Network cannot be configured and operates according to factory defaults.
Page 141
In the Activation Key field, enter or paste the Product Activation Key obtained earlier. Click OK. If you do not have an Activation Key, click Polycom Resource Center to access the Service & Support page of the Polycom website. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments The system prompts with a restart dialog box: Step 11: Unplug the USB device. Remove the USB device from the USB port of the RMX. >> Step 12: Restart the RMX.
Page 143
Enter an administrator Username and Password. Click OK. Step 3: Open the Certification Repository. On the RMX menu, click Setup > RMX Secured Communication > Certification >> Repository. Step 4: Update the CRL files. In the Certification Repository: Click the CRL tab. 4-11 Polycom, Inc.
Page 144
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Click Add. In the Install File dialog box, select the DER or PEM format depending on which file format was chosen in Step 1 of this procedure. Click the Browse button to navigate to the folder on the workstation where you saved the CRL files in Step 1 of this procedure.
Page 145
The Management Network Properties dialog box is displayed. Select the Secured Communication check box. Click OK. A message informs you that your session will be disconnected and that you must re-connect the RMX using https in the browser URL. Click OK. 4-13 Polycom, Inc.
Page 146
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments A system restart confirmation message is displayed. Click Yes to restart the RMX. The RMX restarts. System restart can take 5 - 10 minutes, depending on the RMX’s configuration.
Deploying a Polycom RMX™ Serial Gateway S4GW UC-APL Public Key Infrastructure (PKI) requires that the Serial Gateway S4GW be connected directly to the RMX and not to the H.323 network. The Serial Gateway effectively becomes an additional module of the RMX, with all web and H.323 traffic passing through the RMX.
After initial setup, the Serial Gateway is configured, managed and monitored via the RMX Web Client / RMX Manger. For more information see “Setting Up Your Polycom RMX Serial Gateway S4GW” in the RMX Serial Gateway S4GW System User Guide.
Page 149
Serial Gateways, each Serial Gateway can be associated with only one Network Service. This requires the configuration of Multiple Network Services on the RMX. For more information see the RealPresence Collaboration Server (RMX) 1500/2000/4000 Administrator’s Guide for Maximum Security Environments, "Multiple Networks” on page 12-37.
Initial Setup of the Serial Gateway Initial Setup must be completed for each of the Serial Gateways to be deployed. For more information see “Setting Up Your Polycom RMX Serial Gateway S4GW” in the RMX Serial Gateway S4GW System User Guide.
Page 151
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW In the Device > Addressing > IP Address Dialog Box: — In the Router IP field, enter the Default Router IP Address. — In the Subnet Mask field, enter the Subnet Mask address.
Page 152
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments In the Port settings field, select Auto LAN. (If configured as 100 Mbps/Full Duplex while dirctly connected to the RMX, the Serial Gateway network adapter is disabled and until the cable is disconnected and reconnect to the RMX.) Click the Advanced Configurations button and verify that: —...
Page 153
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW Un-check Enable H.263+. Un-check Enable T.120. 12 Click the Security tab. Select Independent. 13 Click the Advanced tab. Verify the following settings: • IP to Serial calls: - Translate DTMF from IP...
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments 16 In the HTTPS section of the Administrator > Device > Web dialog box: Use the buttons to install a TLS Certificate. Select the Support Secure Communications (HTTPS) check box.
Page 155
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW The New IP Service dialog box is displayed. In the IP tab: Enter an IP Network Service Name. Enter a Signaling Host IP Address that is on the same VLAN as the Serial Gateway Management address.
Page 156
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments of the Serial Gateway” on page 5-4.) 10 Click the V35 Gateway tab. The network service Properties dialog box is displayed. The Enable field is selected and cannot be un-checked.
Page 157
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW 11 Modify the following fields: Table 5-1 Network Service - V35 tab Field Description V35 Gateway IP Enter the Management IP address of the management interface of Address the Serial Gateway. Username Enter the User Name that the RMX uses to log in to the management interface of the Serial Gateway.
RMX Web Client / RMX Manager. Clicking the Launch V35 GateWay Site button in the Network Properties -V35 Gateway dialog box opens the Serial Gateway’s Administrator console. For more information see “Setting Up Your Polycom RMX Serial Gateway S4GW” in the RMX Serial Gateway S4GW System User Guide. —...
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW Testing Dialing to the RMX from an ISDN Endpoint To dial to the RMX from an ISDN endpoint: Dial String: <ISDN Number of AdTran>##<Conference _Room_Number> Example: 5556789##4000 • The password can be included in the dial string by adding #<password> at the end of the dial string.
Page 160
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments If HTTPS is enabled, a Security Alert screen is displays. Click Yes to proceed and display the Administrator login screen. Click No to cancel the current operation. Type a user name and password.
Page 161
Click Device >> Web Tab> Manage Certificate. Select the Manage Certificate button and follow the prompts to request the certificate. For more information see the RealPresence Collaboration Server (RMX) 1500/2000/ 4000 Administrator’s Guide for Maximum Security Environments, "Certificate Configuration and Management” on page E-1.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Advanced Commands Table 5-3 Advanced Commands Command Parameters Description Default Advanced ENABLE This command puts the Gateway in The default of the Security MAXIMUM security mode. Used by: CS...
Page 163
Chapter 5-Deploying a Polycom RMX™ Serial Gateway S4GW Table 5-3 Advanced Commands (Continued) Command Parameters Description Default NumberOf Sets the number of repeated characters Repeat allowed in valid password. Chars Allowed Available Since V5.7.2 Sets the minimum number of characters...
Page 164
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Table 5-3 Advanced Commands (Continued) Command Parameters Description Default User 2-10 Sets the number of login failures needed to Lockout lockout user. Failed login threshold. MaxFailure Available Since V5.7.2 5-18 Polycom, Inc.
Procedure 2: Deleting the Temporary Internet Files, Collaboration Server Cookie and Collaboration Server Object • Procedure 3: Managing Add-ons Collisions • Procedure 4: Add the Collaboration Server to the Internet Explorer Trusted Sites List • Procedure 5: Browser Hosting Controls (Optional) Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 1: Ending all Internet Explorer Sessions In some cases, although all the Internet Explorer sessions were closed, the system did not end one or several IE processes. These processes must be ended manually.
Deleting the Temporary Internet Files To delete the Temporary files: In the Internet Explorer, click Tools > Internet Options. The Internet Options dialog box opens. In the Browsing history pane, click the Delete button. The Delete Browsing History dialog box opens. Polycom, Inc.
Page 168
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments It is recommended to delete only the Temporary Internet files. By default, the Cookies option is also selected. Clear it if you do not want to clear the cookies from your computer.
In the Internet Options dialog box - Browsing History pane, click the Settings button. The Temporary Internet Files and History Settings dialog box opens. Click the View files button. The Windows Explorer screen opens, listing Windows Temporary Internet Files. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Browse to the RMX/ RMX cookie. The cookie is listed in the format: cookie:user name@RMX/RMX IP address. For example: cookie:valerie@172.22.189.110. Right-click the RMX cookie and click Delete. The system prompts for confirmation.
In some cases, previously installed add-ons, such as anti virus programs can create collisions between applications and prevent the installation of a new add on. Disabling these add-ons may be required in order to install the RMX Web Client. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments To disable an add-on: In the Internet Explorer, click Tools > Manage Add-ons. The Manage Add-ons - Toolbars and Extensions dialog box opens. Scroll to the add-on to disable (for example, the anti virus add-on), right-click it and then click Disable.
Page 173
In the Add this website to the zone: field, enter, “https://” followed by the IP address or the DNS name of the Collaboration Server. Click the Add button. Clear the Require server verification (https:) for all sites in this zone checkbox. Click the Close button. Polycom, Inc.
RealPresence Collaboration Server (RMX) 1500/2000/4000 Deployment Guide for Maximum Security Environments Procedure 5: Browser Hosting Controls (Optional) If the Collaboration Server Web Client does not load and run after Procedures 1-4 have been performed, the reason may be that .NET Framework 4 or higher is running on the workstation with Managed Browser Hosting Controls disabled.
Need help?
Do you have a question about the Collaboration Server (RMX) 1500 and is the answer not in the manual?
Questions and answers