Cisco TelePresence Administrator's Manual page 110

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Device authentication
VCS Control
1. Configure SIP domains
It must be configured with all of the domains for which it will receive delegated authentication checks.
2. Configure the relevant authentication mechanisms (local database, Active Directory Service or H.350
directory via LDAP).
3. Enable Delegated credential checking
4. Ensure that the traversal client zone is configured to Accept delegated credential checks.
VCS Expressway
1. Configure SIP domains
It must be configured with all of the domains for which it will delegate authentication checks.
2. For each domain, choose the traversal zone over which the credential checks are to be delegated.
3. If NTLM / Active Directory Service authentication is required, ensure that NTLM protocol challenges
(Configuration > Authentication > Devices > Active Directory
4. Enable Delegated credential checking on the
5. Ensure that the relevant zone and subzone
Note that any H.323 messages that arrive at the zones or subzones that are now configured to Check
credentials will still have those credentials checked via the relevant mechanisms (such as the local
database or H.350 directory) on that local VCS and they will not be delegated.
6. If required as part of your dial plan, configure search rules that forward SIP call signaling messages to the
relevant traversal client zones.
(Note that no specific search rules are required to support the delegation of authentication messages to
the VCS Control.
The credential checking of authentication challenges made by the VCS Expressway should now be
delegated through the traversal zone to the VCS Control.
Testing the credential checking service
To verify whether the VCS to which credential checking has been delegated is able to receive messages and
perform the relevant authentication checks:
1. Go to
Configuration >
2. Select the relevant domains.
3. Click Test credential checking service.
The system displays a
traversal zone and, additionally, if it is able to perform credential checking for both NTLM and SIP digest
type challenges.
If you are not using NTLM authentication in your video network, and thus the receiving VCS is not
configured with a connection to an Active Directory Service, then the NTLM check will be expected to
fail.
TURN services
If
TURN services
are enabled on the VCS Expressway and you also want to delegate the credential
checking of TURN server requests:
1. Go to
Configuration > Traversal >
2. Set Delegated credential checking to On.
Cisco VCS Administrator Guide (X8.1.1)
(Configuration >
Domains).
(Configuration > Protocols >
(Configuration >
Domains).
SIP
authentication policies
Domains.
Results
section and reports whether the receiving VCS can be reached over the
TURN.
SIP).
Service) is set to Auto.
page
(Configuration > Protocols >
are set to Check credentials.
About device authentication
SIP).
Page 110 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents