Setting Up The Vcs Expressway; Setting Up Vcs Security Certificates - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Unified Communications
Note that load balancing is managed by Unified CM when it passes routing information back to the registering
endpoints.

Setting up the VCS Expressway

This section describes the configuration steps required on the VCS Expressway.
Configuring DNS and NTP settings
Check and configure the basic system settings on VCS:
1. Ensure that System host name and Domain name are specified
2. Ensure that public DNS servers are specified
3. Ensure that all VCS systems are synchronized to a reliable NTP service
Authentication method in accordance with your local policy.
If you have a cluster of VCSs you must do this for every peer.
Configuring the VCS Expressway for Unified Communications
To enable mobile and remote access functionality:
1. Go to
Configuration > Unified Communications >
2. Set Unified Communications mode to Mobile and remote access.
3. Click Save.
Ensuring that TURN services are disabled on VCS Expressway
You must ensure that TURN services are disabled on the VCS Expressway used for mobile and remote
access.
1. Go to
Configuration > Traversal >
2. Ensure that TURN services are Off.

Setting up VCS security certificates

This deployment requires secure communications between the VCS Control and the VCS Expressway, and
between the VCS Expressway and endpoints located outside the enterprise. Therefore, you must:
1. Install a suitable server certificate on both the VCS Control and the VCS Expressway. The certificate on
each VCS has different requirements for what needs to be included as subject alternate names as
described in
VCS Control / VCS Expressway server certificate requirements
The certificate must include the Client Authentication extension. (The system will not allow you to
l
upload a server certificate without this extension when mobile and remote access is enabled.)
The VCS includes a built-in mechanism to generate a certificate signing request (CSR) and is the
l
recommended method for generating a CSR. This CSR includes the client authentication request and
can be used to help ensure each VCS certificate includes the correct subject alternate names for
Unified Communications and to establish a secure traversal zone. Ensure that the CA that signs the
request does not strip out the client authentication extension.
Cisco VCS Administrator Guide (X8.1.1)
(System >
DNS).
Configuration.
TURN.
Configuring mobile and remote access on VCS
(System >
DNS).
(System >
Time). Use an
below.
Page 72 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents