Setting Up Secure Vcs Traversal Zones - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Unified Communications

Setting up secure VCS traversal zones

To support Unified Communications features such as mobile and remote access, there must be a secure
traversal zone connection between the VCS Control and the VCS Expressway:
The traversal client zone and the traversal server zone must be configured to use SIP TLS with TLS verify
n
mode set to On, and Media encryption mode must be Force encrypted.
Both VCSs must trust each other's server certificate. As each VCS acts both as a client and as a server
n
you must ensure that each VCS's certificate is valid both as a client and as a server.
If a H.323 or a non-encrypted connection is required, a separate pair of traversal zones must be configured.
n
To set up a secure traversal zone, configure your VCS Control and VCS Expressway as follows:
1. Go to
Configuration > Zones >
2. Click New.
3. Configure the fields as follows (leave all other fields with default values):
Name
Type
Username
Password
H.323 Mode
SIP
section
Mode
Port
Transport
Unified
Communications
services
TLS verify mode
TLS verify subject
name
Media encryption
mode
Authentication
section
Cisco VCS Administrator Guide (X8.1.1)
Zones.
VCS Control
"Traversal zone" for example
Traversal client
"exampleauth" for example
"ex4mpl3.c0m" for example
Off
On
7001
TLS
Yes
On
Not applicable
Force encrypted
Configuring mobile and remote access on VCS
VCS Expressway
"Traversal zone" for example
Traversal server
"exampleauth" for example
Click Add/Edit local authentication database,
then in the popup dialog click New and enter
the Name ("exampleauth") and Password
("ex4mpl3.c0m") and click Create credential.
Off
On
7001
TLS
Yes
On
Enter the name to look for in the traversal
client's certificate (must be in either the Subject
Common Name or the Subject Alternative
Name attributes). If there is a cluster of traversal
clients, specify the cluster name here and
ensure that it is included in each client's
certificate.
Force encrypted
Page 74 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents