Authentication Policy Configuration Options; Zone-Level Authentication Policy - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Authentication Policy configuration options

The Authentication Policy behavior varies for H.323 messages, SIP messages received from local domains
and SIP messages from non-local domains. The following tables summarize the policy behavior when
applied at the zone and subzone level, and how it varies depending on the message protocol.

Zone-level Authentication Policy

The VCS's Authentication Policy at the zone level controls how the VCS authenticates incoming messages
from that zone. Note that the Authentication Policy is configurable for the Default Zone but does not apply to
DNS and ENUM zones.
To configure a zone's Authentication policy, go to the
click
View/Edit
or the name of the zone). The policy is set to Do not check credentials by default.
The behavior varies for H.323 and SIP messages as shown in the tables below:
H.323
Authentication
Behavior
policy
Check
Messages are classified as either authenticated or unauthenticated depending on whether any
credentials
credentials in the message can be verified against the authentication database.
If no credentials are supplied, the message is always classified as unauthenticated.
Do not check
Message credentials are not checked and all messages are classified as unauthenticated.
credentials
Treat as
Message credentials are not checked and all messages are classified as authenticated.
authenticated
SIP
The behavior for SIP messages at the zone level depends upon the
(meaning whether the VCS trusts any pre-existing authenticated indicators - known as P-Asserted-Identity
headers - within the received message) and whether the message was received from a local domain (a
domain for which the VCS is authoritative) or a non-local domain.
Authentication
Trust
policy
Check
Off
credentials
Cisco VCS Administrator Guide (X7.1)
In local domain
Messages are challenged for
authentication.
Messages that fail authentication are
rejected.
Messages that pass authentication are
classified as authenticated and a P-
Asserted-Identity header is inserted into the
message.
Edit zone
page
(VCS configuration >
SIP authentication trust mode
Outside local domain
Messages are not challenged for
authentication.
All messages are classified as
unauthenticated.
Any existing P-Asserted-Identity headers
are removed.
Device authentication
Zones, then
setting
Page 99 of 479

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.1

Table of Contents