Active Directory Service (Ads) Configuration - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

The PC on which Movi / Jabber Video runs must use appropriate settings which match the settings of the AD
server.
More information about how to configure your system to use NTLM and Active Directory Service is contained
in
Device authentication on VCS deployment

Active Directory Service (ADS) configuration

The
Active Directory Service
Service) is used to configure a connection to an
Jabber Video endpoints (version 4.2 or later).
The configurable options are:
Field
Description
Connect to
Enables or disables the connection
Active
between the VCS and the Active Directory
Directory
Service.
Service
NTLM
Controls whether or not the VCS sends
protocol
NTLM protocol challenges (in addition to
challenges
Digest challenges) when authenticating
devices over SIP.
Auto: the VCS decides, based on the
device type, whether to send NTLM
challenges.
Off: NTLM challenges are never sent.
On: NTLM challenges are always sent.
The default is Auto
AD domain
This must be the fully qualified domain
name (FQDN) of the AD domain that the
VCS will join.
Short
The short domain name used by the VCS
domain
when it joins the AD domain.
name
Cisco VCS Administrator Guide (X7.2)
guide.
page
(VCS configuration > Authentication > Devices > Active Directory
Active Directory Service
for device authentication of Movi /
Usage tips
When the connection is enabled, the VCS will
include NTLM protocol challenges when
authenticating endpoints, according to the NTLM
protocol challenges setting.
Turning Connect to Active Directory Service to Off
does not cause the VCS to leave the AD domain.
Under normal operation this should be set to Auto
where the VCS decides, based on the device type,
whether to send NTLM challenges.
If you are migrating from an existing authentication
mechanism to Active Directory (direct) then select Off
while the connection to the AD server is being
configured; select Auto later, when you have an
active connection and are ready to switch over to this
authentication mechanism.
Never use On, as this will send NTLM challenges to
devices that may not support NTLM (and therefore
they may crash or otherwise misbehave).
Note that the VCS must be connected to an Active
Directory Service in order to send NTLM challenges.
Typically the domain would be the same as the DNS
name of the Kerberos server.
Case sensitivity issues with Active Directory have
been reported and therefore upper case entry is
enforced.
It is also known as the NetBIOS domain name.
Device authentication
Page 118 of 498

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.2

Table of Contents