Remote-access Guide

cisco expressway mobile and remote access 8.6

by Dashawn Koelpin Published 2 years ago Updated 1 year ago
image

What is Expressway C?

How does the Expressway work?

What are the two Cisco certificates?

How does Jabber verify the identity of Expressway E?

What is a mobile and remote access solution?

What is Cisco Unified Communications?

Is unified CM impacted by Expressway?

See 2 more

About this website

image

What is Cisco Mobile Remote Access?

The Cisco Mobile and Remote Access (MRA) feature is a “client edge” solution that allows external software and hardware clients to register to enterprise Cisco Unified Communication (UC) solutions without requiring a VPN.

What is the purpose of mobile and remote access MRA in the Cisco CUCM architecture?

The Mobile and Remote Access solution (MRA) supports a hybrid on-premises and cloud-based service model. This provides a consistent experience inside and outside the enterprise. MRA provides a secure connection for Jabber application traffic without having to connect to the corporate network over a VPN.

How do I access Cisco Expressway?

Open a browser window and in the address line type one of the following: • IP address of the Cisco Expressway (for example, https://10.0.0.1). Enter the address as HTTPS. FQDN of the Cisco Expressway (for example, https://mydomain.example.com).

What is Cisco expressway used for?

Cisco Expressway is a powerful gateway solution specifically designed for comprehensive collaboration services provided through Cisco Unified Communications Manager, Cisco Business Edition, or Cisco Hosted Collaboration Solution (HCS).

What are MRA phones?

Basically, MRA (Cisco Unified Communications Mobile and Remote Access) allows endpoints such as Cisco Jabber to have their registration, call control, provisioning, messaging and presence services provided by CUCM when the endpoint is outside the enterprise network.

How do you set up an MRA?

0) - MRA Configuration [Cisco Expressway Series] - Cisco....ProcedureOn the Expressway-C, go to Configuration > Unified Communications > Configuration.Set Unified Communications mode to Mobile and Remote Access.Click Save.Repeat this procedure on Expressway-E.

What is the difference between Cisco Expressway C and E?

Differences between VCS C and VCS E Tandberg's legacy devices typically used VCS Control, or VCS C, within the organization and VCS Expressway, or VCS E, was used between firewalls. To put it more simply, VCS C was used internally within the organization while VCS E was utilized externally.

Is Expressway secure?

Secure communication is possible with Expressway because it uses two servers. The core server, known as Expressway-C, sits inside and acts as a firewall traversal client. The second server, Expressway-E server, is on the edge of your network and is the only point of access to the public Internet.

How do I upgrade my Cisco Expressway?

2:144:49How to Upgrade an Expressway Cluster - YouTubeYouTubeStart of suggested clipEnd of suggested clipAnd restore type an encryption password. And create system backup. File. Now go to maintenanceMoreAnd restore type an encryption password. And create system backup. File. Now go to maintenance maintenance mode. And turn maintenance mode on if there are any active calls or registrations.

What is difference between Expressway-C and expressway-E?

The Expressway-C is configured with DNS servers which are located on the internal network. The Expressway-E is configured with DNS servers which are publicly routable.

What does Expressway mean?

Definition of expressway : a high-speed divided highway for through traffic with access partially or fully controlled.

What are two functions of Cisco expressway in the collaboration edge?

A. Expressway-C provides encryption for Mobile and Remote Access but not for business-to-business communications. B. Expressway-E provides a VPN entry point for Cisco IP phones with a Cisco AnyConnect client using authentication based on certificates.

What does Cisco Unified Communications Manager do?

CUCM is responsible for digit analysis of all calls. CUCM enables users to create scalable dial plans. Phone feature administration: CUCM extends services such as hold, transfer, forward, conference, speed dial, redial, call park, and many other features to IP phones and gateways.

How does Cisco Unified Communications Manager work?

CUCM uses SIP or SCCP to communicate with Cisco IP Phones for call setup and teardown and for supplementary service tasks. After a call has been set up, media exchange occurs directly between the Cisco IP Phones across the IP network, using the Real-Time Transport Protocol (RTP) to carry the audio.

What is the difference between CUCM publisher and subscriber?

The publisher verifies the subscriber's authenticity and adds the subscriber's IP address to its dynamic firewall (iptables). The subscriber is allowed to access the publisher database. The database content is replicated from the publisher to the subscriber.

What are network services and feature services What is the difference between them?

To avoid throwing errors only the needed feature services are activated (i.e. allowed to start). Network services are non-optional services for that product: they are required in all deployment scenarios. You have no ability to prevent them from starting but are able to stop/start/restart them.

What is off-premises access?

Off-premises access: a consistent experience outside the network for Jabber and EX/MX/SX Series clients

Can a third party SIP device register to Expressway C?

Third-party SIP or H.323 devices can register to the Expressway-C and, if necessary, interoperate with Unified CM -registered devices over a SIP trunk.

Does MRA require Expressway?

Any MRA solution requires Expressway and Unified CM, with MRA-compatible soft clients and/or fixed endpoints. The solution can optionally include the IM and Presence Service and Unity Connection. This guide assumes that the following items are already set up:

What is Cisco Jabber?

Cisco Jabber Overview#N#Cisco Jabber is a suite of enterprise-class collaboration tools supported by the Cisco Unified Communications Manager (CUCM) platform. Jabber offers a highly secure solution for interacting with your contacts via Instant Messaging and Presence (IM&P), voice and video calling and conferencing, visual voicemail, desktop sharing, and file transfer. Jabber clients are available for Windows and Mac computers, Virtual Desktop Infrastructure (VDI) desktops, plus Apple iOS and Android smartphones and tablets. Jabber also works seamlessly with Cisco IP voice and video phones and integrates with Microsoft Office applications.

Does Jabber support SIP?

Voice and Video Calling: Integrated audio/video is available on desktops used as soft phones or on Cisco IP video phones. Jabber supports Session Initiation Protocol (SIP) for URI-based dialing, and you can call directly from your contact list. (See Progent's Cisco SIP infrastructure integration consulting .) Jabber's multiline support allows you to set up users with as many as 8 phone lines. CUCM options available for call control include mute, call forwarding, and ad hoc conferencing.

Does Jabber work with Cisco Unity?

Voicemail: Jabber integrates with Cisco Unity Connection to allow clients to view, play back, and erase voicemail and visual voicemail messages. (See Cisco Unity Connection integration services.

Does WebEx Messenger work with Jabber?

You can use Cisco WebEx Messenger in a cloud or hybrid deployment. Current versions of Jabber fully support the O Auth open-standard authorization protocol.

eDirectory Indexes

eDirectory relies on distributed indexes to maintain its scalability and high level of performance. An index is an attribute of a Server object and is stored in the Directory. As such, each index is unique to one server and is not shared by other servers in the eDirectory tree.

Lab Exercise 3.3: Create Novell eDirectory Indexes

As you learned in this lesson, creating an eDirectory index is a three-step process:

eDirectory Filtered Replicas

eDirectory 8.6 includes a segmentation strategy known as partitioning. Partitioning breaks up your eDirectory tree into two or more logical divisions that can be separated and distributed. Copies of partitions can be distributed on multiple file servers in a strategy known as replication .

Lab Exercise 3.4: Configure Filtered Replicas

In this exercise, you learn to use ConsoleOne to create partitions of the Organizational Unit containers you imported in Exercise 3.2. You then create filtered replicas of these partitions on the WHITE-SRV1 server.

Lab Exercise 3.5: Understanding Novell's Newest eDirectory (Word Search Puzzle)

Circle the 20 Novell eDirectory terms hidden in this word search puzzle using the hints provided.

Hints

Index automatically created by eDirectory when certain attributes are created.

InformIT Promotional Mailings & Special Offers

I would like to receive exclusive offers and hear about products from InformIT and its family of brands. I can unsubscribe at any time.

About Agami Technologies

Agami Technologies has pioneered Cisco technologies for the past 25 years, consistently delivering business value with the latest technology.

Technology solutions to help businesses succeed

Agami Technologies is a privately owned Information Technology Services business founded in 2006. Today we’re proud to boast a strong team of IT engineers who thrive to solving your IT challenges and meeting your business needs.

Our History

Agami Technologies is established in 2006 by Rani Chouha, a Cisco Certified Internetwork Expert (CCIE #15943). AT&T Labs in Middletown, NJ hires Agami Technologies to help design and test MPLS networks for their large scale prestigious clients.

What is Expressway C?

Expressway-C automatically generates non-configurable neighbor zones between itself and each discovered Unified CM node. A TCP zone is always created, and a TLS zone is created also if the Unified CM node is configured with a Cluster Security Mode (System > Enterprise Parameters > Security Parameters) of 1 (Mixed) (so that it can support devices provisioned with secure profiles). The TLS zone is configured with its TLS verify mode set to On if the Unified CM discovery had TLS verify mode enabled. This means that the Expressway-C will verify the CallManager certificate for subsequent SIP communications. Each zone is created with a name in the format 'CEtcp-<node name>' or 'CEtls-<node name>'.

How does the Expressway work?

The Expressway can limit the number of times that any user's credentials can be used, in a given configurable period, to authorize the user for collaboration services. This feature is designed to thwart inadvertent or real denial of service attacks, which can originate from multiple client devices authorizing the same user, or from clients that reauthorize more often than necessary.

What are the two Cisco certificates?

The two Cisco Unified Communications Manager certificates that are significant for Mobile and Remote Access are the CallManager certificate and the tomcat certificate . These are automatically installed on the Cisco Unified Communications Manager and by default they are self-signed and have the same common name (CN).

How does Jabber verify the identity of Expressway E?

Jabber clients must verify the identity of the Expressway-E they are connecting to by validating its server certificate. To do this, they must have the certificate authority that was used to sign the Expressway-E's server certificate in their list of trusted CAs.

What is a mobile and remote access solution?

The mobile and remote access solution supports a hybrid on-premises and cloud-based service model, providing a consistent experience inside and outside the enterprise. It provides a secure connection for Jabber application traffic without having to connect to the corporate network over a VPN. It is a device and operating system agnostic solution for Cisco Jabber clients on Windows, Mac, iOS and Android platforms.

What is Cisco Unified Communications?

Cisco Unified Communications mobile and remote access is a core part of the Cisco Collaboration Edge Architecture. It allows endpoints such as Cisco Jabber to have their registration, call control, provisioning, messaging and presence services provided by Cisco Unified Communications Manager (Unified CM) when the endpoint is not within the enterprise network. The Expressway provides secure firewall traversal and line-side support for Unified CM registrations.

Is unified CM impacted by Expressway?

The Unified CM dial plan is not impacted by devices registering via Expressway. Remote and mobile devices still register directly to Unified CM and their dial plan will be the same as when it is registered locally.

image
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9