VCS Expressway, highway

Hello

Gently, I confused, what are the differences between VCS Expressway and Freeway?

-Don't need Expressway a HW (server), it is only allowed in CUCM I need to buy?

-pre sales engineer, when can I choose VCS-E? and when can I take the freeway?

Thanks and greetings

There is a thread here:

https://supportforums.Cisco.com/discussion/12699961/Expressway-series-vs-VCs-control-Expressway

To summarize:

What are the differences between VCS Expressway and Freeway?

-VCS expressway or the Server Traversal is the 'legacy' that supports local recording of external H323/SIP based endpoints by using its features of Registrar Gatekeeper h.323 and SIP. It also serves as the traversal server for VCS (client of crossing) control to support for firewall traversal calls and B2B.

-Highway consists of Core Expressway and the highway, or they call it 'Collaboration Edge'. The concept of highway is the same as the 'life' VCS control + VCS Expressway to provide firewall route, B2B calls. Channel Express is an extension for CUCM controlled environment for Mobile and remote access. With Highway, external clients/video endpoints can register on the CUCM without using VPN. Expressway in this case do not support the records the of endpoints. Endpoints will locally save on CUCM using technology of firewall Expressway (Core + Edge) courses.

Expressway takes a HW (server), it is only allowed in CUCM I need to buy?

Highway needs a server and it can be deployed in a virtual environment.

You can take a look at offerings Cisco Business Edition 6000 (BE6K):

http://www.Cisco.com/c/en/us/products/collateral/Unified-Communications/Business-Edition-6000/data_sheet_c78-717454.html?CacheMode=refresh

as when can pre sales engineer, I choose VCS-E? and when can I take the freeway?

-I suggest to contact your Cisco representative helping you find the right solution for your customer.

Kind regards

Acevirgil

Tags: Cisco Support

Similar Questions

  • Jabber VCS Expressway - DNS resolution internal Highway itself

    Much of community support.

    I am currently configuration solution VCS Expressway (Highway E both Expressway C servers). Due to some restrictions of firewall that I need to resolve the fqdn Expressway C directly from the highway E server which means that I need to Hwy E resolve C Expressway fqdn withoout using the DNS server. I was wondering if there is a way to edit the VCS Expressway hosts file (if such a thing exists in the VCS) as anyone can do in the operating systems such as linux. I make this question because I took a capture .pcap of VCS and there saw the DNS query process but option number one was 127.0.0.1, which is the highway itself. Perhaps this connection attempt is just the highway to research in its DNS cache, but I'm not sure.

    Best regards

    Roberto Lopez.

    Ah, this is the reason why I asked. You don't need DNS for it.

    The way it will work is when the Traversal (in your case Expressway-C) client tries to connect to the server of course (in your case Expressway-E), the Traversal server will look at the common name on the cert that was produced by the customer of the crossing. He sees if the highway E would be there with what is specified when you configure the zone crossing on the highway e.

    Basically, DNS is not necessary. You just need to make sure that the domain Highway C FULL name is what is specified in the "TLS check name of the topic." Also make sure that if the certificates are signed by a CA, root/intermediate certificates must be downloaded to the two C/E Expressway. also, make sure you put the FULL name of the motorway E in the crossing area on the fast track C, and not the IP address.

    HTH

  • Highway-C and highway-E and VCS Expressway

    Hello

    I'm confused by these three

    I know that expressway-E is used with Express-C track

    Their function is like VCS Expressway? or am I wrong?

    Please help to know when to use each one?

    Also why use us next to the firewall? What is the average of the crossing of firewall?

    Also, when I connect external with Jabber, is there any type of registration with each of them? I see a number taken in charge of registeration of 2500 and 5000 in the VCS Expressway data sheet

    Thank you

    Haitham

    Hi Haitham,

    In general, a point of endpoints/client must register for a 'device' so that it can be used as part of a company dial plan. This 'device' could be CUCM or a VCS and will determine if an endpoint/client is used to connect, or how the calls and form, it can be done.

    If the endpoint does NOT have one of these devices (CUCM or VCS), it could still be used (for example, a videoconferencing device stand alone), it's just that we do not see within the company structure of appeal. It may not appear in the directories, it cannot give priority to call outside, etc etc. The Jabber client has to register with CUCM either a VCS to make it work at all.

    If you use CUCM with a VCS-E, endpoints will record to CUCM. If the endpoints are internal to the company, they apply directly to the CUCM and if are external, then they will be connect via VCS-E and the recording will be dug through CUCM, so still save with CUCM.

    VCS-C/e with environment of TMS, endpoints will record VCS - c when internal and again use the VCS-E for tunnel applications from external device to the VCS - C. Depending on how you want to deploy these devices, external devices/clients could actually register directly with VCS-E, but I'm getting ahead of things. Jabber in this environment use of TMS to provide authentication of the user, even if the actual recording takes place on the VCS.

    Does that help?

    Chris

  • Control of VCS and VCS expressway design

    I have a problem with the design of control and track Express VCS. Now, here's two VCS control and a highway. As you know, put on the Internet Highway and a control on my seat. At the same time, I want to put the other control on the management of my company which is in another city. Can it work correctly? How dose it work?

    You must create two zones on VCS Expressway crossing server and a customer journey area by control VCS.

    In other words, you should have a link path by VCS - C connection VCS-E separately.

    Please be sure to set different H.323/SIP port on each VCS - C.

    For example:

    VCS - C1 (Headquarters): area of traversal client pointing to VCS-E 6001 as port H323 and SIP traversal port 7001.

    VCS - C2 (branch): area of traversal client pointing to VCS - E with 6002 as port H323 and SIP traversal port 7002.

    VCS-E: a traversal server zone list for VCS - C1 (6001 as port H323 and SIP traversal port 7001) and other traversal server list for VCS - C2 (6002 as port H323 and SIP traversal port 7002)

  • Question record DNS SRV + VCS Expressway

    Hi all

    I have a South, VCS in the DMZ, and I am facing a problem with the SRV DNS records.

    VCS Expressway Hostname:-VCSe

    Domain: example.com

    FULL VCSE domain name: VCSe.example.com

    and I have an a record set up for the same FQDN in DNS Public Server.

    I have a sip domain configured as 'cisco.com' in my VCS Expressway.

    What is the SRV records, I need to create in the Public DNS server.

    Kind regards

    Nikhil Jayan

    Nikhil,

    It seems that you have not checked the link I sent you earlier... A very explicit documents. in any case that we talked about earlier is we were talking about signs send calls to the highway as well as parts of the record.

    In your deployment, you have a different domain for DNS and SIP domain. Also as you say you meet Highway cluster and you want to record to both endpoints and then I suggest you to check the document for the creation of cluster on cisco webesite.

    Now, if you have a cluster for Highway then you must create several srv records that would be pointing to each domain name FULL of the approved cluster with equal weight. In normal use scneario of domain common to different services are recommended.

    Srv records would have seen something like that.

    _sips._tcp.company.com. 86400 IN SRV 1 1 5061 vcse1.company.com.

    _sips._tcp.company.com. 86400 IN SRV 1 1 5061 vcse2.company.com.

    _sip._tcp.company.com. 86400 IN SRV 1 1 5060 vcse1.company.com.

    _sip._tcp.company.com. 86400 IN SRV 1 1 5060 vcse2.company.com.

    _h323ls._udp.company.com. 86400 IN SRV 1 1 1719 vcse1.company.com.

    _h323ls._udp.company.com. 86400 IN SRV 1 1 1719 vcse2.company.com.

    _h323cs._tcp.company.com. 86400 IN SRV 1 1 1720 vcse1.company.com.

    _h323cs._tcp.company.com. 86400 IN SRV 1 1 1720 vcse2.company.com.

    _h323rs._udp.company.com. 86400 IN SRV 1 1 1719 vcse1.company.com.

    _h323rs._udp.company.com. 86400 IN SRV 1 1 1719 vcse2.company.com.

    However, your case is different. In your deplyoment what you have to do is any request for the domain "cisco.com" should be resolved in FQDN of the VCS-Highway peers with equal weight.

    for example

    _tcp.gmail.com. IN SRV 20 0 5222     talk2.l.google.com.

    Therefore, any request to gmail.com would resolve to the talk2.1.google.com server.

    same way you have to make it work.

    Thank you

    Alok

  • VCS Expressway outside to endpoints internal call

    I have a new implementation where internal control 1 to VCS in LAN and VCS Expressway in DMZ 1.

    VCS Expressway has an IP public address/NAT.

    Currently, we have a group of VC endpoint, each endpoint has a public IP/NAT to the local network, to allow internet to make H.323 call directly by public IP address of the composition of the endpoint.

    My question is, after having implemented VCS Expressway in DMZ, how do the numbering plan at each endpoint internal VCS Highway outside call? Do I still need to give to each endpoint an ip/NAT publich.

    Thank you very much.

    A much simpler and in my opinion, more elegant and more scalable solution would be not to use IP addresses for calls, but to allocate and register outcomes with E.164 alias. That way you all you need is the internal IP address.

    So the outer ends may, in this case, call your settings using the [email protected] / * / or [email protected] / * /-E_IP_address.

    Internal assessment criteria can call each other using alias only for as long you have the rules of research in place, and cannot therefore have the external ends you will allow to record with you VCS-E for one reason or another.

    If you have the outcomes of Polycom external with the old version of the software that does not support Annex O URI component, then it's very simple to include a transformation of prior research on the VCS-E which will allow these settings call using owners 'numbering URI "; VCS-E_IP_address ##Alias - and if you, on the odd occasion, a final point which cannot use anything other than IP addresses, you can configure the alias of relief on the VCS-E to point to a specific or a standard automatic on a MCU, purpose etc.

    A dial plan using as above will also allow you to use DHCP addresses, the alias remains static, and that's what counts, addresses much simpler to give to people. e.g. 123456 is much easier to remember than 202.138.98.23 etc, not to mention the IPv6 addresses, and because you save your settings with domain name, and then customers SIP will also be able to connect very easily.

    /Jens

  • VCS Expressway & movi 4.2 configuration

    Hi all

    I created movi account manually in the TMS and it work perfectly with VCS - control.

    However, it cannot register for VCS expressway. Is it mandatory to have a name authority pointer record in DNS?

    For example, configure us abc.com as the domain name SIP Highway VCS, is mandatory to fix abc.com as public highway VCS by DNS server IP address?

    Thank you

    Ben

    That is to say you do not originate in the AMZ comes directly to the public IP address of the VCSE

    If that's the case at least, you should see registration tent if nothing can be seen then you need to look at the firewall

    is he ASA? try tp packets capture and see why you arew not hitting the VCSE using SIP

    as it could be firewall issue!

    HTH

  • How to make or VCS Expressway TURN illustrated works?

    Hi, Experts.

    My VCS Expressway equipped Tower, and I found for TOWER configuration is pretty simple, it allow just under VCS Configuration > Expressway > turn ON, but no matter, I tried, licenses of relay TOWER always indicated '0' in the 'current' line under the VCS Expressway dashboard.

    I took my test in this way, two Jabber client video (v4.5, MAC edition) reside in a different network behind NAT (no firewall), they call each other and regardless I turn on or turn off the TOWER, still good video quality services mine. (VCS Highway away from the two movi), I assumed that in both cases, the media traffic send directly between the two Movi, rather than climb up to the VCS Highway and then return, normally called us "Hairpin" traffic.

    The result is not I have enabled or disabled the service of the TOWER, it always not-pinned hair, and still no license relay TOWER was used.

    What happens here? something wrong? I'm quite confused.

    You have to turn on the feature of ice on the Jabber video model?

    On the model of commissioning, you must configure the address of TurnServer, TurnAuthUsername and TurnAuthPassword.

    You must also configure the authentication domain in VCS - E who use to run the server (you must set the match name and user password with TurnAuthUsername and TurnAuthPassword set up on the model of commissioning).

  • 2 MCU and VCS Expressway, routing problem

    Hi all

    We have a design with a group of control VCS (2 members), cluster VCS Expressway (2 members), and a couple of microcontrollers (registred H.323 on VCS control cluster with the same prefix: 90).

    Each highway has a public IP address and incoming calls from outside can only be routed to microcontrollers:

    [email protected]/ * / for MCU_1 and [email protected]/ * / for MCU_2 (we don't have external DNS resolution).

    I put a conversion into motorway of VCS to change [email protected]/ * / to [email protected] / * / and [email protected]/ * / to [email protected] / * /.

    The problem is when someone calls [email protected]/ * / sometimes (randomly) the call is routed to MCU_2 (instead of MCU_1) and if the appellant see the auto attendant.

    The occcurs even then of the appeal [email protected]/ * / (MCU_2), sometimes the call is routed to MCU_1.

    Any idea what can cause this device or a way to make it work well?

    Thanks for help.

    José

    I think still that separate prefix would work, but here are a few ideas:

    Are incoming calls which do not possibly using SIP that is being interoperability H323 or incoming calls all certainly the H323?

    If you want to keep pure H323, you could perhaps just have a search rule/turn on your VCS-E who changed [email protected] to an E164 e.g. 90... and had a search on your VCS - C rule that says 90... stop at the local area.

    I also noticed that you direct calls to [number]@MCU-IP - have you tried to direct all calls to [number]@VCS-C IP instead?  If the VCS is the holder of a registration for a number, it should be able to deliver accordingly.

  • review during deployment - VCS Expressway

    Hello world!!!

    We knew the benefits of deployment - VCS Expressway. After reading "Cisco TelePresence video Communication Server Configuration of base (control with Highway) - Deployment Guide", I and my team are faced with the following:

    1 - if we do not "Advanced Networking option key", we are not able to use the static NATing feature of the VCS Expressway, but also the interfaces network double. This is why we need this firewall do NAT reflection (it allows to control VCs access the IP public VCSexpressway) and the deep Inspection (to change the IP address that is part of the SIP header). This statement is correct?

    2. - If in my deployment, I'll open some ports in the firewall, is it means that my network is exposed to external threats? There are a few Considerations to keep in mind the safety on the end points that will be in the Internet?

    I also leaves a small attached file, in this file, you can get an idea of what I'm doing. I will seek in advance for your comments. Thank you for all.

    The same concept applies to the least.

    If you already have a DMZ with public IPs, you should be fine. If not, you could split the existing subnet you have, get a new ISP, use proxy arp...

    Not sure how are your details if you are unsure how to configure what I told you in the message before you may need to ask a guy to additional network.

    As you say yourself, if you can not prevent NAT (course, which is a nice way to deploy, but it would require double interface, now known as enhanced networking key).
    Also remember that you must not share the VCS-E IP with other services.

    Another option may be to accommodate the VCS-E to an ISP or there is also some providers that offer an area crossing of VCS (at least the non-cucm style) as a service.

    That you have developed a computer user, do you plan to use jabber-video (old style of tms) or jabber (cucm)?

    Please note the messages with the stars below and define the thread if it's an answer!

  • VCS Expressway

    Hello

    • Is attached design, pls confirm if it is correct?
    • Actually my boss want to have a video conference with the xyz company that is have a VCS highway up and it works direct, we ordered the new switch Express VCS and 1 not old codec C20 it asked me to install, and unfortunately, I'm not able to configure, want to know the concept how URI dialing , and how do I register endpoints TP in VCS, I am recording Codec C20 for VCS and it shows in the registration of newspapers rejected and failed on C20.
    • Very new to VCS and desperately want to know how the flow of calls will be in 2 our separate entities for example, mycompany.com and xyz.com
    • There is no default gateway for LAN2 option so how traffic will be routed to other areas, we can add a route in VCS.

    Thank you

    Usually, there are two components - control and VCS VCS Expressway. VCS control is located on the internal network and VCS Expressway is located on the external/DMZ network. Endpoints register control VCS. VCS control build a "Zone of crossing" VCS Expressway and when endpoint route tent yells, he's going to Control of VCS VCS Expressway and then.

    You may be able to register endpoint for VCS Highway if you supply on this device license. You must configure a domain on the VCS to accept records. You must define this area even on the endpoint as well.

    Take a look at this to resolve endpoint records. http://www.Cisco.com/c/en/us/TD/docs/Telepresence/infrastructure/article...

    This can also be caused by firewall as well.

    You can see the documentation below for how to configure the outgoing VCS-C/VCS-e call.

    http://www.Cisco.com/c/en/us/TD/docs/Telepresence/infrastructure/article...

  • Jabber client - encryption of VCS Expressway with MRA

    Hi all

    I'm working on the implementation of MRA for a video solution existing. Version CUCM is 9.1.2 (no IM & P server), vcs - c and vcs-e 8.2.2.  Client Jabber is 11.5.x

    I finished most of the introduction and I am able to call internally and externally through MRA.

    I still have a few things to tweak.  One is the encryption of video calling once jabber connects from outside.  From my understanding, the thigh jabber call end point and VCS Expressway uses TLS. But when I run wireshark on the PC with Jabber client, I don't see the RTP stream as being encrypted.

    CUCM my jabber device does not use a secure profile.  Is it ok or not?

    Please let me know if more are needed.  Thank you

    You can confirm the call is encrypted from the client of jabber MRA by doing as follows (I used 11.5 jabber client, if you are using an older client, I can't guarantee this method):

    1. make a call from the client jabber ARM, once the call is configured and media is established, you can end the call.
    2. create a jabber client problem report (help > report a problem...)
    3. Enter the required details and save the .zip file.
    4 extract the file "jabber.log" from the .zip file. Since this file (at least since the version of client jabber 11.5) has the SIP messaging included in this document, you can use TranslatorX to view the file (you can also use a text editor if you wish).
    5 generate a diagram of the log file.

    6. in the diagram of the scale, you should be able to locate the origin of the call. Search for an invitation, in my case a "RE-INVITE" and select it. A pop-up window will appear with the details of the SIP message.

    7. read the content of the message prompt of the SIP protocol (focusing on the SDP - the component of negotiating media). I won't go into detail about how to read SIP messages (there's a good article here, it is not for jabber specifically, but the same concepts apply).

    8. close the prompt message and open the message 'OK w/SDP' to examine the response of the VCS-E. The SDP response, we can confirm that the encryption settings have been accepted for the media (media will be encrypted).

    For re - apply point Jamie, unless you run CUCM in mixed mode and using security profiles, signalling/media encryption stops on the thigh of CUCM/endpoint and the VCS - C respectively. See the diagram below for reference (mixed mode not implemented).

    You need not applied to the device of CSF security profiles to obtain the encryption between the client of jabber MRA and the VCS-E. If you can decode signaling and media packets in Wireshark your jabber client, you probably will not connect via ARM (ARM is always encrypted).

    Please let us know if that helps.

    -Jon

  • VCS expressway firewall rules

    Hello

    I just need your confirmation on the following configuration.

    VCSC - FW - Internet

    |

    |

    VCSE

    We use the double option with NAT Nic key.

    VCS expressway wil be connected with 1 single interface LAN for FW.  It will be a private ip address.  Firewall will be Natting the private ip address of VCSE to a public ip address.

    When updating the FW in ruling according to the following link:

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Basic_Configuration_Cisco_VCS_Control_with_Cisco_VCS_Expressway_Deployment_Guide_X7-1.PDF

    Appendix 3 - Page 55-58

    What address VCS expressway ip do you need to use FW rules?  a private or public?

    Thanks in advance.

    Ahmed

    Hi, Ahmed.

    If you use the VCS-E with the option of dual interface for NAT with all of a communication interface,

    the internet and your internal network must go to the _public_ ip address, not the private sector

    one. If it's not only on the firewall, but also the destination of the area on the VCS - C.

    Regards to your firewall, that depends on what must have configured your firewall.

    Some firewalls (or at least admins/users) seem to have problems getting the vcs - e accessible from inside on the

    external ip address. If there is a problem, you must use the secondary interface of the vcs and set a new

    DMZ.

    Please remember useful frequency responses and identify useful or correct answers.

  • VCS Expressway Starter Pack

    Hi all

    First of all, let me say that I am the kind again in part "Tandberg" telepresence.

    I'll put up a VCS Expressway Starter Pack (with the option to double network interface) the week next to our customers.

    I read the VCS Expressway SP deployment guide, but I still have a few questions:

    -What is the best place to place the SP VCSe?  (inside the DMZ, or the Public network)

    Tomorrow we will hear whether or not the customer has a demilitarized area.

    -I understand that the external firewall must redirect the ports 5060, 5061 and range 50000/52399 to SP VCSe

    If there is a demilitarized zone we need to open the ports on the firewall inside as well?

    -Is possible with MS VCSe to receive video calls to (locally) the ends registred? (For example: an E20 to another company) If so, we need to open additional ports on the firewall?

    Thank you in advance,

    Wouter

    Hi Wouter,

    Check out the link for more information below.

    http://www.Cisco.com/en/us/prod/collateral/ps7060/ps11305/ps11315/ps11337/data_sheet_c78-697075.html

    It gives answer to some of your questions, like which is the best place to install the VCS - SP network.

    Normally, we have seen many customers put the box in the DMZ and use for incoming and outgoing calls.

    Although the deployment either specifically depends on requirement and network design once.

    Also see VCS starter pack deployment guide.

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Expressway_Starter_Pack_Deployment_Guide_X7-1.PDF

    He gave the port information and also check the document use of port at the link below.

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_IP_Port_Usage_for_Firewall_Traversal_Deployment_Guide_X4_to_X7.PDF

    and answer your last questions, yes its possible to receive video call of endpoint not locally registered in VCS - SP, but then you need of DNS SRV records for your video field or you must call using ip address-SP-VCS.

    SRV DNS is the preferred method.

    Thank you

    Alok

  • Control of Cisco and VCS VCS Expressway

    Dear team,

    We bought Cisco VCS and VCS Expressway 7.X.

    Need download link for the model of the FVO and software and please guide how to install Cisco VCS and VCS Expressway 7.X?

    Thank you

    Cisco_VCS_Virtual_Machine_Deployment_Guide_X7-2 may exceed OVA installation and initial configuration.  Additional configuration and deployment guides that they can be found here.

Maybe you are looking for

  • DVD - ROM works do not (S1800-804)

    Suddenly, the DVD doesn't work. The light is on permanently. The dvd seems to begin by putting in a disk, but doesn´t actually read any CD or DVD. Nothing happens. Everyone who recognize this behavior, or what to do?BIOS (2.20)

  • Droid RAZR, what we expected the Bionic to be?

    http://reviews.CNET.com/8301-19736_7-20111681-251/Moto-droid-RAZR-could-offer-dual-core-processor-Lt... http://blog.wirelessground.com/Motorola-Atrix-2-droid-RAZR-Spyder/ For those of us who does not jump to the bionic, it seems that the Razr Droid c

  • Windows Media Player is dragged off the screen, now I need to go back to the screen as soon as possible HELP

    SO I was using windows media player and makes it smaller.  Unfortunately I dragged off the screen too far to the right.  How get her back to the screen?  Help

  • Is blackBerry smartphones possible to use ID BlackBerry 8520?

    Hello. Is it possible for BB 8520 (gemini) to transfer contacts via BBM ID BBM? No backup and restore of BB desktop software (using desktop software will take all bbm contacts to be re-guests and have agreed to be in contact again).I think I need to

  • Screen white dv5 - 1128ca

    My monitor was working fine so I reset my labtop did not move to the screen and it won't turn. I disconnected all the power supplies that is held the button for 30 seconds and then plugged the power in. Still no light upward and turn on. I connected