VCS-highway safety issue

Hi, I just want to know who runs the VCS-E server itself to avoid attacking

If the outside IP LAN cannot be ping and web access?  or other means?

Thank you very much

Depends on your deployment, that is, if you put the VCS-E in a DMZ or completely in the wild. Otherwise web access (https) and ssh console access can be enabled/disabled as needed on the VCS itself. In the end, it is entirely at you how do you protect the system against attacks. Take a look at the deployment guide: http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/config_guide/X8-2/Cisco-VCS-Basic-Configuration-Control-with-Expressway-Deployment-Guide-X8-2.pdf

Also suggest you take a look at the Administrator's guide: http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/admin_guide/Cisco-VCS-Administrator-Guide-X8-2.pdf - see "intrusion protection" in particular.

/Jens

Please note the answers and score the questions as "answered" as appropriate.

Tags: Cisco Support

Similar Questions

  • family safety issues - have not received activity reports

    Original title: family safety issues

    I created an account for a child more than a week and had no activity reports.  When I log into my account, click on the family, and then my son's name he says no accounts are active for him. I have everything turned on and implemented. Don't know what's the problem? I tried the option to turn on family safety on an existing Childs account. I drag the right side of the screen, select settings, change laptop settings, click accounts and I can't go any further. My watch account only and not my Childs (it doesn't have its own account on sound / this tablet).  the instructions say select other accounts, but it is not an option. I have to close his account and start over?

    Hi Peterren,

    Thanks for posting your question in the Microsoft Community.

    I'm sorry to know that you are facing this problem.

    Please answer this question to get more clarity on this issue.

    • You did changes to the computer before this problem?

    Manually, you can update the family safety filter and restart the computer to see if that help.

    How to update the family safety filter?: http://windows.microsoft.com/en-US/windows-live/family-safety-filter-faq

    Keep us in the loop to help you further.

  • Cisco VCS-highway network Dual interface option key required

    Dear expert;

    I'm new on TV Cisco presence.

    We have below BOM ordered by the customer as well as the VCS-Express is device without network double button Option Interface.

    Now they have made the redundant system with VCS-highway in VM and want to use Nating for which we need double Network Interface license key option.

    How we get this.

    Appreicate your valuable response.

    The option key double network is provided with virtual VCS, however, is a separate post for the VCS material, to enable network features dual on your existing hardware VCS, you will need to order LIC-VCS-DI.

  • VCS-Highway RTP streams

    Hello

    If 2 of my home (EX90) users are registered the SCV-Expressway of internet, when they make calls.

    1. the RTP necessarily flow via Hwy VCS and consume traversal licenses; Suppose that there is no work required for H.323, SIP or IPV4 to IPv6.

    2. it will make a difference if the end EX90 points have a public IP address and not Natted router SOHO?

    3. what happens if the EBU home use Jabber or Movi?

    best regards

    Kabylie

    If you connect public network directly to EX90 with attribution of a public IP, while EX90 will have same IP (local IP address on EX90) and IP source address.

    Also of the PC with 3G mobile connection (3 +, LTE service, etc.), ISP can assign the public IP video Jabber will of the contract, the IP address and the IP source address.

    If EX90 is located behind the home router and NAT to connect the VCS-E, call will treat as traversal appeal except call establish ICE TOUR call.

    ICE (Interactive Connectivity Establishment), two SIP UA are trying to link the RTP/RTCP directly during the call to install and successfully establish the link, then stream media directly, otherwise fall back to the relay of the TOWER (route call via VCS - E).

  • VCS Highway internal of external call (Live ip)

    Dear members,

    It is I want to call the other end points all over the world who have direct ip, and similarly with the keeper change affecting I want to call my end points too.

    Note:

    When I call from my endpoints the register to the doorman, but when I do the direct ip call I choose the Direct option. I can able to appeal to both ends with the change of the setting.

    Kind regards

    Archambeau

    I might be a little lost on what you have and how it is configured, but on page 30 of this guide http://www.cisco.com/en/US/docs/telepresence/infrastructure/vcs/config_guide/Cisco_VCS_Basic_Configuration_Control_with_Expressway_Deployment_Guide_X7-2.pdf

    the configuration required to enable locally registered endpoints call public IP addresses directly explained. You only need to register your end points of your VCS using SIP and H323 (either one will be fine), and the VCS configuration takes care of the rest.

    -Zac Colton

  • -Map and safety issues. Privacy settings

    Can someone please tell me the benefits and negatives of to 'Use wireless networks' checked in location & security settings - my location and "back up my data" enabled in the privacy settings.

    Gary

    Thank you!!

    No effect on the battery life?

  • VCS Expressway cannot connect

    Hello

    I just put in place a control of VCS and a highway of VCS. I set up the traversal client on the VCS control using the port 6001 H.323 and SIP 7001.  I set up the crossing on the VCS Exp server using the same ports.  I get "H.323 could not not connect to x.x.x.x:6001 no response of the system.

    The SIP will not connect either 'connection failed '.

    There is no list of the control of VCS to VCS highway.  Authentication is disabled.  They are both pointed out the same NTP.

    Any ideas?

    Thank you!!

    Rhonda,

    In short, the configuration looks OK. Can specify you what other types of devices couche3 between the VCS - C and VCS-E outside the ASA?

    If the firewall is not the issue, the problem may be caused by routing problems. If you allow ICMP from the command to the highway, you can check if the routing of the works by logging in as root (with SSH) for the VCS - C and launching the command

    Traceroute x.x.x.x

    where x.x.x.x is the IP address of your Expressway.

    Thank you

    Andreas

  • How to change the issue secret

    Hi I was wondering how I can change my security question, I know the answer to it, but during the installation I choose a really easy and now want to change?

    If you change your password, you will be prompted for a new safety issue. If you are comfortable with your current password, go through the process, but simply provide the same password where he asks a new.

  • Cisco VCS Lync Interworking with Lync Server/multiple domains

    Unfortunately I don't find any reference in the guides of deploymend, if it is possible to master several server/domains on a single VCSE lync. Is there a way to gather environments different lync with a vcs? For example, interoperability with clients a and b, which have completely separated from lync environments.

    We wanted to master it with VCSE, or is the Microsoft key option only avalible for VCS?

    Thanks for the reply.

    The Deployment Guide says you should use a VCS-control, not a VCS-Highway to serve as gateway of Lync.

    I don't think I have several B2BUAs connect to Lync on a single VCS - you would need to have a separate VCS for each Lync environment (IE, one for the customer) and another for client B and search rules appropriate to direct traffic areas in the right direction.

  • License VCS\VCSE of virtual machine hardware migration.

    Hi all

    I want to migrate my hardware to virtual VCS\VCSE.

    Both servers are covered by the active maintenance contract.

    How licenses work in this case? What is the procedure of transfer?

    Any cost?

    Thank you.

    Hello

    About Cisco VCS, you want to migrate virtual machine hardware, you will need to purchase a new license to make the transfer. These are the partnumbers you need:

    R-VMVCS-C-M-K9

    HW migration to E - Delivery Virtual VCS only controls

    R-VMVCS-E-M-K9

    HW migration to E - Delivery Virtual VCS Highway only

    Please contact your Cisco representative for more information.

    After purchasing the license, the license of the VM device rehost will be made by a specific Cisco team, not the team of global license, it is a process different rehost. You will need to send your request to [email protected] / * /, this team will provide instructions to rehost your VCS license correctly.

    I hope this helps.

    Concerning

    Paulo Souza

    Please note the answers and mark it as "answered" as appropriate.

  • Question record DNS SRV + VCS Expressway

    Hi all

    I have a South, VCS in the DMZ, and I am facing a problem with the SRV DNS records.

    VCS Expressway Hostname:-VCSe

    Domain: example.com

    FULL VCSE domain name: VCSe.example.com

    and I have an a record set up for the same FQDN in DNS Public Server.

    I have a sip domain configured as 'cisco.com' in my VCS Expressway.

    What is the SRV records, I need to create in the Public DNS server.

    Kind regards

    Nikhil Jayan

    Nikhil,

    It seems that you have not checked the link I sent you earlier... A very explicit documents. in any case that we talked about earlier is we were talking about signs send calls to the highway as well as parts of the record.

    In your deployment, you have a different domain for DNS and SIP domain. Also as you say you meet Highway cluster and you want to record to both endpoints and then I suggest you to check the document for the creation of cluster on cisco webesite.

    Now, if you have a cluster for Highway then you must create several srv records that would be pointing to each domain name FULL of the approved cluster with equal weight. In normal use scneario of domain common to different services are recommended.

    Srv records would have seen something like that.

    _sips._tcp.company.com. 86400 IN SRV 1 1 5061 vcse1.company.com.

    _sips._tcp.company.com. 86400 IN SRV 1 1 5061 vcse2.company.com.

    _sip._tcp.company.com. 86400 IN SRV 1 1 5060 vcse1.company.com.

    _sip._tcp.company.com. 86400 IN SRV 1 1 5060 vcse2.company.com.

    _h323ls._udp.company.com. 86400 IN SRV 1 1 1719 vcse1.company.com.

    _h323ls._udp.company.com. 86400 IN SRV 1 1 1719 vcse2.company.com.

    _h323cs._tcp.company.com. 86400 IN SRV 1 1 1720 vcse1.company.com.

    _h323cs._tcp.company.com. 86400 IN SRV 1 1 1720 vcse2.company.com.

    _h323rs._udp.company.com. 86400 IN SRV 1 1 1719 vcse1.company.com.

    _h323rs._udp.company.com. 86400 IN SRV 1 1 1719 vcse2.company.com.

    However, your case is different. In your deplyoment what you have to do is any request for the domain "cisco.com" should be resolved in FQDN of the VCS-Highway peers with equal weight.

    for example

    _tcp.gmail.com. IN SRV 20 0 5222     talk2.l.google.com.

    Therefore, any request to gmail.com would resolve to the talk2.1.google.com server.

    same way you have to make it work.

    Thank you

    Alok

  • VCS Expressway outside to endpoints internal call

    I have a new implementation where internal control 1 to VCS in LAN and VCS Expressway in DMZ 1.

    VCS Expressway has an IP public address/NAT.

    Currently, we have a group of VC endpoint, each endpoint has a public IP/NAT to the local network, to allow internet to make H.323 call directly by public IP address of the composition of the endpoint.

    My question is, after having implemented VCS Expressway in DMZ, how do the numbering plan at each endpoint internal VCS Highway outside call? Do I still need to give to each endpoint an ip/NAT publich.

    Thank you very much.

    A much simpler and in my opinion, more elegant and more scalable solution would be not to use IP addresses for calls, but to allocate and register outcomes with E.164 alias. That way you all you need is the internal IP address.

    So the outer ends may, in this case, call your settings using the [email protected] / * / or [email protected] / * /-E_IP_address.

    Internal assessment criteria can call each other using alias only for as long you have the rules of research in place, and cannot therefore have the external ends you will allow to record with you VCS-E for one reason or another.

    If you have the outcomes of Polycom external with the old version of the software that does not support Annex O URI component, then it's very simple to include a transformation of prior research on the VCS-E which will allow these settings call using owners 'numbering URI "; VCS-E_IP_address ##Alias - and if you, on the odd occasion, a final point which cannot use anything other than IP addresses, you can configure the alias of relief on the VCS-E to point to a specific or a standard automatic on a MCU, purpose etc.

    A dial plan using as above will also allow you to use DHCP addresses, the alias remains static, and that's what counts, addresses much simpler to give to people. e.g. 123456 is much easier to remember than 202.138.98.23 etc, not to mention the IPv6 addresses, and because you save your settings with domain name, and then customers SIP will also be able to connect very easily.

    /Jens

  • ESXi and MMIC to VCS CE500

    Hello, I m quite confuse about running on a CE500 VCS.

    I have never installed one of these, but it says it works on UCS-C220-M3L.

    The installation guide has a table with MMIC as future use and the procedure indicates that the KVM will lead to the prompt of VCS.

    Issues related to the:

    -Is the MMIC (Mgmt interface) available and configurable than other C220-M3 servers?

    -Is that VCS, a virtual machine running on a hidden ESXi? If so, is there a way to reach the ESXi interface?

    Thank you

    As far as I know Yes, you should be able to set up CIMC as any other UCS, but there is no ESXi, this is a bare metal installation.

  • VCS ExpressWay and control over the different Versions

    Hello world

    Can be used on a newer VCS Highway then control VCS?

    Currently we have a highway of VCS and a tester of VCS X6.1 running. I plan to upgrade to X7.2.1 and will temporarily have the South, the new version with the old version running control.

    I don't see any documentation that may not be completed. Especially since X7.2.1 had interop tests already performed with X6.x.

    Mark

    Hi Mark,

    Please check the following page 8, section "Prerequisites", document

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Basic_Configuration_Control_with_Expressway_Deployment_Guide_X7-2.PDF

    Prerequisites

    Before you begin the configuration of the system, make sure that you have access to:

    -Guide the administrator of VCS and VCS Getting Started Guide (for reference purposes)

    -control of VCS running the version X 5 or later

    -a PC connected by Ethernet to a local network that allows to route HTTP (S) traffic to the VCS

    -a web browser runs on the PC

    -a serial interface on the PC and the cable (if the initial configuration must be performed on the interface series)

    Answer to your question, there is no problem if VCSE and VCSC installed on versions of different software.

  • Client Jabber Viceo registry for VCS/MSDS

    Hello

    I am trying to record a video jabber VCS or TMS customer but his does not work. Whenever I was

    "Bad username, domain and/or password". Check spelling and caps lock.

    Do not know why. Should what I do to register a customer with username and password? VCSC and VCSe are configured for access from inside and outside VCSe.

    Is there a guide for video Jabber clients?

    Best regards

    Jason

    Hi Jason!

    You need a starter pack of VCS-highway or TMS (license + Movi licenses) and a VCS (with the option of commissioning key device).

    As you write VCSe and c its more likely that you do not have the starter pack.

    She has need of configuration and user creation, so it would work not just out of the box.

    The recommended method is the TMSPE, you will find here the deployment guide:

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/tmspe/Install_Guide/Cisco_TMSPE_Deployment_Guide_1-0.PDF

    If you have older versions of TMS/VCS you will use it (but I recommend you upgrade and use TMSPE!):

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/TMS/config_guide/Cisco_TMS_Provisioning_Deployment_Guide_13-0.PDF

    In addition to this documentation Cisco for TMS, VCS and JabberVideo control.

    TMS:

    http://www.Cisco.com/en/us/products/ps11338/tsd_products_support_series_home.html

    VCS:

    http://www.Cisco.com/en/us/products/ps11337/tsd_products_support_series_home.html

    JabberVideo:

    http://www.Cisco.com/en/us/products/ps11328/tsd_products_support_series_home.html

    Jason: Please note the validations and define the thread if it's an answer!

Maybe you are looking for