Sunteți pe pagina 1din 100

CCIE Collaboration -

Troubleshooting Jabber Login


Devasayee Gopalan
Ishan Sambhi
LABCCIE-3022
Agenda
• Accessing the Lab
• MRA Solution Overview
• Deployment Scenarios
• MRA Solution Configuration (This section is already completed in this lab)
• Getting ready
• VCS Expressway Configuration
• VCS Control Configuration
• Unified CM Configuration
• IM&P Server Configuration
• Firewall Configuration

• Troubleshooting Jabber Login


Accessing the Lab
• VPN Details
 Open Cisco Any Connect VPN client
 Enter the Server IP address “72.163.218.175”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Accessing the Lab
• Go to Settings ; Uncheck the “Block Connections to untrusted servers”
• Check the “Allow local (LAN) access when using VPN (if configured)”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Accessing the Lab

• Click on “Connect”. When it prompts for username & password login with the
following credentials
• Username : ciscolive1
• Password : ciscolive1

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Accessing the Lab

• Once connected , you can access the below Servers :


• Windows PC RDP : 192.168.X.14
• VCS-C : 192.168.X.10
• VCSE : 192.168.X.11
• IM&P : 192.168.X.22
• CUCM : 192.168.X.23
• All servers Username / password : admin / ciscolive
• Windows PC login : administrator / Cisco,123
• The X in the 3rd octet would be the VLAN number of your POD and will be provided to you
by the proctor
LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Accessing the Lab

• When accessing servers from each other for example when the CUCM
has to reach out to the VCS . Please use the below IP addresses :
• VCSC - 192.168.105.10
• VCSE - 192.168.105.11
• Int PC : 192.168.105.15
• Ext PC : 192.168.105.14
• CUCM : 192.168.105.23
• IMP : 192.168.105.22
• Note : Do not use the IP’s in the previous slide when accessing the
servers from each other

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
MRA Solution Overview
Mobile and Remote Access
 The mobile and remote access solution supports a hybrid on-premise and cloud-based
service model, providing a consistent experience inside and outside the enterprise. It
provides a secure connection for Jabber application traffic without having to connect to
the corporate network over a VPN.

AnyConnect VPN

Unified CM
&
applications
Expressway
Firewall Traversal
LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
MRA Solution Overview
Mobile and Remote Access
 It is a device and operating system agnostic solution for Cisco Unified Client Services
Framework clients on Windows, Mac, iOS and Android platforms
• Session-based firewall traversal
• Allows access to collaboration applications ONLY
 It allows Jabber clients that are outside the enterprise to:
• use instant messaging and presence services
• make voice and video calls
• search the corporate directory
• share content
• launch a web conference
• access visual voicemail

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
MRA Solution Overview
Mobile and Remote Access
 HTTPS proxy for secure provisioning of endpoints
 SIP/TLS, RTP/SRTP for audio/video media
 XCP router in the Edge for IM&P for Jabber
 Visual Voicemail (REST/HTTPS) supported with HTTPS Directory Access (8.6.2
UDS/HTTPS) supported with HTTPS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
MRA Solution Overview
Requirement
 Support Version
Software Version Status
VCS X8.1 or later version
Unified CM 9.1.2 or later version
• Unified IM&P 9.1.1 or later version

9.7 or later version (* 9.6 support it as experimental but require additional


Jabber for Windows
configuration, refer to slide 123 for more detail)

| 9.6.1 or later version with minimum iOS6.1


Jabber for iPad/iPhone
(* iPhone4 only support audio call)
• Jabber for MAC 9.7.2
EX/MX series Endpoint TC7.1.0 or later version

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Deployment Scenarios
Single network elements
 In this scenario there are single (non-clustered) Unified CM, IM & Presence, VCS
Control and VCS Expressway servers (or combination of Expressway-C and
Expressway-E)

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Deployment Scenarios
Single clustered network elements
 In this scenario each network element is clustered Unified CM, IM & Presence, VCS
Control and VCS Expressway servers (or combination of Expressway-C and
Expressway-E)

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Deployment Scenarios
Multiple clustered network elements
 In this scenario there are multiple clusters of each network element of Unified CM,
IM & Presence, VCS Control and VCS Expressway servers (or combination of
Expressway-C and Expressway-E)

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Deployment Scenarios
Hybrid deployment
 In this scenario, IM and Presence services for Jabber clients are provided via the
WebEx cloud and registered on Unified CM via VCS Control and VCS Expressway
servers (or combination of Expressway-C and Expressway-E)

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
MRA Solution Configuration
Deployment Scenario
• In this lab we are going to use single network element deployment model.
• Single SIP domain deployment
• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway VCS Control Single-Node CUCM Single-Node IMP


expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
MRA Solution Configuration
External DNS Configuration
Note : This step has been already completed for this lab

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway VCS Control Single-Node CUCM Single-Node IMP


SRV Record: cucm.ciscolive.com cups.ciscolive.com
expressway.ciscolive.com
control.ciscolive.com

Note : This step has been * FQDN & IP Address listed above are just sample for configuration reference
already completed for this lab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
MRA Solution Configuration
Configure SRV record – External DNS
Note : This step has been already completed for this lab
Service Protocol Port Record Definition/Host
_collab-edge TLS 8443 expressway.ciscolive.com

 External DNS Record (for general deployment not specifically Mobile and Remote
Access service)
 Configure A/AAAA record as needed

Service Protocol Port Record Definition/Host


_sips TCP 5061 expressway.ciscolive.com
_sip TCP 5060 expressway.ciscolive.com

Note : This step has been


* FQDN & IP Address listed above are just sample for configuration reference
already completed for this lab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
MRA Solution Configuration
Internal DNS Configuration
Note : This step has been already completed for this lab

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

Cluster VCS Expressway Cluster VCS Control Single-Node CUCM Single-Node IMP
expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

Note : This step has been already


* FQDN & IP Address listed above are just sample for configuration reference
completed for this lab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
MRA Solution Configuration
Configure SRV record – Internal DNS
Note : This step has been already completed for this lab
Service Protocol Port Record Definition/Host
_cuplogin TCP 8443 cups.ciscolive.com
_cisco-uds TCP 8443 cucm.ciscolive.com
_sips TCP 5061 cucm.ciscolive.com
_sip TCP 5060 cucm.ciscolive.com
_sip UDP 5060 cucm.ciscolive.com

 Configure A/AAAA record as needed


IMPORTANT: Make sure _cuplogin SRV/FQDN record is NOT resolvable outside of
internal network otherwise Jabber client won’t start Mobile and Remote Access
negotiation via VCS Expressway (or Expressway-E).
Note : This step has been * FQDN & IP Address listed above are just sample for configuration reference
already completed for this lab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing CUCM Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing CUCM Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing CUCM Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM
On the IM&P Server - Integrating IM&P with CUCM

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Integrating IM&P with CUCM


Password : ciscolive

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Integrating IM&P with CUCM


CUCM Security Password : ciscolive

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Integrating IM&P with CUCM

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing IM&P Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing IM&P Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Changing IM&P Hostname to IP

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Configuring
TFTP
Server on
IM&P

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Login to the IM&P Server


using putty to restart the
server

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Restart the
IM&P Server

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Login to the IM&P


server and go to
the Serviceability
tab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
MRA Solution Configuration
• Getting Ready – Integrating IM&P and CUCM

Ensure that all services on the IM&P are activated

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
MRA Solution Configuration Go back to the
Administration
page on the
• Getting Ready – Integrating IM&P and CUCM IM&P Server

Go to System -> Cluster and see


if things are green , ignore the
Cisco XCP Message Archiver
service

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
MRA Solution Configuration
VCS Expressway Configuration

• Single SIP domain deployment


• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway Cluster VCS Control Single-Node CUCM Single-Node IMP


expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
MRA Solution Configuration
VCS Expressway Configuration
• System host name and domain name
 Ensure host name and domain name are specified for every VCS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
MRA Solution Configuration
VCS Expressway Configuration
 Ensure that VCS is Synchronized on every VCS . If NTP is not synchronized over
traversal it may lead to a lot of problems

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
MRA Solution Configuration
VCS Expressway Configuration
• Server Certificate

 Install appropriate serve certificates and trusted CA certificates for TLS traversal session
between VCS Control
• This deployment requires secure communication between VCS Control

Note : This step has been


already completed for this
lab
LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
MRA Solution Configuration
VCS Expressway Configuration
• Mobile and Remote Access
 Enable Mobile and remote access feature from
Configuration > Unified Communications > Configuration

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
MRA Solution Configuration
VCS Expressway Configuration
• Traversal Zone
 Create TLS verify enable Unified Communications traversal zone between VCS
Control and enable Mobile and remote access

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
MRA Solution Configuration
VCS Expressway Configuration
• Traversal Zone
 Create TLS verify enable Unified Communications traversal zone between VCS
Control and enable Mobile and remote access – Create a new User for Traversal
Authentication

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
MRA Solution Configuration
VCS Expressway
Configuration
• Traversal Zone
 Create TLS verify enable
Unified Communications
traversal zone between
VCS Control and enable
Mobile and remote access
– Create a new User for
Traversal Authentication

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
MRA Solution Configuration
VCS Expressway Configuration
• Traversal Zone
 Create TLS verify enable Unified Communications traversal zone between VCS
Control and enable Mobile and remote access – Create a new User for Traversal
Authentication

User the Password - ciscolive

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
MRA Solution Configuration
VCS Expressway Configuration
• Traversal Zone
 Create TLS verify enable traversal zone between VCS Control and enable Mobile and
remote access
 Use the below setting on the Traversal Server Configuration

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
MRA Solution Configuration
Please verify this step at the end of all
VCS Expressway Configuration the configuration – This wont be active
unless the configuration on the VCSC is
• Unified Communications Status completed
 After all configurations, Unified Communication status should shows…
• Unified Communications mode: Enabled
• Unified Communication service: Active
• Zone (Sip status): Active

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
MRA Solution Configuration
VCS Control Configuration
• Solution Configuration - Deployment Scenarios
• Single SIP domain deployment
• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway VCS Control Single-Node CUCM Single-Node IMP


expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
MRA Solution Configuration
VCS Control Configuration
• System host name and domain name
 Ensure host name and domain name are specified for every VCS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
MRA Solution Configuration
VCS Control Configuration
• DNS Server on the VCS control
 Ensure the DNS server is the 192.168.X.15 DNS sever , if not configured please
configure and Flush DNS cache

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
MRA Solution Configuration
VCS Control Configuration
 Ensure that VCS is Synchronized on every VCS . If NTP is not synchronized over
traversal it may lead to a lot of problems

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
MRA Solution Configuration
VCS Control Configuration
• Server Certificate
 Install appropriate serve certificates and trusted CA certificates for TLS traversal session between
VCS Expressway
• This deployment requires secure communication between VCS Control and Expressway
• For detail of certificate creation and deployment, please refer to “Cisco VCS Certificate Creation
and Use Deployment Guide”

Note : This step has been


already completed for this lab

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
MRA Solution Configuration
VCS Control Configuration
• Mobile and Remote Access
 Enable Mobile and remote access feature from Configuration > Unified Communications
> Configuration

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
MRA Solution Configuration
VCS Control Configuration
• Configure Unified CM servers
 Add Unified Communication server used for remote access from Configuration >
Unified Communications > Unified CM servers
 Step 1: Click “New”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
MRA Solution Configuration
VCS Control Configuration
• Configure Unified CM servers
 Step 2: Entre Unified CM publisher address, AXL Web service username and password,
then click “Add address”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
MRA Solution Configuration
VCS Control Configuration
• Configure Unified CM servers
 VCS automatically negotiate SIP link between Unified CM
• Depending on Unified CM configuration, link establishes with TCP or TLS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
MRA Solution Configuration
VCS Control Configuration
• Neighbor zone between Unified CM
 Non-configurable neighbor zone “CEtcp-<UCMName>” or/and “CEtls-<UCMName>”
automatically created after configure Unified CM servers

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
MRA Solution Configuration
VCS Control Configuration
• Search rule pointing to Unified CM
 Non-configurable search rule “CEtcp-<UCMName>” or/and “CEtls-<UCMName>” automatically
created after configure Unified CM servers

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
MRA Solution Configuration
VCS Control Configuration
• Configure IM and Presence server
 Add IM and Presence used for remote access from
Configuration > Unified Communications > IM and Presence servers
 Step 1: Click “New”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
MRA Solution Configuration
VCS Control Configuration
• Configure IM and Presence server
 Step 2: Add publisher FQDN, AXL Web service username and password, then click
“Add address”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
MRA Solution Configuration
VCS Control Configuration
• Configure IM and Presence server
 Configured IM and Presence server will add on VCS and status shows as “Active”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
MRA Solution Configuration
VCS Control Configuration
• Traversal Zone
 Create TLS verify enable Unified Communication traversal zone between VCS
Expressway and enable Mobile and remote access

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
MRA Solution Configuration
VCS Control Configuration
• Traversal Zone
 Create TLS verify enable traversal zone between VCS Expressway and enable
Mobile and remote access
Username : traversal
Password : ciscolive

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
MRA Solution Configuration
VCS Control Configuration
• Traversal Zone
 Create TLS verify enable traversal zone between VCS Expressway and enable
Mobile and remote access

• Enable Mobile and remote access: “Yes”


• Entire FQDN of each VCS Expressway

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
MRA Solution Configuration
VCS Control Configuration
• SIP domain to route to Unified CM
 Configure the domains for registration, call control, provisioning, messaging and
presence services are to be routed to Unified CM from Configuration > Domains
(select target domain and click “View/Edit”)
 Enable feature to route to Unified CM

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
MRA Solution Configuration
VCS Control Configuration
• Zone Status
 After all configurations, traversal zone status should shows “Active”
(require to complete VCS Expressway configuration before zone status become
active)

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
MRA Solution Configuration
VCS Control Configuration
• Unified Communications Status
 After all configurations, Unified Communication status should shows…
• Unified Communications mode: Enabled
• Unified Communication service: Active
• Zone (Sip status): Active

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
MRA Solution Configuration
Unified CM Configuration
• Solution Configuration - Deployment Scenarios
• Single SIP domain deployment
• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway VCS Control Single-Node CUCM Single-Node IMP


expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
MRA Solution Configuration
Unified CM Configuration
• Maximum Session Bit Rate
 Ensure that the Maximum Session Bit Rate for Video Calls and Audio Bit Rate
between and within region is set to a suitable upper limit (i.e. 6000kbps and
Wideband) System > Region

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
MRA Solution Configuration
Unified CM Configuration
• End User Configuration
 Enable user for Unified CM IM and Presence service with appropriate profile – In this
lab you can use the “Non” UC Service Profile”

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
MRA Solution Configuration
Unified CM Configuration You may need to associate the device(CSF) after
creating it on the CUCM
• End User Configuration
 Associated user with appropriate Controlled Devices

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
MRA Solution Configuration
Unified CM Configuration
• End User Configuration
 Make sure “Standard CCM End Users” and “Standard CTI Enabled” add as Access
Control Group

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
MRA Solution Configuration
Unified CM Configuration
• Phone Configuration
 Add Phone with appropriate profile and DN

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
MRA Solution Configuration
Unified CM Configuration
• Phone Configuration
 Device owner user ID must be mapped on the device to link the service profile
 If owner user ID is not specified, user will use the default service profile

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
MRA Solution Configuration
Unified CM Configuration
• Phone Configuration
 Add owner user ID in “Associate End Users” under Directory Number Configuration

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
MRA Solution Configuration
IM&P Server Configuration
• Solution Configuration - Deployment Scenarios
• Single SIP domain deployment
• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

VCS Expressway VCS Control Single-Node CUCM Single-Node IMP


expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
MRA Solution Configuration
IM&P Server Configuration
• User Profile sync status
 Check user profile created on Unified CM properly sync
System > Cluster Topology

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
MRA Solution Configuration
Firewall Configuration
• Solution Configuration- Deployment Scenario
• Single SIP domain deployment
• Simple deployment with single UDS and IMP server

Jabber Client External DNS VCS Expressway VCS Control Internal DNS CUCM Home UDS IM&P Server

Cluster VCS Expressway Cluster VCS Control Single-Node CUCM Single-Node IMP
expressway.ciscolive.com SRV Record: cucm.ciscolive.com cups.ciscolive.com
control.ciscolive.com

* FQDN & IP Address listed above are just sample for configuration reference

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
MRA Solution Configuration
Firewall Configuration
• Port usage: VCS Control to VCS Expressway
DMZ
Internet
IM&P
CUCM-UDS VCS Control VCS Expressway
VCS Control VCS Expressway
Source Port Listening Port
TLSA = Configurable TCP Outbound ports range
Management Control Inbound and outbound calls

Open Firewall Private to DMZ


TLSB = Configurable traversal port for traversal link between Control
and Expressway (i.e. 7001, 7002, etc.)
IP address of IP address of
IP Address
- VCS Control - VCS Expressway
Ue = Configurable TCP ephemeral port range
TCP Ue
XMPP (IM and Presence) TCP 7400
30000 to 35999 *
YC = Configurable traversal media ports range (on Control/C)
SSH TCP Ue
TCP 2222
(HTTP/S tunnels) 30000 to 35999 *
YE = Configurable traversal media ports range (on Expressway/E)
TCP & TLSA TCP & TLSB
IP Ports

SIP signaling
25000 to 29999 7001
* Default ephemeral ports range (X8.1) for is 30000 – 35999 which
SIP media
UDP YC UDP YE configurable
30002 to 35999 ** 36000 to 36001**

TURN server control UDP source port UDP 3478 *** ** Default media ports range (X8.1) is 36000 – 59999 which
configurable

Note : This step has been *** Default TURN request listening port. For large scale deployment,
default port range is 3478-3483
already completed for this lab LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
MRA Solution Configuration
Firewall Configuration
• Port usage: VCS Expressway to/from Public Internet
DMZ
Internet
IM&P
CUCM-UDS VCS Control VCS Expressway
VCS Expressway Internet SIP UA
Source Port Listening Port
N = VCS wait unit it receives media, then it sends its media to the IP
Management Control Outbound to SIP UA in the Internet port from which media was received (egress port of the media from
Open Firewall DMZ to Internet the far end non SIP-aware firewall)

IP address of IP address of S = Source port, typically >=1024


IP Address
- VCS Expressway - Any (or specific IP)

XMPP (IM and Presence) N/A N/A YE = Configurable traversal media ports range (on Expressway/E)
UDS
N/A N/A
(Provisioning and Phonebook) ** Default media ports range (X8.1) is 36000 – 59999 which
TURN Server Control N/A N/A
configurable

TLS TLS S
IP Ports

SIP signaling
25000 to 29999 >= 1024

UDP YE UDP N
Media
36000 to 59999 ** >= 1024

Note : This step has been already


completed for this lab
LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
MRA Solution Configuration
Firewall Configuration
• Port usage: VCS Expressway to/from Public Internet
DMZ
Internet
IM&P
CUCM-UDS VCS Control VCS Expressway
VCS Expressway Internet SIP UA
Listening Port Source Port
N = VCS wait unit it receives media, then it sends its media to the IP
Management Control Inbound from SIP UA in the Internet
port from which media was received (egress port of the media from
Open Firewall Internet to DMZ the far end non SIP-aware firewall)
IP address of IP address of
IP Address
- VCS Expressway - Any (or specific IP) S = Source port, typically >=1024
TCP S
XMPP (IM and Presence) TCP 5222
>= 1024 YE = Configurable traversal media ports range (on Expressway/E)
UDS TCP S
(Provisioning and Phonebook)
TCP 8443
>= 1024 ** Default media ports range (X8.1) is 36000 – 59999 which
UDP S
configurable
TURN Server Control UDP 3478 ***
>= 1024
IP Ports

*** Default TURN request listening port. For large scale deployment,
TLS S
SIP signaling TLS 5061 default port range is 3478-3483
>= 1024

UDP YE UDP N
Media
36002 to 59999 ** >= 1024

Note : This step has been already


completed for this lab
LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
MRA Solution Configuration
Internal port usage
• Port usage: VCS Control to Unified CM and IM&P
DMZ
IM&P
Internet
CUCM-UDS VCS Control VCS Expressway

Management System VCS Control


Listening Port Source Port Ue = Configurable TCP ephemeral port range
Management Control Private Network
* Default ephemeral ports range (X8.1) for is 30000 – 35999 which
Open Firewall N/A
configurable
IP address of
IP address of
- VCS Control
IP Address - Unified CM
- IM & Presence Server

TCP 7400 TCP Ue


XMPP (IM and Presence)
(IM&P Server) 30000 to 35999 *

UDS TCP 8443 TCP Ue


(Provisioning and Phonebook) (CUCM Server) 30000 to 35999 *
IP Ports

TCP 6970 TCP Ue


TFTP
(TFTP Server) 30000 to 35999 *

TCP 443 TCP Ue


CUC (Voicemail)
(CUC server) 30000 to 35999 *

Note : This step has been already


completed for this lab LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
MRA Solution Configuration
Jabber for Windows
• IMP base deployment

Phone service is not yet ready

Entre IMP user ID and password Client attempting logon over MRA Logon…, attempting UCM registration

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
MRA Solution Configuration
Registration Status
• Jabber for Windows registered on Home-UDS

Jabber Client External VCS VCS Internal


“liveuser” CUCM TFTP IM&P
DNS Expressway Control DNS Home Server Server
UDS

Phone registered on CUCM and ready for phone service

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
MRA Solution Configuration
Registration Status
• Jabber for Windows registered on Home-UDS

Jabber Client Internal CUCM IM&P


External VCS VCS DNS TFTP Server
“liveuser” DNS Expressway Control Home Server
UDS

Phone registered on CUCM and ready for phone service


Detail status available from Help > Show connection status

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Troubleshooting Jabber Login
Step 1
 If Jabber Displays “Cannot Communicate with Server “ , try clearing Jabber Cache from the
Local PC
 To Clear Jabber Cache : Go to Start -> Run and go to %APPDATA%
 Go into both Local and Roaming folders and within Cisco folder delete Unified Communications
folder

 Path :C:\Users\administrator\AppData\Local\Cisco\Unified Communications


 C:\Users\administrator\AppData\Roaming\Cisco\Unified Communications

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Troubleshooting Jabber Login
Step 2 :
 Verify DNS SRV records on the external PC and the VCS-C
 From the external PC try using nslookup , set type=srv and perform an SRV lookup for
_collab-edge._tls.ciscolive.com – this should resolve to expressway.ciscolive.com
 On the VCS-C use the DNS Lookup tool to check for _cuplogin._tcp.ciscolive.com ,_cisco-
uds._tcp.cisco.com and for expressway.ciscolive.com
 DNS Lookup Utility on the VCS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Troubleshooting Jabber Login
Step 2 : (Continued)
 Result

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Troubleshooting Jabber Login
Step 2 : ( Continued )
 Ifyou do not get the above results , make sure the right DNS Server is
configured on the VCS-C , under System -> DNS

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Troubleshooting Jabber Login
Step 3 :
 Make sure that IMP Server is active and reachable

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Troubleshooting Jabber Login
Step 3 : (Continued)
 If you see the below error Output

 Restart XCP Router Service on the IMP Server and refresh the IMP Servers
from the VCS-C

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Troubleshooting Jabber Login
Step 4:
 IfNTP is not synchronised and the traversal is created - it may cause issues and
you see an X-Auth token expired error in the Jabber PRT
 To resolve this issue :
 Synchronise NTP on the C and E to preferably the same source at the same
stratum ( preferably Stratum 3 and lower ) and recreate the traversal server /
traversal client zones

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Troubleshooting Jabber Login
Step 5:
 IfLogin is still failing , collect Diagnostic logs from the VCS-C and VCS-E for a
failed Jabber Login attempt and work with the proctor to review them
 To capture logs:
 Go to Maintenance -> Diagnostics -> Diagnostic Logging

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Troubleshooting Jabber Login
Step 5:
 Click on Start New Log

 Recreate the issue & Click Stop Logging

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Troubleshooting Jabber Login
Step 5: (Continued)
 Click on Download Log and Save

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Complete Your Online Session Evaluation
• Please complete your Online
Session Evaluations after each
session
• Complete 4 Session Evaluations &
the Overall Conference Evaluation
(available from Thursday) to receive
your Cisco Live T-shirt
• All surveys can be completed via
the Cisco Live Mobile App or the
Don’t forget: Cisco Live sessions will be available
Communication Stations for viewing on-demand after the event at
CiscoLive.com/Online

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Lunch & Learn
• Meet the Engineer 1:1 meetings
• Related sessions

LABCCIE-3200 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Thank You

S-ar putea să vă placă și