Showing posts with label Cisco CUCM/Call Manager. Show all posts
Showing posts with label Cisco CUCM/Call Manager. Show all posts

Friday, 21 April 2023

Thursday, 20 April 2023

Sunday, 20 March 2022

CA automatic enterprise CA endpoint Certificate enroll

 


MMC.exe

Console I - [Console Root] 
File Action Viewu Favorites 
Console Root 
Windowu 
Help 
Name 
Add or Remove Snap-ins 
There are no items to shouu in this viewu. 
Actions 
More Actions 
You can select snap-ins For this console From those available on your computer and configure the selected set OF snap-ins. For 
extensible snap-ins, you can configure which extensions are enabled. 
Available snap-ins: 
Vendor 
Snap-in 
Microsoft Cor.. 
Active Directory Do... 
Active Directory Site... Microsoft Cor.. 
Microsoft Cor... 
Active Directory Use... 
ActiveX Control 
Microsoft Cor... 
2 
AD51 Edit 
Microsoft Cor... 
Authorization Manager 
Microsoft Cor... 
Certificate Templates 
Microsoft Cor... 
Certificates 
Microsoft Cor.. 
Certification Authority 
Microsoft Cor... 
Microsoft Cor.. 
Component Services 
Microsoft Cor... 
Computer Managem. 
Microsoft Cor.. 
Device Manager 
Disk Management 
Microsoft and.. 
Description: 
Selected snap-ins: 
Console Root 
Certificate Templates 
Certification Authority (Local) 
Add > 
Edit Extensions... 
Remove 
Move up 
Move Down 
Advanced... 
Allows you to configure certification authority properties and to manage certificates issued by this CA.

 

Action Viewu Favorites Windowu 
Insole Root 
Help 
Certificate Templates (CA. cloud.cisco.com) 
Certification Authority (Local) 
Template Display Name 
Administrator 
Authenticated Session 
Basic EFS 
CA Exchange 
CEP Encryption 
ciscoratemplate 
ClientServer 
Code Signing 
Computer 
Cross Certification Authority 
Directory Email Replication 
Domain Controller 
Domain Controller Authentication 
EFS Recovery Agent 
Enrollment Agent 
Enrollment Agent (Computer) 
Exchange Enrollment Agent (Offline 
Exchange Signature Only 
Exchange user 
IPSec (Offline request) 
Kerberos Authentication 
Key Recovery Agent 
OCSP Response Signing 
RAS and IAS Server 
Root Certification Authority 
Router (Offline request) 
Smartcard Logon 
Smartcard user 
Subordinate Certification Authority 
Trust List Signing 
Properties of Neuu Template 
Subiect Name 
Superseded Templates 
Server 
Issuance Requirements 
Extensions 
Security 
Compatibility General Request Handling Cryptography Key Attestation 
Actions 
Certificate Tem lates CA.dc10L 
More Actions 
ClientServer 
More Actions 
T emplate display name: 
ciscoratemplate 
T emplate name: 
ciscoratem late 
Validity period: 
Renewal period: 
8 weeks 
Publish certificate in Active Directory 
Do not automatically reenroll if a duplicate certificate exists in Active 
Directory 
Cancel 
uthentication 
uthentication 
uthentication, Smart Card Logon 
uthentication, Smart Card Logon, KD 
uthentication

 

Console Root 
Certificate Templates (CA.dcIoud.cisco.com) 
Certification Authority (Local) 
Template Display Name 
Administrator 
Authenticated Session 
Basic EFS 
CA Exchange 
CEP Encryption 
ciscoratemplate 
ClientServer 
Code Signing 
Computer 
Cross Certification Authority 
Directory Email Replication 
Domain Controller 
Domain Controller Authentication 
EFS Recovery Agent 
Enrollment Agent 
Enrollment Agent (Computer) 
Exchange Enrollment Agent (Offline 
Exchange Signature Only 
Exchange user 
IPSec (Offline request) 
Kerberos Authentication 
Key Recovery Agent 
OCSP Response Signing 
RAS and IAS Server 
Root Certification Authority 
Router (Offline request) 
Smartcard Logon 
Smartcard user 
Subordinate Certification Authority 
Trust List Signing 
Properties of Neuu Template 
Subiect Name 
Server 
Issuance Requirements 
Compatibility General Request Handling Cryptography Key Attestation 
Superseded Templates 
Group or user names: 
Authenticated users 
Administrator 
Extensions 
a 
cisco ra (ciscora@dcloudciscocom) 
Domain Admins (D CLOUD SD omain Admins) 
Enterprise Admins (DCLOLlD\Enterprise Admins) 
Permissions for cisco ra 
Full Control 
Enroll 
Autoenroll 
For special permissions or advanced settings, click 
Advanced 
Cancel 
Security 
uthentication 
uthentication 
uthentication, Smart Card Lc 
uthentication, Smart Card Lc 
Advanced 
uthentication

 

Console I - [Console Root\Certification Authority Templates] 
File Action Viewu Favorites Windowu Help 
zdl 
Console Root 
Certificate Templates (CA.dcIoud.cisco.com) 
Certification Authority (Local) 
dcIoud-CA 
Revoked Certificates 
Issued Certificates 
Pending Requests 
Failed Requests 
Certificate Temp at 
> cenøne temmate to 
Name 
ciscoratemplate 
ClientServer 
Web Server 5y 
Directory Email Replication 
Domain Controller Authentication 
Kerberos Authentication 
EFS Recovery Agent 
Basic EFS 
Domain Controller 
Web Server 
Computer 
Subordinate Certification Authority 
Administrator 
Intended Purpose 
Client Authentication, Server Authentic... 
Server Authentication, Client Authentic... 
Server Authentication 
Directory Service Email Replication 
Client Authentication, Server Authentic... 
Client Authentication, Server Authentic... 
File Recovery 
Encrypting File System 
Client Authentication, Server Authentic... 
Server Authentication 
Client Authentication, Server Authentic... 
Encrypting File System, Secure Email, Cl... 
Microsoft. Trust List Signing, Encrypting...

stop then start the service

 

Internet Information Services (IIS) Manager 
CA Sites Default Web Site 
File Viewu Help 
Connections 
Start Page 
CA (DCLOLlD\Administrator) 
Application Pools 
Default Web Site Home 
Shouu All 
Group by: 
ASP.NET 
.NET 
Authorizat... 
Providers 
ASP 
.NET 
Compilation 
http 
Session State S 
Edit Site Binding 
Host name: 
Area 
IP address: 
All Unassigned 
Pages and 
Controls 
Port: 
Authentic... 
co 
Require Server Name Indication 
SSL certificate: 
ca.dcloud.cisco.com 
MIME Types Modules 
ctions 
Explore 
Edit Permissions... 
Edit Site 
Basic Settings... 
Viewu Applications 
Viewu Virtual Directories 
Manage Website 
Browse Website 
Brouuse w:BO (http) 
Brouuse (https) 
Advanced Settings... 
Configure 
Failed Request Tracing... 
Cancel 
Management 
Configurat... 
Features Viewu 
Content Viewu

CUCM : 

Upload root cert as CAPF-Trust

un•nea 
CISCO 
For Cisco Unified 
;how • ietllr,ga 
List 
Generate Self-signed 
Status 
32 records found 
operanng system Aamlrustranon 
Solutions 
Upload Certificate/Certificate chain - Mozilla Firefox 
Upload 
Status 
https://cucm 1 .dcloud. 
'cm platform/certificateupload.do 
cisco.com 
Certificate/certif•cdte chain 
Close 
Certificate List 
Find Certificate List "here 
- 3? of 3 
(1 
Certific 
cucml. 
cucml .dcloud. 
-EC .dclo 
(D 
Warning: Uploading a cluster-nide certificate "ill distribute it to all servers in this cluster 
Upload Certificate/ Certificate chain 
C e rd ficate 
CallManager 
CallManager- 
ECOSA 
CallManager- 
CallManager- 
CallManager- 
CallManager- 
CallManager- 
CallManager- 
CallManager- 
AUTHZ 
cucml 
ACT 2 SLIDI C 
CAP-RTP-002 
dcIoud-CA 
Cisco Manufa 
Cisco Root CA 
CAP-RTP-001 
Certificate Purpose 
Description(friendly name) 
Upload File 
- indicates required item. 
CAPF-trust 
Bronsa„ 
certnen.cer 
Cisco ManufacturinQ 
CA 
RSA 
RSA 
CAP-RTP-OOI 
Cisco _ Manufacturing 
CA 
Issued 
I.dcloud.cisco.com 
cloud.cisco.com 
CA 2048 
CA M? 
CA 2048 
CAP-RTP-001 
cisco Root CA 2048

 

CAPF-trust is used for CAPF/cisco registration authority via https toIIS. Callmanager-trust is used for trust of LSC cert(secured tftp)

[40 
Generate Self-signed 
Status 
10 records found 
Certificate List 
Upload CertificateCediticate chain 
[40 
Generate CSR 
(1 
Find Certificate List "here 
- 10 of ro) 
Certificate 
C e rd ficate 
CAPF-trust 
CAPF-trust 
ZAPF-trust 
CAPF-trust 
CAPF-trust 
CAPF-trust 
CAPF-trust 
CAPF-trust 
ACT 2 
Common Name 
-81acc25e 
SLIDI CA 
begins with 
CA-signed 
CA-signed 
cucml.dcloud.cisco.com 
ACT 2 
SLIDI CA 
Clear Filter 
Cisco 
RSA 
RSA 
RSA 
RSA 
RSA 
RSA 
RSA 
RSA 
RSA 
Issued 
-81acc25e 
Root CA 
CAP-RTP-002 
dcIoud-CA 
Cisco Root 
CA 2048 
CAP-RTP-002 
dcIoud-CA 
Cisco Root CA 
CAP-RTP-001 
2048 
CAP-RTP-001 
CAP-RTP-002 
dcIoud-CA 
Cisco Root CA 
CAP-RTP-001 
CA 
2048 
2048 
2048 
Cisco 
Cisco 
ManufacturinQ 
Root CA M? 
-81acc25e 
Cisco _ Manufacturing 
Cisco 
Root CA M? 
-81acc25e 
CA 
Cisco 
Cisco 
Root CA 
Root CA 
-81acc25e 
Expiratio 
01/10/2023 
05/14/2029 
10/10/2023 
11/10/2028 
11/12/2037 
05/14/2029 
02/06/2023 
05/14/2029 
11/12/2037 
01/10/2023

 

Cisco 
CISCO 
For 
Routing 
Um fled 
CM Administration 
Unified Communications Solutions 
Media Fesc•urcea Advanced Features 
Applicatic•r, 
l_Eer Management • 
aulk 
Help 
Service Parameter Configuration 
Save 
Set to Detaut 
— Status 
Status: Ready 
—Select Server and Service 
Server 
Service 
cucmI.dcIoud.cisco.com--CLlCM Voice/ Video (Activi 
Cisco Certificate Authority Proxy Function (Active) 
All parameters apply only to the current server except parameters that are in the cluster-nide group(s). 
—Cisco Certificate Authority Proxy Function (Active) Parameters on server cucmI.dcIoud.cisco.com--CUCM Voice/ Video (Active) 
Parameter Name 
Certificate Issuer to Endooint 
Duration Of Certificate Validity tin 
Kev Size 
Maximum Allowable Time For Kev 
days) 
Generation 
Maximum Allowable Attemots for Kev Generation 
Online CA Parameters 
Online CA Hostname 
Online CA Port. 
Online CA Temolate 
Online CA Tuoe 
Online CA Username 
Online CA Password 
- indicates required item. 
Parameter galue 
Online CA 
1024 
ca.dcloud.cisco.com 
443 
ciscoratemplate 
Microsoft. CA 
cisc•ra I OCA123! 
(D 
* *The Set-to-Oefault button restores all parameters that have been modified to their original default values.

 

restart Cisco Certificate Authority Proxy Function

 

LCS installation,only for hardware phone

 

CUCM enables mix mode 

admin:utils ctl set-cluster mixed-mode

 

This operation will set the cluster to Mixed mode. Auto-registration is enabled on at least one CM node. Do you want to continue? (y/n): y

 

restart Callmanager service

 

Phone

Certification Authority Proxy Function (CAPF) Information 
Certificate Operation 
Authentication Mode 
Authentication String 
enerate Strin 
Key Order 
RSA Key size 
EC Key size (Bits) 
Operation Completes ay 
Certificate Operation 
Note: Security Profile 
Install/l_lpgrade 
ay Null String 
RSA only 
2048 
Status: Operation 
Contains Addition 
12 
pending 
CAPF settings.

if CSF  also add

Protocol Specific Information 
Packet Capture Mode 
Packet Capture Duration 
BLF Presence Group 
SIP Dial Rules 
Device Security Profile 
eruu e 
SUBSCRIBE calling search space 
SIP Profile 
Digest User 
None 
Standard Presence group 
None > 
LIOT-Encrypted-NuIIString.dcIoud.cisco.com 
Main-css 
Main-css 
Standard SIP Profile 
None > 
View Details 
Media Termination Point Required 
Unattended Port. 
Require OTMF Reception

 

Find and List Phones 
Add New From Template 
Status 
8 records found 
Phone 
Find Phone "here Device Name 
Lsc Issued ay 
Device Name (Line) 
CSFAMCKENZIE 
CSFAPEREZ 
CSFMCHENG 
CSFWWHITMAN 
SEPAOAOAOAOAOAO 
SEPAIAIAIAIAIAI 
SEPA2A2A2A2A2A2 
SEPA3A3A3A3A3A3 
Clear All 
Delete Selected 
Reset Selected 
2 
Apply Contig to Selected 
Clear Filter 
begins 
begins 
CSF for Adam 
McKenzie 
with 
with 
Select 
item 
or 
enter 
search 
text 
Lsc status 
Upgrade 
Success 
Upgrade 
Success 
None 
None 
None 
None 
None 
None 
Lsc Issued 
dcIoud-CA 
dcIoud-CA 
Lsc Issuer Ex 
11/10/2028 
11/10/2028 
CAPF Auth 
String 
12/04/2024 
12/04/2024 
Related Links: 
cucml.dcloud.cisco 
cucml.dcloud.cisco 
cucml.dcloud.cisco 
CSF for Anita Perez 
CSF for Monica 
CSF for walt 
Whitman 
8845 for Adam 
Mckenzie 
8845 for Monica 
8845 for Walt 
Whitman 
8845 for Anita Perez 
status 
Registered 
Registered 
Registered 
Rejected 
None 
None 
None 
None 
Regist 
Non 
Non 
Non 
Add 
New 
\+14085551116 
\+19195552132 
\+14085551119 
\+19195552130 
\+14085551116 
\+14085551119 
\+19195552130 
\+19195552132 
Reset Selected 
amckenzie 
nnhitman 
amckenzie 
nnhitman 
Add New 
From Template 
Select All 
Clear All 
Delete Selected 
Apply 
Config to Selected


SIP OAuth (line side) on-prim Jabber Encrypted Call

SIP OAuth (line side) on-prim Jabber Encrypted Call

 

CUCM12 no need for mix mode

UnityCN:


 

Cisco Unit-y Connection Administration 
CISCO 
For Cisco Unified 
Cisco Unity Connectio 
tor•nmunications Solutions 
Cisco Syslog Agent 
Unified Messaging Accounts Statu: 
SpeechViel,w Transcription 
Video Services 
Video Services Accounts Status 
Dial Plan 
Partitions 
Search Spaces 
System Settings 
General Configuration 
Cluster 
Authentication Rules 
Restriction Tables 
Licenses 
Schedules 
Holiday Schedules 
Global Nicknames 
Subject Line Formats 
Attachment Descriptions 
Service Parameters 
Fax Server 
S slo Severit 
For Remote S slo 
messa es 
LOAP 
SAML 
Authz 
Cross 
SMTP 
Single Sign on 
Servers 
-Origin Resource 
Configuration 
Sharing (C 
Advanced 
Telephony Integrations 
Phone System 
Port. Group 
Port. 
Speech Connect Port. 
Trunk 
Security 
Tools 
Task Management 
CUCReports Parameters 
Re ort. Socket Connection Timeout 
Re ort. Socket Read Timeout 
Mgcp Trace Log Configuration 
Enable M c Trace Lo 
Call Trace Log Configuration for Session Trace 
Enable Call Trace Lo 
Max Number of Call Trace Lo Files 
Call Trace LOQ File Size {Ma) 
Cisco Jabber 
Never Start. Call with Video 
Cisco Directory Number Alias 
OSCP for LOAP tall services usinQ Directory Number Alias Dort) 
SSO and OAuth Configuration 
OAuth Access Token Exoiru Timer {minutes) 
Jabber OAuth Refresh Token Exoiru Timer [days) 
Physical Phone OAuth Refresh Token Exoiru Timer [days) 
Redirect LIRIs for Third Part. SSO Client 
SSO Lo in Behavior for iOS 
Disabled 
Enabled 
default oscp (000000) 
use embedded browser (WebViel,w) 
Enabled 
Disabled 
Enabled 
default oscp (000000) 
use embedded browser (WebViel,w) 
Disabled 
OAuth with Refresh 
use SSO for RTMT 
Directory Search 
Lo in Flow 
Parameters

check jabber voicemail button

 

CUCM 

admin:utils sipOAuth-mode enable

SIP OAuth Mode already enabled.

 

restart callmanager service

CISCO 
Cisco Unit-y Connection Administration 
For Cisco Unified 
tor•nmunications Solutions 
Cisco Unity Connection 
Mailbox Stores 
Mailbox Stores Membership 
Mailbox Quotas 
Message Aging 
Networking 
Legacy Links 
Branch Management 
HTTP(s) Links 
Locations 
Connection Location Passwords 
Unified Messaging 
Unified Messaging Services 
Unified Messaging Accounts Statu: 
SpeechViel,w Transcription 
Video Services 
Video Services Accounts Status 
Dial Plan 
Partitions 
Search Spaces 
General Configuration 
Cluster 
Authentication Rules 
Restriction Tables 
Licenses 
Schedules 
Holiday Schedules 
Global Nicknames 
Subject Line Formats 
Attachment Descriptions 
Enterprise Parameters 
Service Parameters 
Fax Server 
LOAP 
SAML Single Sign on 
Cross-origin Resource Sharing (C 
Edit Authz Server 
Authz Servers 
Refresh 
Edit Authz Server 
Display Name* 
Authz Server* 
Port* 
Username* 
Password* 
ucml.dcloud.cisco.com 
cucml.dcloud.cisco.com 
8443 
administrator 
Ignore Certificate Errors 
Fields marked with an asterisk ( * ) are required. Cisco unified CM Administration 
CISCO 
For Cisco Unified tommunications Solutions 
Call Media Fesc•urcea Advanced Features 
Enteronse Parameters Configuration 
Applicatic•r, 
l_Eer Management • 
aulk 
Enabled 
Insecure 
3804 
Disable 
Help 
Save 
Apply Contig 
cluster security mooe m 
cluster SIP 
O Auth 
Mode 
LaM Security Mode 
CAPF Phone Port 
CAPF Ooeration Exoires in [days) 
Endooint Advanced Encruotion AIQorithms Suooort_ 
T FTP File Sianature AIQorithm 
Enable CachinQ 
Authentication Method for API Browser Access 
TLS ciDhers 
All Ciphers RSA Preferred 
Insecure 
3804 
Disable 
All Ciphers RSA Preft

 

System > Security >  Phone Security Profile 

Call Media Fesc•urcea 
Phone Security Profile Configuration 
Save 
Status 
Status: Ready 
Phone Security Profile Information 
Advanced Features 
Apply Contig 
Applicatic•r, 
l_Eer Management • 
aulk 
Help 
Add New 
Product Type: 
Device Protocol: 
Name 
Description 
Protocol Not Specified 
UOT-Jabber-SIPOAuth 
Encrypted with SIP OAuth (LIOT-based) 
Device Security Mode Encrypted 
T FTP Encrypted Config 
Enable OAuth Authentication 
Phone Security Profile CAPF Information 
Authentication Mode 
Key Order 
RSA Key size 
EC Key size (Bits) 
ay Null String 
RSA only 
2048 
None > 
Note: These fields are related to the CAPF Information settings on the Phone Configuration page. 
Save 
(D 
- indicates 
required 
Apply Config 
item. 
Add New

 

Cisco unified CM Administration 
CISCO 
For Cisco Unified tommunications Solutions 
Call Media Fesc•urcea Advanced Features 
Applicatic•r, 
l_Eer Management • 
aulk 
Phone Configuration 
Save 
2 
Apply Contig 
Add New 
BLF Presence Group 
SIP Dial Rules 
MT P Preferred Originating Codec 
Device Security Profile 
SUBSCRIBE calling search space 
Standard Presence group 
None > 
711ulaI,w 
UOT-Jabber-SIPOAuth 
Main-css 
Main-css 
Standard SIP Profile 
None > 
Help 
View Details 
SIP Profile 
Digest User 
Media Termination 
Point Required

 

Anita Perez 
Anita 
Anita Perez 
ococn 
VCAM 
MAOV

 

 

Wednesday, 24 April 2019

Cisco CMS Clustering and Redundancy

Cisco CMS Clustering and Redundancy

Create Database Master on CMS1

Enter the command: database cluster localnode a
Then enter the command: database cluster initialize
Confirm enter: Y

Connect Second and third CMS to Master

Enter the command: database cluster localnode a
Then enter the command: database cluster join CMS1_IP
Confirm join by entering: Y
Run command: database cluster upgrade_schema

Verify cluster status



Create Call Bridge Cluster


Three Callbridges


Create CallbridgeGroups


Assign callBridgeGrou “HO” to each callBridge

callBridgeGroup loadbanance

Monday, 25 March 2019

Extension Mobility / Extension Mobility Cross Cluster (EM/EMCC)

Extension Mobility / Extension Mobility Cross Cluster
(EM/EMCC)

Prior to certificate consolidation, start with the cluster ID naming and Certificate export/consolidate/import is already in place for two clusters
EMCC devices available per cluster is already set to 100. Assumption is that no more than 100 EMCC users will be concurrently visiting the same cluster and use EMCC, if this is the case, it’s safe to increase the limit to 500 EMCC device. This change from 100 to 500 will not cause any IP Phone interruption.
  1. Add EMCC IP Phone Service:
Where X.X.X.X represents the IP Address of the CUCM node where EM service is activated/started.
Make sure to enable “Enterprise Subscription”, this check box will appear once only when a new service is added.
Enable EM on IP Phones:

  1. Create one partition and create one calling search space, assign the created partition to the created calling search space for emergency calling.


  1. Create extension mobility User Device Profile for end users. On the Device Profile Configuration page, for the “Extension Mobility Cross Cluster CSS” assign the CSS created in step 3.

  1. On the end user page assign the EM profile and enable EMCC


And

  1. Add emergency route pattern(s). Partition accessible by the calling search space assigned to UDP “Extension Mobility Cross Cluster CSS”. The Gateway/Route List MUST point to a Standard Local Route Group.


  1. Add Geo location filter to match:
  1. add/update GEO Location configuration. Example of GEO Location:

  1. On all IP Phone Device Pools, add the GEO Location Configuration created. Do not apply any GEO Location filter here.



  1. Add Roaming GEO Location configuration that will match the GEO Location configuration set on the visiting phone. This is necessary to place the visiting IP Phone in the correct Roaming device pool.



  1. Add Roaming Device Pool and apply the filter. Roaming device pool must reflect the correct time zone of the visiting cluster. Apply the GEO Location filter here. On the same Roaming device pool, make sure the correct Media Resource Group list is selected.


  1. Create EMCC SIP Trunk. Critical: the Trunk’s Inbound CSS MUST have access the emergency Route Pattern(s) partition used by the users on the visiting cluster.

  1. EMCC Feature Configuration. EMCC Region Max Audio Bit Rate value must be the same on all cluster participating in the EMCC network.


  1. EMCC Inter-cluster Service Profile. Validation must be successful.

  1. Configure Cluster View. EMCC/TFTP enabled.


Tuesday, 19 March 2019

SME - Global Dial Plan Replication(GDPR)

Session Management Edition  -- Global Dial Plan Replication(GDPR)

A Global Cisco Unified Communications Session Management Edition (Unified CM SME) which is a trunk and dial plan aggregation component for multi-site distributed call processing deployments. The Global SME is essentially a Cisco Unified Call Manager Cluster with trunk interfaces and no IP endpoints. It enables aggregation of multiple Cisco communications telephony systems, known as leaf clusters.
Centralized routing diagram
Main purpose
  • Centralize dial plan
  • Connectivity to 3rd party session management
  • Dial Patterns dynamics (automation)
Server Function for CUCM will fit into one or more of the following feature sets:
  • Publisher
  • Subscriber

Publisher Service Activation
Servers
Service Name
Activation Status
Publisher
This server is responsible for all of the administration updates to the other servers in the cluster. It must communicate with all other servers.

Additionally this server is used for the following functions:
  • AXL-based communications
  • Remote monitoring(SNMP)
  • directory synchronization with the AD environment using Cisco DirSync (if enabled)
  • Bulk updates using the Cisco Bulk Provisioning Service

Due to the administration overhead, Call control (Cisco CallManager), TFTP (Cisco TFTP) and media resource (Cisco IP Voice Media Streaming Application) functionality has been disabled, as to prevent CPU over-utilization.
Encryption services are also disabled, as this feature is not being deployed.
Cisco CallManager
Deactivated
Cisco Messaging Interface
Deactivated
Cisco Unified Mobile Voice Access Service
Deactivated
Cisco IP Voice Media Streaming App
Deactivated
Cisco CTIManager
Deactivated
Cisco Extension Mobility
Deactivated
Cisco Extended Functions
Deactivated
Cisco DHCP Monitor Service
Deactivated
Cisco Intercluster Lookup Service
Activated
Cisco Dialed Number Analyzer Server
Activated
Cisco Dialed Number Analyzer
Activated
Cisco TFTP
Deactivated
Cisco IP Manager Assistant
Deactivated
Cisco WebDialer Web Service
Deactivated
Cisco SOAP - CDRonDemand Service
Deactivated
Cisco CAR Web Service
Deactivated
Platform SOAP Services
Activated
Cisco AXL Web Service
Activated
Cisco UXL Web Service
Activated
Cisco Bulk Provisioning Service
Activated
Cisco TAPS Service
Deactivated
Cisco Serviceability Reporter
Activated
Cisco CallManager SNMP Service
Activated
Cisco CTL Provider Activated
Deactivated
Cisco Certificate Authority Proxy Function
Deactivated
Cisco DirSync
Activated

Subscriber Service Activation
Servers
Service Name
Activation Status
Subscribers
** Cisco AXL Web Service  will only be enabled for Sub1 and Sub2 on each cluster

All Subscribers
  • Cisco CallManager service is enabled
  • Cisco CallManager SNMP Service is enabled
  • Cisco Web Dialler Web Service is enabled
  • Cisco Extended Functions are enabled
Cisco CallManager
Activated
Cisco Messaging Interface
Deactivated
Cisco IP Voice Media Streaming App
Deactivated
Cisco CTIManager
Deactivated
Cisco Extension Mobility
Deactivated
Cisco Extended Functions
Activated
Cisco DHCP Monitor Service
Deactivated
Cisco Dialed Number Analyzer Server
Deactivated
Cisco Dialed Number Analyzer
Deactivated
Cisco TFTP
Deactivated
Cisco IP Manager Assistant
Deactivated
Cisco WebDialer Web Service
Deactivated
Cisco SOAP Services
Deactivated
Cisco AXL Web Service
Activated**
Cisco UXL Web Service
Deactivated
Cisco TAPS Service
Deactivated
Cisco Serviceability Reporter
Deactivated
Cisco CallManager SNMP Service
Activated
Cisco CTL Provider
Deactivated

To ensure that the endpoints’ codec preferences are trusted as calls pass through SME, enable the SIP Profile feature “Accept Audio Codec Preferences in Received Offer” on all SIP Trunks.

Global Dial Plan Replication – GDPR and ILS

Intercluster lookup Service

(ILS)
The Intercluster Lookup Service (ILS) feature is used to interconnect multiple clusters together.  With the ILS cluster discovery service it provides clusters to dynamically learn about remote clusters within the ILS network.  ILS also supports the Global Dial Plan Replication (GDPR) feature. ILS and GDRP work together to dynamically share the global dial plan with all clusters within the ILS network.

Global Dial Plan Replication

(GDPR)

The Global Dial Plan Replication (GDPR) feature uses the ILS feature to share dial plan information between clusters within the ILS network.  The information is captured by a centralized hub cluster which then propagates to all connected spoke clusters.



Menu: Advance Features > ILS Configurations; Select Role: For SME: ‘Hub Cluster’

Leaf clusters: ‘Spoke Cluster’


In the ‘ILS Cluster Registration’ pop up window, input in ‘Registration Server’: For SME: leave blank and click OK; For Leaf: Enter IP of Publisher node of hub cluster and click OK


Input check for ‘Exchange Global Dial Plan Replication Data with remote Clusters’


Enter route string for Cluster, which will populate, to all clusters within the ILS network.  Keep default of 10 minutes for ‘Synchronize Clusters Every’ field. Route string naming convention:The route string will be a combination of Cluster ID + ‘.ils’.  Example: ClusterXXX.ils


For ILS Authentication there are two options to choose from, via TLS certificates or by password.  The Password would be the same entered on all clusters.


ILS network Verification

Once you have the first two networks configured, Hub and a spoke, verify connectivity at top of page.  You may need to click on refresh button a few times. You can also temporary reduce ‘Synchronize Clusters Every’ to 1 minute.  The screen capture below indicates there is 1 hub and 1 spoke.

View from Hub:

View from Spoke:


Partitions for Learned Numbers and Patterns


Configure SIP route patterns

Call Routing > SIP Route Pattern

For SME:  create a SIP Pattern for each cluster it is connected to and assign the associated trunk for that clusters.  



For Leafs: You only need to create one SIP Pattern in each leaf.



ILS Service Parameter configuration

Determine the required max number of learned objects.  



ILS advertises locally configured enterprise alternate numbers and +E.164 alternate numbers to the ILS network where the Advertise globally via ILS option has been selected.

Click:  Add Enterprise Alternate Number