Cisco Virtual Office: Secure Voice and Video
|
|
|
- Easter Whitehead
- 10 years ago
- Views:
Transcription
1 Deployment Guide Cisco Virtual Office: Secure Voice and Video The scope of this deployment guide is to provide detailed design and implementation information for deploying highly secure voice and video with Cisco Virtual Office. Please refer to the Cisco Virtual Office overview for further information about the solution, its architecture, and all the related components Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 1 of 19
2 Contents 1. Introduction Secure Voice and Video Deployment Available Bandwidth and Network Quality Quality of Service Authentication Configuration File Voice and Video Deployment Scenarios SCCP Based Phone Deployment SIP Based Phone Deployment Physical Phone Deployment SoftPhone Deployment Video End Points Deployment Cisco Telepresence E20/EX60/EX Cisco CP Cisco CP Cisco Movi Cisco UC Integration for Microsoft Office Communicator (CUCIMOC) Wireless IP Phone Deployment CVO Voice and Video Traffic Classification Appendix CVO QOS Policies and Configurations Creating MAB Authorization Policies in ACS References Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 2 of 19
3 1. Introduction Cisco Virtual Office (CVO) is a highly secure end-to-end solution that brings enterprise-quality voice, video, wireless, and data into the home and remote offices. It is designed to bring unified communications to employees' home offices, increasing their satisfaction and productivity. This deployment guide covers the deployment of highly secure, voice and video in a CVO environment. For a complete list of supported and recommended products and images, please refer to the CVO Datasheet. 2. Secure Voice and Video Deployment The first step in deploying voice and video is to secure the network endpoint by enabling Cisco Virtual Office layered security features on the Cisco IOS Software of ISR G2 and establishing the trust and authorization of the end devices. Network security will be provided using the Cisco ISR G2 sitting behind the ISP-provided broadband modem. The IP Security (IPsec) with Triple Digital Encryption Standard (3DES) or Advanced Encryption Standard (AES) for encryption is used by ISR G2 to make the connection secure. The CVO uses hierarchical QoS mechanism to provide shaping and Low Latency Queuing (LLQ), allowing for simultaneous use of voice, video and data services without compromising on the quality of services, and allowing for the prioritization of real-time and latency-sensitive traffic such as voice and video. The Network Based Application Recognition (NBAR) is also used to perform deep packet analysis. The NBAR determines the protocol used in the packet such as SIP, SCCP, H.323, etc. By using NBAR and QoS, the Cisco Virtual Office router makes sure that voice and video services are correctly prioritized and external heavy bandwidth applications do not cause degradation of the quality of voice and video. This section summarizes the integration of network security, voice, and video. 2.1 Available Bandwidth and Network Quality Usually the residential broadband connections provide good downlink speed but are not so generous with the uplink speed. During a voice call, traffic gets generated from the talking party to the listener. The bandwidth usage depends on the codec being used. The popular ones are G.729 and G.711. G.729 uses low bandwidth but is more sensitive to jitter and packet loss. G.711 uses higher bandwidth but can tolerate packet loss better. To accommodate generic routing encapsulation (GRE)/IP Security (IPsec) overhead entailed by the use of DMVPN in CVO, the bandwidth on each direction should be at least 128 kbps for G.711 and 80 kbps for G.729. However, to accommodate for data traffic and ISP network congestion, it is recommended to have a minimum of 256kbps in each direction to avoid any voice related problems. Video calls consume lot more bandwidth than voice calls and require broadband services that can provide high uplink speed. The H263 and H264 are the most popular codecs that are used by video end points. H264 codec is used by default in Cisco supported end points. These codecs require different bandwidth depending on the resolution, size and the Frames per Second (FPS) used by the video end points. For example, a minimum 1Mbps uplink and downlink will be required for VGA 640x480 resolution using 30 fps. Similarly, for High Definition 720P video calls with 1280x720 resolutions and 30 fps will require minimum 2Mbps bandwidth in each direction Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 3 of 19
4 2.2 Quality of Service The residential broadband connectivity does not usually have any QoS enabled; it is a best effort network. But QoS can be applied on the CVO spoke router so that voice, video and other essential traffic gets a higher priority to use the uplink bandwidth. Regular data packets are given a lower priority. If the CVO router is sitting behind another broadband termination device (for example, a cable modem), enabling traffic shaping will prevent the router from sending more traffic than the link can carry. For example, if a Cisco 881 ISR is connected behind a cable modem, the modem s uplink will get congested long before the Cisco 881 router s outbound Ethernet interface is congested. If the traffic-shaping value is configured appropriately, the Cisco 881 router will not send more traffic than the modem can forward without dropping packets. In the case of video IP phones, video traffic needs to be prioritized accordingly. The following configuration on a CVO spoke router such as 881 or 891 was used to match the traffic using a Cisco IOS Software feature called Network Based Application Recognition (NBAR). NBAR allows the network to provide differentiated services to each application. It ensures performance for mission critical applications. One can provide absolute priority and guaranteed bandwidth to his mission-critical applications and then do the respective packet matching. class-map match-any NBAR_MAP_TP match protocol telepresence-media match protocol telepresence-control class-map match-any NBAR_MAP_Tandberg match access-group name NBAR_MAP_Tandberg class-map match-any NBAR_MAP_Video match access-group name Movi match access-group name CUVA match protocol rtp payload-type "97" match access-group name NBAR_MAP_Video class-map match-any NBAR_MAP_VoIP match access-group name Cisco_phone_voice_video match protocol rtp audio class-map match-any NBAR_MAP_Signaling match protocol skinny match protocol sip class-map match-all NBAR_MAP_Scavenger match access-group name NBAR_MAP_Scavenger policy-map NBAR_SET class NBAR_MAP_TP set ip dscp cs2 class NBAR_MAP_Tandberg 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 4 of 19
5 set dscp cs4 class NBAR_MAP_Video set dscp cs2 class NBAR_MAP_VoIP set ip precedence 5 class NBAR_MAP_Signaling set ip precedence 3 class NBAR_MAP_Scavenger set ip precedence 1 class class-default set dscp default 2.3 Authentication Cisco Virtual Office routers can be configured with user/device authentication such as Authentication Proxy (authproxy) and IEEE 802.1x. With the authentication proxy feature, users can log in to the network or access the Internet via HTTP, and their specific access profiles are automatically retrieved and applied from a CiscoSecure ACS, or RADIUS, or TACACS+ authentication servers. The 802.1x-based authentication is used to authenticate hosts connecting to the Ethernet switch ports of the CVO router. Deploying this feature in CVO ensures that only authenticated hosts can gain access to the VPN. Unauthenticated hosts can only access the Internet. This is particularly helpful for separating "spouse and kids" computers from employee computers. When 802.1x is enabled, Cisco IP phone can use 802.1x to authenticate. The Cisco Discovery Protocol (CDP) can be used to bypass 802.1x. MAC authentication bypass (MAB) can also be used to bypass 802.1x. For 3rd party phones, MAB can be used to authenticate. When 802.1x is not enabled, CDP can still be used to detect Cisco IP phones and place them on the voice VLAN (separate from the data VLAN). The following 881 configuration shows 802.1x configurations for an IP phone:! Using 802.1x authenticated in an AAA aaa group server radius dot1x server-private <aaa> auth-port 1812 acct-port 1813 key 0 <key> ip radius source-interface Vlan10! aaa authentication dot1x default group dot1x aaa authorization network default group dot1x!! Enable dot1x feature globally dot1x system-auth-control! interface Vlan10 description Data VLAN to used with wireless ip address Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 5 of 19
6 no ip redirects no ip unreachable no ip proxy-arp ip pim sparse-dense-mode ip nat inside ip inspect test in ip virtual-reassembly ip tcp adjust-mss 1360 no autostate tms-class!adding a voice VLAN. interface Vlan11 description Voice VLAN ip unnumbered Vlan10 ip access-group allow_skinny_acl in ip inspect voice_fw in no autostate! interface Vlan20 description Guest VLAN ip address ip pim sparse-dense-mode ip nat inside ip inspect test in ip virtual-reassembly no autostate interface FastEthernet0 switchport access vlan 10 switchport voice vlan 11 dot1x pae authenticator dot1x port-control auto dot1x reauthentication dot1x mac-auth-bypass 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 6 of 19
7 dot1x timeout quiet-period 1 dot1x timeout tx-period 1 dot1x max-req 1 dot1x reauthentication dot1x guest-vlan 20 spanning-tree portfast Note: The same configuration defined in interface F0 should be configured on the rest of the switchports. The command dot1x mac-auth-bypass should be configured to enable MAB. In addition, for non-cisco phones, the correct voice vlan should be pushed from the ACS server and device-traffic-class=voice av-pair should be configured in ACS as part of the 802.1x MAB authorization. 2.4 Configuration File When Cisco IP phone or Cisco Unified Personal Communicator (CUPC) boots up, it downloads a configuration file from a Trivial File Transfer Protocol (TFTP) server. The IP address of this TFTP server can be statically configured on the IP phone or downloaded as a Dynamic Host Configuration Protocol (DHCP) option 150. Using the DHCP option is more viable option from a management perspective. The following configuration example is based on the Cisco 881 router: ip dhcp pool client import all network dns-server <corp. DNS server> <ISP DNS server> default-router domain-name mycorp.com option 150 ip <TFTP server s address > <netbios-name-server <Corp. NETBIOS servers> update arp 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 7 of 19
8 3. Voice and Video Deployment Scenarios The Cisco Virtual Office solution supports both SCCP and Session Initiation Protocol (SIP) based VoIP deployments. The following VoIP deployment cases are supported SCCP Based Phone Deployment Cisco IP phones with SCCP support use TCP port 2000 to communicate with the primary and secondary Cisco Unified Communications Manager. Support for SCCP or SIP on the IP phones depends upon the firmware being used SIP Based Phone Deployment The SIP IP phone deployment is the same as the SCCP deployment. The Cisco IP phones with SIP support uses tcp and udp port 5060 to communicate with primary and secondary Cisco Unified Communications Manager. Some of the Cisco phones such as 7960G, 8945, 6921 and 6941 supports both skinny and sip images. The port 5060 must be opened in the CVO to register the IP phones to CUCM. 3.3 Physical Phone Deployment The Cisco 7960G and 7970G IP phones are the flagship VoIP physical phone solutions provided by Cisco. There is no difference between the phones for either of the phones from a secure voice deployment perspective. Once the Cisco Virtual Office router is configured, as mentioned in the previous section, the IP phone (if already registered and configured on Cisco Unified Communications Manager) is ready to be plugged in behind the router, and it will start working without any changes. The various aspects mentioned in the initial setup need to be configured for good-quality VoIP deployment and also for successful configuration of an IP phone on Cisco Unified Communications Manager. Other Cisco VoIP-based phones, such as the Cisco Unified IP Phone 7975G, can also be used. 3.4 SoftPhone Deployment Cisco Unified Personal Communicator is a VoIP Cisco IP SoftPhone and can be configured as an SCCP or SIP client. Cisco Discovery Protocol support is not needed for Cisco IP Communicator to work, and once the PC is authenticated and gets an IP address from the corporate pool, Cisco IP Communicator should work. The authproxy bypass configuration used for regular IP phones will also work for Cisco IP Communicator. 3.5 Video End Points Deployment Cisco Telepresence E20/EX60/EX90 The CVO supports multiple Tandberg video end points. However, the recommended end points are E20, EX60 and EX90. The IP Video Phone E20 is a business quality personal video conferencing unit that allows for a fully integrated video experience. The CUCM 8.5 and above is required to support native connectivity for E20. A minimum of 1.0Mbps bandwidth is required to make standard video calls using E20. E20 can support a maximum resolution of 768 x 448@30fps (w448p) and requires minimum of 1.5Mbps to support high resolution video calls. The EX Series provides a high quality HD 1080P 30fps video. The EX series streamlines your desk and your communication with one PC screen, video and phone. The CUCM 8.6 and above is required to provide a native support for EX series. The EX series requires high bandwidth due to its high resolution. A minimum of 3.5 Mbps 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 8 of 19
9 bandwidth is required for HD 720P calls. For HD 1080p, a minimum bandwidth of 6Mpbs is required for good quality video calls. Cisco Telepresence call control manager VCS can also be used to provide call control service for voice and video for the above video endpoints. Cisco VCSX 6.1 and above should be used to deploy these endpoints. Note: The Telepresence software Release TC4.1 and later builds should be used for video points to work with CUCM 8.5 and VCSX 6.1. The above Telepresence video end points use the multiple ranges of UDP ports that should be matched by the QoS policy. Following QOS policies must be applied on the CVO spoke to provide good quality video. ip access-list extended NBAR_MAP_Tandberg permit udp any range any dscp 35 permit udp any range any dscp 35 permit udp any range any dscp 35 class-map match-any NBAR_MAP_Tandberg match access-group name NBAR_MAP_Tandberg policy-map NBAR_SET class NBAR_MAP_Tandberg set dscp cs4 class-map match-any QOS_TP_Tandberg match ip dscp cs2 match ip dscp cs4 match ip precedence 4 policy-map CSM_POLICY_MAP_HR_1 class class-default shape average policy-map CSM_POLICY_MAP_1 class QOS_TP_Tandberg bandwidth 4915 queue-limit 256 packets class class-default no fair-queue policy-map CSM_POLICY_MAP_HR_1 class class-default service-policy CSM_POLICY_MAP_1 In case Auth Proxy is being enabled, then following ports must be opened in ACL auth_proxy_inbound_acl Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 9 of 19
10 ip access-list extended auth_proxy_inbound_acl permit udp any range any permit udp any range any permit udp any range any permit udp any any range permit tcp any range any (Only one way voice/video if not added) permit tcp any any range permit udp any range any permit tcp any any eq 6970 (only for Tandberg E20 Series)! Cisco CP-9971 The Cisco Unified IP Phone 9971 delivers high-quality advanced interactive multimedia communications. The phone has large backlit, vibrant high-resolution 640 x 480 pixel fully-adjustable color display. The phone requires Cisco Unified Video Camera to provide interactive video. The phone has both wireless and Bluetooth and provides high-definition voice (HD voice) to provide greater clarity in communications. The CP-9971 supports the SIP protocol. Hence, if Auth Proxy is being enabled then both 5060 and 5061 port must be opened in the auth proxy access list to register the phone with the CUCM. The following configurations needed to be added in the Auth Proxy access list to open the relevant ports: permit udp any any range permit tcp any any range Cisco CP-8945 The Cisco Unified IP Phone 8945 delivers comprehensive multimedia features and capabilities, including real-time video communications and low power consumption. The phone has a built-in, VGA-quality video camera that supports up to 30 frames per second and has a high-resolution 5-inch color display (VGA). The phone supports both SIP and SCCP image. In case the SIP image is used and Auth Proxy is enabled then both 5060 and 5061 port must be opened in the access list to register the phone with the CUCM.. Please refer to access-lists configuration required for CP Cisco Movi Movi offers a cost-effective, easy to use video solution. It allows teleworkers to stay visually connected to colleagues, customers or suppliers. With only an existing computer and a USB Camera, thousands of users in a video-enabled enterprise can connect from public spaces or remote offices whenever they need. Compared with consumer-based PC video solutions, Movi offers unparalleled quality, reliability and ease of use. Movi is a standards-based solution, and it is interoperable with the rest of an enterprise video deployment Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 10 of 19
11 Movi is a SIP based client. If Auth proxy is enabled then some additional ports need to be open in order to make the device register with the CUCM. The following configurations needed to be added in the Auth Proxy access list to open the relevant ports: permit udp any range any permit udp any any range permit tcp any range any permit tcp any any range permit udp any range any permit udp any range any (required for MOVI) Cisco UC Integration for Microsoft Office Communicator (CUCIMOC) CUCIMOC is a soft phone client integration for Microsoft Office Communicator (MOC). It is used for both voice and video calls. CUCIMOC client can be integrated with both SCCP and SIP phones. The user can make voice and video calls through CUCI MOC soft phone or through desk phone. If Auth proxy is enabled then some additional ports need to be open in order to make the device register with the CUCM. The following configurations needed to be added in the Auth Proxy access list to open the relevant ports: permit udp any range any permit udp any any range permit tcp any range any permit tcp any any range permit udp any range any 3.6 Wireless IP Phone Deployment The Cisco Unified IP Phone CP-9971 have a built-in a/b/g Wireless-fidelity (Wi-Fi) radio. The phone can be configured as either wired or wireless mode. An external power should be connected to phone to enable Wi-Fi and configure wireless settings. If the phone is getting power through PoE then the Wi-Fi will not be enabled. This phone supports different wireless authentication such as Wired Equivalent Privacy (WEP), and LEAP, EAP-FAST etc. After the wireless authentication step is completed, the phone will register with Cisco Unified Communications Manager as a regular IP phone would, and will be ready for use Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 11 of 19
12 4. CVO Voice and Video Traffic Classification Following traffic classifications must be followed for Video end points. End Points NBAR Match QOS Policies CIUS UDP/ for Voice (Prec 5) Payload 97 for Video (CS4) Priority Queue (128K) CBFWQ (384K) CUVA UDP/5445; CS4 CBFWQ (384K) CP-9900 Series CP-8900 Series UDP/ for Voice (Prec. 5) Payload 97 for Video (CS4) Priority Queue (128K) CBFWQ (384K) MOVI UDP/ (CS2) CBFWQ (1Mbps) Tandberg MXP1700 Tandberg E20 Tandberg EX Series UDP/ DSCP CS2 UDP/ (CS4) DSCP CS2 UDP/ DSCP CS4 CBFWQ (1Mbps) CBFWQ (1Mbps) CBFWQ (1Mbps) 5. Appendix 5.1 CVO QOS Policies and Configurations The section lists down the recommended QOS policies for the CVO spoke (ISR G2). These QOS policies must be applied on the CVO spoke (ISR G2) to provide good quality of Telepresence Video and Voice phones.!************************* NBAR::ACL ********************************* ip access-list extended NBAR_MAP_Scavenger permit tcp any any eq ip access-list extended NBAR_MAP_Tandberg permit udp any range any dscp 35 permit udp any range any dscp 35 permit udp any range any dscp 35 ip access-list extended NBAR_MAP_Video permit udp any range any dscp 33 permit udp any range any dscp 33 permit udp any range any dscp 33!************************* NBAR::Class-map **************************** class-map match-any NBAR_MAP_Tandberg match access-group name NBAR_MAP_Tandberg class-map match-any NBAR_MAP_Video match access-group name Movi 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 12 of 19
13 match access-group name CUVA match protocol rtp payload-type "97" match access-group name NBAR_MAP_Video class-map match-any NBAR_MAP_VoIP match access-group name Cisco_phone_voice_video match protocol rtp audio class-map match-any NBAR_MAP_Signaling match protocol skinny match protocol sip class-map match-all NBAR_MAP_Scavenger match access-group name NBAR_MAP_Scavenger!************************* NBAR::Policy-map **************************** policy-map NBAR_SET class NBAR_MAP_Tandberg set dscp cs4 class NBAR_MAP_Video set dscp cs2 class NBAR_MAP_VoIP set ip precedence 5 class NBAR_MAP_Signaling set ip precedence 3 class NBAR_MAP_Scavenger set ip precedence 1 class class-default set dscp default!********************** QoS::ACL ******************************* ip access-list extended CSM_QOS_ACL_1 permit udp any any eq isakmp!********************** QoS::Class-map ************************** class-map match-any CSM_CLASS_MAP_1 match ip dscp cs3 match ip precedence Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 13 of 19
14 class-map match-any CSM_CLASS_MAP_2 match access-group name CSM_QOS_ACL_1 match ip precedence 7 match ip precedence 6 class-map match-any CSM_CLASS_MAP_3 match ip dscp ef match ip precedence 5 class-map match-any QOS_TP_Tandberg match ip dscp cs2 match ip dscp cs4 match ip precedence 4!********************** QoS::Policy-map ************************ policy-map CSM_POLICY_MAP_HR_1 class class-default shape average policy-map CSM_POLICY_MAP_1 class CSM_CLASS_MAP_1 bandwidth 32 queue-limit 128 packets class CSM_CLASS_MAP_2 bandwidth 32 queue-limit 128 packets class CSM_CLASS_MAP_3 priority 128 class QOS_TP_Tandberg bandwidth 4915 queue-limit 256 packets class class-default policy-map CSM_POLICY_MAP_HR_1 class class-default service-policy CSM_POLICY_MAP_1 int Fastethernet4 (Wan Interface) service-policy output CSM_POLICY_MAP_HR_1 int vlan10 service-policy input NBAR_SET 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 14 of 19
15 5.2 Creating MAB Authorization Policies in ACS Create a group MAB under ACS in section Users and identity stores: Create a Network Authorization Profile for Voice and Telepresence phones under network Access: 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 15 of 19
16 Under the Tab Common Tasks, select Vlan ID as Static and put VLAN value such as 30. Change Voice Vlan to Static. Under the Tab Radius Attributes, select dictionary type as Radius-Cisco : 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 16 of 19
17 Select Dictionary type RADIUS-Cisco and cisco-av-pair under Radius Attribute. Assign the value of cisco-avpair as Vlan ID i.e. 30. Press Add button and then submit. Here is the snapshot of ACS after the profile configuration Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 17 of 19
18 Create a MAB Authorization under Access Services. Create a rule and select IP-Phone-Profile: The Authorization policy will be as follows after the creation: 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 18 of 19
19 6. References Cisco 802.1x port based authentication Cisco Unified IP Phone 8945 Cisco Unified IP Phone 9971 Cisco Tandberg Video End Points Cisco Virtual Office Deployment Guide Cisco Virutal Office Datasheet Cisco Movi Printed in USA C / Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 19 of 19
Cisco Virtual Office Express
. Q&A Cisco Virtual Office Express Overview Q. What is Cisco Virtual Office Express? A. Cisco Virtual Office Express is a solution that provides secure, rich network services to workers at locations outside
Cisco Virtual Office Flexibility and Productivity for the Remote Workforce
Cisco Virtual Office Flexibility and Productivity for the Remote Workforce Cisco Virtual Office Overview Q. What is the Cisco Virtual Office? A. The Cisco Virtual Office solution provides secure, rich
PC-over-IP Protocol Virtual Desktop Network Design Checklist. TER1105004 Issue 2
PC-over-IP Protocol Virtual Desktop Network Design Checklist TER1105004 Issue 2 Teradici Corporation #101-4621 Canada Way, Burnaby, BC V5G 4X8 Canada p +1 604 451 5800 f +1 604 451 5818 www.teradici.com
PCoIP Protocol Network Design Checklist. TER1105004 Issue 3
PCoIP Protocol Network Design Checklist TER1105004 Issue 3 Teradici Corporation #101-4621 Canada Way, Burnaby, BC V5G 4X8 Canada phone +1.604.451.5800 fax +1.604.451.5818 www.teradici.com The information
Switch Configuration Required to Support Cisco ISE Functions
APPENDIXC Switch Configuration Required to Support Cisco ISE Functions To ensure Cisco ISE is able to interoperate with network switches and functions from Cisco ISE are successful across the network segment,
- QoS Classification and Marking -
1 - QoS Classification and Marking - Classifying and Marking Traffic Conceptually, DiffServ QoS involves three steps: Traffic must be identified and then classified into groups. Traffic must be marked
AutoQoS for Medianet
Appendix A AutoQoS for Medianet As of August 2010, an updated version of AutoQoS was released for the Catalyst 2960- G/S, 3560-G/E/X, and 3750-G/E/X family of switches (with IOS Release 12.2(55)SE). This
Hosted Voice. Best Practice Recommendations for VoIP Deployments
Hosted Voice Best Practice Recommendations for VoIP Deployments Thank you for choosing EarthLink! EarthLinks best in class Hosted Voice phone service allows you to deploy phones anywhere with a Broadband
HOSTED VOICE Bring Your Own Bandwidth & Remote Worker. Install and Best Practices Guide
HOSTED VOICE Bring Your Own Bandwidth & Remote Worker Install and Best Practices Guide 2 Thank you for choosing EarthLink! EarthLinks' best in class Hosted Voice phone service allows you to deploy phones
Configuring QoS in a Wireless Environment
12 CHAPTER This chapter describes how to configure quality of service (QoS) on your Cisco wireless mobile interface card (WMIC). With this feature, you can provide preferential treatment to certain traffic
IP videoconferencing solution with ProCurve switches and Tandberg terminals
An HP ProCurve Networking Application Note IP videoconferencing solution with ProCurve switches and Tandberg terminals Contents 1. Introduction... 3 2. Architecture... 3 3. Videoconferencing traffic and
Application Note. Onsight Mobile Collaboration Video Endpoint Interoperability v5.0
Application Note Onsight Mobile Collaboration Video Endpoint Interoperability v5. Onsight Mobile Collaboration Video Endpoint Interoperability... 3 Introduction... 3 Adding Onsight to a Video Conference
Cisco VoIP CME QoS Labs by Michael T. Durham
Cisco VoIP CME QoS Labs by Michael T. Durham Welcome to NetCertLabs CCNA Voice Lab series. In this set of labs we will be working with the QoS (Quality of Service). A communications network forms the backbone
Quality of Service Analysis of site to site for IPSec VPNs for realtime multimedia traffic.
Quality of Service Analysis of site to site for IPSec VPNs for realtime multimedia traffic. A Network and Data Link Layer infrastructure Design to Improve QoS in Voice and video Traffic Jesús Arturo Pérez,
Verizon LTE Mobile Private Network Cisco Jabber
Guide Verizon LTE Mobile Private Network Cisco Jabber Mobile Device Deployment Guide for Private Network Traffic Management (LTE QoS) on Verizon Wireless MPN Revision 1.0 October 2015 2015 Cisco and/or
DS3 Performance Scaling on ISRs
This document provides guidelines on scaling the performance of DS3 interface (NM-1T3/E3) for the Cisco 2811/2821/2851/3825/3845 Integrated Services Routers. The analysis provides following test results;
Cisco CCNP 642 845 Optimizing Converged Cisco Networks (ONT)
Cisco CCNP 642 845 Optimizing Converged Cisco Networks (ONT) Course Number: 642 845 Length: 5 Day(s) Certification Exam This course will help you prepare for the following exam: Cisco CCNP Exam 642 845:
Extended Reach: Implementing TelePresence over Cisco Virtual Office
Deployment Guide Extended Reach: Implementing TelePresence over Cisco Virtual Office Table of Contents Overview... 3 Components... 3 Cisco TelePresence System 500... 3 Network Topology... 4 Cisco TelePresence
WiNG 5.X How To. Policy Based Routing Cache Redirection. Part No. TME-05-2012-01 Rev. A
WiNG 5.X How To Policy Based Routing Cache Redirection Part No. TME-05-2012-01 Rev. A MOTOROLA, MOTO, MOTOROLA SOLUTIONS and the Stylized M Logo are trademarks or registered trademarks of Motorola Trademark
CONNECTING TO LYNC/SKYPE FOR BUSINESS OVER THE INTERNET NETWORK PREP GUIDE
CONNECTING TO LYNC/SKYPE FOR BUSINESS OVER THE INTERNET NETWORK PREP GUIDE Engineering Version 1.3 June 3, 2015 Table of Contents Foreword... 3 Current Network... 4 Understanding Usage/Personas... 4 Modeling/Personas...
Best Practice Recommendations for VLANs and QoS with ShoreTel
Application Note ST AppNote 10325 (AN 10325) August 17, 2011 Best Practice Recommendations for VLANs and QoS with ShoreTel Description: This application note discusses the use of Virtual LANs, DHCP scopes
Juniper Networks EX Series Ethernet Switches/ Cisco VoIP Interoperability Test Results. September 25, 2009
Juniper Networks EX Series Ethernet Switches/ Cisco VoIP Interoperability Test Results September 25, 2009 Executive Summary Juniper Networks commissioned Network Test to assess interoperability between
Routing. Static Routing. Fairness. Adaptive Routing. Shortest Path First. Flooding, Flow routing. Distance Vector
CSPP 57130 Routing Static Routing Fairness Adaptive Routing Shortest Path First Flooding, Flow routing Distance Vector RIP Distance Vector Sometimes called Bellman-FOrd Original Arpanet, DECNet, Novell,
Lab 8.1.10.2 Introduction to the Modular QoS Command-Line Interface
Lab 8.1.10.2 Introduction to the Modular QoS Command-Line Interface Objective Configuring Quality of Service (QoS) involves classifying, marking, and policing traffic flows. It is often necessary to apply
Call Flows for Simple IP Users
This chapter provides various call flows for simple IP users. Finding Feature Information, page 1 Simple IP Unclassified MAC Authentication (MAC TAL and Web Login) Call Flows, page 1 Finding Feature Information
Quality of Service (QoS) for Enterprise Networks. Learn How to Configure QoS on Cisco Routers. Share:
Quality of Service (QoS) for Enterprise Networks Learn How to Configure QoS on Cisco Routers Share: Quality of Service (QoS) Overview Networks today are required to deliver secure, measurable and guaranteed
Voice over IP Basics for IT Technicians
Voice over IP Basics for IT Technicians White Paper Executive summary The IP phone is coming or has arrived on desk near you. The IP phone is not a PC, but does have a number of hardware and software elements
Configure IOS Catalyst Switches to Connect Cisco IP Phones Configuration Example
Configure IOS Catalyst Switches to Connect Cisco IP Phones Configuration Example Document ID: 69632 Introduction Prerequisites Requirements Components Used Conventions Background Information Configure
Cisco Unified Communications 500 Series
Cisco Unified Communications 500 Series IP PBX Provisioning Guide Version 1.0 Last Update: 02/14/2011 Page 1 DISCLAIMER The attached document is provided as a basic guideline for setup and configuration
Network Considerations for IP Video
Network Considerations for IP Video H.323 is an ITU standard for transmitting voice and video using Internet Protocol (IP). It differs from many other typical IP based applications in that it is a real-time
Configuring Auto-QoS
Finding Feature Information, page 1 Prerequisites for Auto-QoS, page 1 Restrictions for Auto-QoS, page 2 Information About, page 3 How to Configure Auto-QoS, page 5 Monitoring Auto-QoS, page 9 Configuration
MINIMUM NETWORK REQUIREMENTS 1. REQUIREMENTS SUMMARY... 1
Table of Contents 1. REQUIREMENTS SUMMARY... 1 2. REQUIREMENTS DETAIL... 2 2.1 DHCP SERVER... 2 2.2 DNS SERVER... 2 2.3 FIREWALLS... 3 2.4 NETWORK ADDRESS TRANSLATION... 4 2.5 APPLICATION LAYER GATEWAY...
Cisco SPA525G2 5-Line IP Phone
Q & A Cisco SPA525G2 5-Line IP Phone Q. What is the Cisco SPA525G2 5-Line IP Phone? A. The Cisco SPA525G2 IP Phone is a five-line phone that features a high resolution color display. The phone operates
MS Series: VolP Deployment Guide
Solution Guide MS Series: VolP Deployment Guide JULY 2013 How to deploy a distributed VoIP infrastructure with Meraki MS switches. Table of Contents Introduction 3 Getting Started 4 Setting up VoIP using
Voice over IP (VoIP) Basics for IT Technicians
Voice over IP (VoIP) Basics for IT Technicians VoIP brings a new environment to the network technician that requires expanded knowledge and tools to deploy and troubleshoot IP phones. This paper provides
Cisco WIP310 Wireless-G IP Phone Cisco Small Business IP Phones
Cisco WIP310 Wireless-G IP Phone Cisco Small Business IP Phones Wireless-G IP Phone for VoIP Service Highlights Business-quality VoIP calls over a Wi-Fi network with wireless handset convenience Configurable
Cisco Virtual Office Overview. Contents. Scope of Document. Introduction
Deployment Guide Cisco Virtual Office Overview Contents Scope of Document... 1 Introduction... 1 Requirements Addressed... 2 Cisco Virtual Office Solution Components... 3 Zero-Touch Deployment and Management...
Polycom Unified Communications Deployment Guide for Cisco Environments
Polycom Unified Communications Deployment Guide for Cisco Environments Wave 5 March 2012 3725-00010-001G Trademark Information Polycom, the Polycom Triangles logo, and the names and marks associated with
Configuring QoS in a Wireless Environment
Configuring QoS in a Wireless Environment This chapter describes how to configure quality of service (QoS) on your Cisco wireless interface. With this feature, you can provide preferential treatment to
Application Note. Configuring WAN Quality of Service for ShoreTel. Quality of Service Overview. Quality of Service Mechanisms. WAN QoS for ShoreTel 5
Application Note ST-0130 April 28, 2006 Configuring WAN Quality of Service for ShoreTel This application note discusses configuration techniques and settings that can be used to achieve highquality voice
Using a Sierra Wireless AirLink Raven X or Raven-E with a Cisco Router Application Note
Using a Sierra Wireless AirLink Raven X or Raven-E with a Application Note Cisco routers deliver the performance, availability, and reliability required for scaling mission-critical business applications
Bandwidth Security and QoS Considerations
This chapter presents some design considerations for provisioning network bandwidth, providing security and access to corporate data stores, and ensuring Quality of Service (QoS) for Unified CCX applications.
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.
Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials. CHAPTER 5 OBJECTIVES Configure a router with an initial configuration. Use the
Lab 8: Confi guring QoS
Lab 8: Objective Implement QoS, mark traffi c, and display and interpret QoS output. Lab Topology For this lab, your network design will include two pods of devices. You will be responsible for confi guring
About Firewall Protection
1. This guide describes how to configure basic firewall rules in the UTM to protect your network. The firewall then can provide secure, encrypted communications between your local network and a remote
LAN Planning Guide LAST UPDATED: 1 May 2013. LAN Planning Guide
LAN Planning Guide XO Hosted PBX Document version: 1.05 Issue date: 1 May 2013 Table of Contents Table of Contents... i About this Document... 1 Introduction: Components of XO Hosted PBX... 1 LAN Fundamentals...
Optimizing Converged Cisco Networks (ONT)
Optimizing Converged Cisco Networks (ONT) Module 5: Implement Cisco AutoQoS Introducing Cisco AutoQoS Objectives Describe the features of Cisco Auto QoS. List the prerequisites when using Cisco Auto QoS.
Chapter 7 Lab 7-1, Configuring Switches for IP Telephony Support
Chapter 7 Lab 7-1, Configuring Switches for IP Telephony Support Topology Objectives Background Configure auto QoS to support IP phones. Configure CoS override for data frames. Configure the distribution
IOS NAT Load Balancing for Two ISP Connections
IOS NAT Load Balancing for Two ISP Connections Document ID: 100658 Contents Introduction Prerequisites Requirements Components Used Conventions Configure Network Diagram Configurations Verify Troubleshoot
Cisco TelePresence Multipoint Switch
Data Sheet Cisco TelePresence Multipoint Switch Product Overview The Cisco TelePresence Multipoint Switch solution allows geographically dispersed organizations to hold Cisco TelePresence meetings across
Cisco RV215W Wireless-N VPN Router
Data Sheet Cisco RV215W Wireless-N VPN Router Simple, Secure Connectivity for the Small Office and Home Office Figure 1. Cisco RV215W Wireless-N VPN Router The Cisco RV215W Wireless-N VPN Router provides
Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1
Smart Tips Enabling WAN Load Balancing Overview Many small businesses today use broadband links such as DSL or Cable, favoring them over the traditional link such as T1/E1 or leased lines because of the
ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0
ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0 Module 1: Vulnerabilities, Threats, and Attacks 1.1 Introduction to Network Security
On-boarding and Provisioning with Cisco Identity Services Engine
On-boarding and Provisioning with Cisco Identity Services Engine Secure Access How-To Guide Series Date: April 2012 Author: Imran Bashir Table of Contents Overview... 3 Scenario Overview... 4 Dual SSID
Implementing Cisco Voice Communications and QoS
Implementing Cisco Voice Communications and QoS Course CVOICE v8.0; 5 Days, Instructor-led Course Description Implementing Cisco Voice Communications and QoS (CVOICE) v8.0 teaches learners about voice
Cisco Integrated Services Routers Performance Overview
Integrated Services Routers Performance Overview What You Will Learn The Integrated Services Routers Generation 2 (ISR G2) provide a robust platform for delivering WAN services, unified communications,
Configure Policy-based Routing
How To Note How To Configure Policy-based Routing Introduction Policy-based routing provides a means to route particular packets to their destination via a specific next-hop. Using policy-based routing
Cisco Analog Telephone Adaptor Overview
CHAPTER 1 This section describes the hardware and software features of the Cisco Analog Telephone Adaptor (Cisco ATA) and includes a brief overview of the Skinny Client Control Protocol (SCCP). The Cisco
Hardware Features Voicemail message waiting indicator light Voicemail message retrieval button Volume control Redial Button Flash Button Standard
Hardware Features Voicemail message waiting indicator light Voicemail message retrieval button Volume control Redial Button Flash Button Standard 12-button dialing pad High-quality handset One Ethernet
Break Internet Bandwidth Limits Higher Speed. Extreme Reliability. Reduced Cost.
Break Internet Bandwidth Limits Higher Speed. Extreme Reliability. Reduced Cost. Peplink. All Rights Reserved. Unauthorized Reproduction Prohibited Presentation Agenda Peplink Balance Pepwave MAX Features
Cisco Performance Agent Data Source Configuration in the Branch-Office Router
Deployment Guide Cisco Performance Agent Figure 1. Application visibility in all network segments using Performance Agent in branch office Cisco Performance Agent is a licensed software feature of Cisco
UIP1868P User Interface Guide
UIP1868P User Interface Guide (Firmware version 0.13.4 and later) V1.1 Monday, July 8, 2005 Table of Contents Opening the UIP1868P's Configuration Utility... 3 Connecting to Your Broadband Modem... 4 Setting
Cisco Virtual Office Unified Contact Center Architecture
Guide Cisco Virtual Office Unified Contact Center Architecture Contents Scope of Document... 1 Introduction... 1 Platforms and Images... 2 Deployment Options for Cisco Unified Contact Center with Cisco
Configuring an efficient QoS Map
Configuring an efficient QoS Map This document assumes the reader has experience configuring quality of service (QoS) maps and working with traffic prioritization. Before reading this document, it is advisable
Cisco RV110W Wireless-N VPN Firewall
Data Sheet Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1. Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides
Cisco RV180 VPN Router
Data Sheet Cisco RV180 VPN Router Secure, high-performance connectivity at a price you can afford. Figure 1. Cisco RV180 VPN Router (Front Panel) Highlights Affordable, high-performance Gigabit Ethernet
Yealink VCS Network Deployment Solution
Yealink VCS Network Deployment Solution Feb. 2015 V10.15 Yealink Network Deployment Solution Table of Contents Table of Contents... iii Network Requirements Overview... 1 Bandwidth Requirements... 1 Bandwidth
Cisco WIP310 Wireless-G IP Phone Cisco Small Business IP Phones
Cisco WIP310 Wireless-G IP Phone Cisco Small Business IP Phones Wireless-G IP Phone for VoIP Service Highlights Business-quality VoIP calls over a Wi-Fi network with wireless handset convenience Configurable
Cisco RV110W Wireless-N VPN Firewall
Data Sheet Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1. Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides
Certes Networks Layer 4 Encryption. Network Services Impact Test Results
Certes Networks Layer 4 Encryption Network Services Impact Test Results Executive Summary One of the largest service providers in the United States tested Certes Networks Layer 4 payload encryption over
The need for bandwidth management and QoS control when using public or shared networks for disaster relief work
International Telecommunication Union The need for bandwidth management and QoS control when using public or shared networks for disaster relief work Stephen Fazio Chief, Global Telecommunications Officer
ClearPass Policy manager Cisco Switch Setup with CPPM. Technical Note
ClearPass Policy manager Cisco Switch Setup with CPPM Technical Note Copyright 2012 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba
Cisco - Catalyst 2950 Series Switches Quality of Service (QoS) FAQ
Page 1 of 8 Catalyst 2950 Series Switches Quality of Service (QoS) FAQ Document ID: 46523 TAC Notice: What's C han g i n g o n T A C We b H el p u s h el p y ou. Questions Introduction What is the software
CCNP: Optimizing Converged Networks
CCNP: Optimizing Converged Networks Cisco Networking Academy Program Version 5.0 This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for noncommercial
CT505-30 LANforge-FIRE VoIP Call Generator
1 of 11 Network Testing and Emulation Solutions http://www.candelatech.com [email protected] +1 360 380 1618 [PST, GMT -8] CT505-30 LANforge-FIRE VoIP Call Generator The CT505-30 supports SIP VOIP
Network Security Solutions Implementing Network Access Control (NAC)
Network Security Solutions Implementing Network Access Control (NAC) Tested Solution: Protecting a network with Sophos NAC Advanced and Switches Sophos NAC Advanced is a sophisticated Network Access Control
BroadCloud PBX Customer Minimum Requirements
BroadCloud PBX Customer Minimum Requirements Service Guide Version 2.0 1009 Pruitt Road The Woodlands, TX 77380 Tel +1 281.465.3320 WWW.BROADSOFT.COM BroadCloud PBX Customer Minimum Requirements Service
Cisco Unified IP Phones and TelePresence System Video Endpoints Guide
Cisco Unified IP Phones and TelePresence System Video Endpoints Guide Cisco Unified IP Phones and TelePresence System Video Endpoints Guide Document Last Updated: November 21, 2013 This guide provides
Improving Quality of Service
Improving Quality of Service Using Dell PowerConnect 6024/6024F Switches Quality of service (QoS) mechanisms classify and prioritize network traffic to improve throughput. This article explains the basic
Part Number: 203285. HG253s V2 Home Gateway Product Description V100R001_01. Issue HUAWEI TECHNOLOGIES CO., LTD.
Part Number: 203285 HG253s V2 Home Gateway Issue V100R001_01 HUAWEI TECHNOLOGIES CO., LTD. 2013. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any means
Cisco Virtual Office Deployment Guide
Cisco Virtual Office Deployment Guide Scope of Document This deployment guide provides detailed information on configuring the Cisco Virtual Office headend devices and ManageExpress Virtual Office. It
Technote. SmartNode Quality of Service for VoIP on the Internet Access Link
Technote SmartNode Quality of Service for VoIP on the Internet Access Link Applies to the following products SmartNode 1000 Series SmartNode 2000 Series SmartNode 4520 Series Overview Initially designed
How To Set Up A Cisco Rv110W Wireless N Vpn Network Device With A Wireless Network (Wired) And A Wireless Nvv (Wireless) Network (Wireline) For A Small Business (Small Business) Or Remote Worker
Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1 Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides simple,
Cisco SPA901 1-Line IP Phone Cisco Small Business IP Phone
Cisco SPA901 1-Line IP Phone Cisco Small Business IP Phone Durable, Affordable, Feature-Rich IP Telephone for the Home Office and Business Small, affordable, single line business class IP Phone Connect
- QoS and Queuing - Queuing Overview
1 Queuing Overview - QoS and Queuing - A queue is used to store traffic until it can be processed or serialized. Both switch and router interfaces have ingress (inbound) queues and egress (outbound) queues.
SSVP SIP School VoIP Professional Certification
SSVP SIP School VoIP Professional Certification Exam Objectives The SSVP exam is designed to test your skills and knowledge on the basics of Networking and Voice over IP. Everything that you need to cover
Introducing Cisco Voice and Unified Communications Administration Volume 1
Introducing Cisco Voice and Unified Communications Administration Volume 1 Course Introduction Overview Learner Skills and Knowledge Course Goal and Course Flow Additional Cisco Glossary of Terms Your
System Installation Guide. Version 2.4
System Installation Guide Version 2.4 Table of Contents SCOPE OF THIS INSTALLATION GUIDE... 3 ADDITIONAL INSTALLATION RESOURCES... 4 FREEDOMIQ INSTALLATION IN FOUR STAGES... 5 STAGE 1: THE PRE- SALES STAGE...
Using Cisco UC320W with Windows Small Business Server
Using Cisco UC320W with Windows Small Business Server This application note explains how to deploy the Cisco UC320W in a Windows Small Business Server environment. Contents This document includes the following
Installation of the On Site Server (OSS)
Installation of the On Site Server (OSS) rev 1.1 Step #1 - Initial Connection to the OSS Having plugged in power and an ethernet cable in the eth0 interface (see diagram below) you can connect to the unit
Level: 3 Credit value: 9 GLH: 80. QCF unit reference R/507/8351. This unit has 6 learning outcomes.
This unit has 6 learning outcomes. 1. Know telephony principles. 1.1. Demonstrate application of traffic engineering concepts Prioritization of voice traffic Trunking requirements Traffic shaping. 1.2.
CISCO SPA3102 PHONE ADAPTER WITH ROUTER
CISCO SMALL BUSINESS VOICE GATEWAYS AND ATAS Intelligent Call-Routing Gateway for VoIP HIGHLIGHTS Enables high-quality, feature-rich voice-over-ip service through your broadband Internet connection Two
To ensure you successfully install Timico VoIP for Business you must follow the steps in sequence:
To ensure you successfully install Timico VoIP for Business you must follow the steps in sequence: Firewall Settings - you may need to check with your technical department Step 1 Install Hardware Step
Edgewater Routers User Guide
Edgewater Routers User Guide For use with 8x8 Service May 2012 Table of Contents EdgeMarc 250w Router Overview.... 3 EdgeMarc 4550-15 Router Overview... 4 Basic Setup of the 250w, 200AE1 and 4550... 5
SSVVP SIP School VVoIP Professional Certification
SSVVP SIP School VVoIP Professional Certification Exam Objectives The SSVVP exam is designed to test your skills and knowledge on the basics of Networking, Voice over IP and Video over IP. Everything that
640-460 - Implementing Cisco IOS Unified Communications (IIUC)
640-460 - Implementing Cisco IOS Unified Communications (IIUC) Course Introduction Course Introduction Module 1 - Cisco Unified Communications System Introduction Cisco Unified Communications System Introduction
The Basics. Configuring Campus Switches to Support Voice
Configuring Campus Switches to Support Voice BCMSN Module 7 1 The Basics VoIP is a technology that digitizes sound, divides that sound into packets, and transmits those packets over an IP network. VoIP
Broadband Phone Gateway BPG510 Technical Users Guide
Broadband Phone Gateway BPG510 Technical Users Guide (Firmware version 0.14.1 and later) Revision 1.0 2006, 8x8 Inc. Table of Contents About your Broadband Phone Gateway (BPG510)... 4 Opening the BPG510's
