VidyoWay IT Guide Product Version 3.0 Document Version 3.0 A 5/9/2014
433 Hackensack Ave Hackensack, NJ 07601 USA 2014 Vidyo, Inc. all rights reserved. Vidyo s technology is covered by one or more issued or pending United States patents, as more fully detailed on the Patent Notice page of Vidyo's website http://www.vidyo.com/about/patent-notices/, as well as issued and pending international patents. The VIDYO logotype is a registered trademark of Vidyo, Inc. in the United States and certain other countries, and is a trademark of Vidyo, Inc. throughout the world. VIDYO and the Vidyo family of marks are trademarks of Vidyo, Inc. in the United States and throughout the world.
Table of Contents Table of Contents Welcome to VidyoWay... 4 VidyoWay Settings and Network Configurations... 4 VidyoWay and Legacy Endpoint Communication... 5 Configuring Ports for Inbound Calls... 5 Dialing VidyoWay from Your Legacy Endpoints... 6 Configuring Ports for Outbound Calls... 7 Dialing Your Legacy Endpoints from VidyoWay... 7 Configuring Inter-Portal Communication Between VidyoDesktop and VidyoWay... 9 Configuring an Allowed or Whitelist VidyoWay Entry in Your VidyoPortal... 9 Opening Ports on Your Network for Mobile Device, VidyoDesktop, and IPC Use... 11 Configuring Specific VidyoWay IPC Ports... 11 Matching VidyoPortal Security... 9 iii
VidyoWay Settings and Network Configurations Welcome to VidyoWay VidyoWay Settings and Network Configurations IT and/or your company s Video Conferencing Administrator should review this guide in order to ensure the best video conferencing experience for your company s VidyoWay implementation. Note: At times this manual refers to legacy devices. Legacy devices can be telephones or conferencing systems using a traditional H.323 and SIP-based videoconferencing solutions. Some legacy device brands include Cisco, Polycom, and LifeSize to name a few. This document uses the following tasks to help the IT or Video Conferencing administrators of your company ensure the proper settings and accessibility from your network to the VidyoWay system are in place: Configuring Access between Legacy Systems and VidyoWay This section helps you ensure you ve configured and opened the correct ports to allow your legacy endpoints to work with VidyoWay. The section ends with testing for successful configuration and open ports by dialing into VidyoWay from your legacy endpoint. Configuring Inter-Portal Communication (IPC) between VidyoDesktop Users and VidyoWay If you already have VidyoPortal running at your company, this section shows you how to configure it to communicate and manage VidyoWay-to-VidyoWay calls on mobile devices, VidyoDesktop, and VidyoPortal and IPC. Tip: Prior to planning an important VidyoConference, you should test the use of legacy endpoints with VidyoWay. Also, test your legacy endpoints to ensure they re working properly on their own. 4
Configuring Ports for Inbound Calls VidyoWay and Legacy Endpoint Communication This section helps ensure you ve opened the correct ports and completed appropriate testing in order to successfully receive both inbound calls to VidyoWay from your legacy endpoints and make outbound calls from VidyoWay to your legacy endpoints. Configuring Ports for Inbound Calls Before making sure specific ports are cleared for dialing VidyoWay from your legacy endpoints, you must make sure all ports are configured to use the 74.201.162.140 (legacy.vidyoway.com) IP address on your network. Note: Be sure to create exceptions if necessary on any firewall, gatekeeper, or session border controller used with your legacy endpoints. With that done, make sure the following ports are open in both directions on your network: TCP Static Control Port 1720 For Q.931 call signaling (H.225 protocol) used in setting-up and terminating a call. Q.931 negotiates which dynamic port range to use between the endpoints for H.245 Call Parameters, data, audio and video. The firewall must be able to allow H.323-related traffic through. Tip: If you notice that you re unable to establish any calls, the TCP 1720 Control Port may be blocked. UDP Port 5060 For SIP calls. Additional ports must be opened in the outbound direction if you plan on dialing your legacy endpoints from VidyoWay. See Configuring Ports for Outbound Calls for more information. Note: Refer to your legacy endpoint vendor for specific inbound port requirements. 5
Dialing VidyoWay from Your Legacy Endpoints Dialing VidyoWay from Your Legacy Endpoints With the aforementioned settings made, it s important to test for successful communication by dialing VidyoWay from your specific legacy endpoints. To dial VidyoWay from your legacy endpoint, use one of the following options: Use your legacy endpoint interface and dial the 74.201.162.140 (legacy.vidyoway.com) IP address. An interactive voice response (IVR) then prompts you with both voice and text for your meeting ID and PIN number. Dial the URL (legacy.vidyoway.com). Tip: For these first two dialing options, create a directory speed dial entry in your legacy system for quicker access to subsequent VidyoWay meetings using the 74.201.162.140 IP address or the legacy.vidyoway.com URL (if your endpoint supports H.323 URI dialing). Dial directly into your desired meeting room using the meeting room ID and PIN (if needed). The room ID and PIN are separated by an asterisk *. For example, 1234567*1234 If desired, you can bypass the IVR and dial directly into meeting rooms using the following SIP and H.323 dialing strings: SIP dialing string to directly dial into a meeting room: 1234567*1234@legacy.vidyoway.com H.323 dialing string to directly dial into a meeting room:1234567*1234@legacy.vidyoway.com 6
Configuring Ports for Outbound Calls Configuring Ports for Outbound Calls Before making sure specific ports are cleared for dialing your legacy endpoints from VidyoWay, you must make sure all ports are configured to use the 74.201.162.140 (legacy.vidyoway.com) IP address on your network. Note: Be sure to create exceptions if necessary on any firewall, gatekeeper, or session border controller used with your legacy endpoints. With that done, make sure the following ports are open in the outbound direction: TCP Ports 50000 to 65535 Dynamic H.245, for call parameters. UDP Ports 50000 to 65535 Dynamic RTP, for video stream data. UDP Ports 50000 to 65535 Dynamic RTP, for audio stream data. UDP Ports 50000 to 65535 Dynamic RTCP, for control information. Additional ports must be opened in the inbound direction if you plan on dialing VidyoWay from your legacy endpoints. See Configuring Ports for Inbound Calls for more information. Note: Refer to your legacy endpoint vendor for specific outbound port requirements. Dialing Your Legacy Endpoints from VidyoWay With the aforementioned settings made, it s important to test for successful communication by dialing your legacy endpoints from VidyoWay. To dial your legacy endpoint from VidyoWay: 1. Locate the meeting ID on the meeting invitation of your specific VidyoWay meeting. If you haven t setup a meeting, refer to the VidyoWay User Guide for more information. 2. Log into VidyoWay. 3. Click the Manage My Meeting tab. 4. Enter a Meeting ID in the Enter Meeting ID to manage text box. 7
The Dial Out Now section of the screen appears. Dialing Your Legacy Endpoints from VidyoWay 5. Enter your room PIN if one is used for the meeting. 6. Enter the IP address of your Legacy room system. 7. Click Call. 8
Matching VidyoPortal Security to Make IPC Calls Configuring Inter-Portal Communication Between VidyoDesktop and VidyoWay If you already have VidyoPortal running at your company, this section shows you how to configure it to communicate with VidyoWay. These sections show you how to allow or whitelist the VidyoWay domain on your VidyoPortal, check that you ve opened the necessary ports on your network, and provide a security certificate guideline. Matching VidyoPortal Security to Make IPC Calls VidyoWay is a secured VidyoPortal. In order to make use your own VidyoPortal with VidyoWay and establish calls using inter-portal communication (IPC), your VidyoPortal(s) must also have both HTTPS enabled and run the Vidyo Encryption option. Notes: All VidyoPortals you plan on using must have SSL certificates with matching intermediates included. For more information about securing the VidyoPortal, refer to the Security section of the VidyoPortal Administrator Guide. For more information about the Vidyo Encryption option, contact your Vidyo sales representative. Configuring an Allowed or Whitelist VidyoWay Entry in Your VidyoPortal Your VidyoPortal must include a whitelist entry for the VidyoWay domain. To configure a whitelist VidyoWay domain entry in your VidyoPortal: 1. Log in to your Super Admin portal at http://<fqdn or IP>/super. 2. Click the Settings tab. 3. Click Inter-Portal Communication on the left menu. 9
4. Select the System Access Control Level. Configuring an Allowed or Whitelist VidyoWay Entry in Your VidyoPortal 5. If you have cascaded VidyoRouters, choose the IPC router pool from the Router Pool dropdown list, if desired. 6. Select the Allowed List Access Control Mode. 7. Click Add on the lower part of the screen. The Add address or domain dialog box opens. 8. Enter the vidyo.vidyoway.com domain name and click OK. Repeat these steps to add more domains or addresses to the list. 9. Click Save to save your list. 10
Opening Ports on Your Network for Mobile Device, VidyoDesktop, and IPC Use Opening Ports on Your Network for Mobile Device, VidyoDesktop, and IPC Use In order to allow VidyoWay-to-VidyoWay calls on mobile devices, VidyoDesktop, and VidyoPortal and IPC, you must ensure certain ports are open on your network. Note: Be sure to create exceptions if necessary on any firewall, gatekeeper, or session border controller in order to open the ports. Ensure the following ports are open on your network: TCP 80 For web access to the VidyoPortal. TCP 443 For SSL secured web access and VidyoProxy to the VidyoPortal. TCP 17992 For the EMCP protocol client connection to VidyoWay. TCP 17990 For the SCIP protocol client connection to the VidyoRouter. UDP and TCP 50000 65535 For bi-directional RTP/SRTP media, one RTP/RTCP port pair for each audio, video, data-sharing stream used in conferences. Configuring Specific VidyoWay IPC Ports Specific ports are used for IPC on your network and must be opened for use. Note: Be sure to create exceptions if necessary on any firewall, gatekeeper, or session border controller in order to open the ports. Ports that must be opened for IPC include the following: TCP 80, 443, and 17992 Must be opened between VidyoPortal 1 and VidyoPortal 2. TCP 17990 and UDP Must be opened between VidyoRouter 1 and VidyoRouter 2. 11