Category Archives: expressway

Cisco Support Community Collaboration Videos

Thanks to Java for sharing this – can’t believe I’ve never come across this!

A really, really awesome resource for a number of Collab-related support topics.  Some excellent videos on topics such as:

  • CUOS certificates
  • Self-Provisioning
  • Conference Now
  • PCD
  • TelePresence
  • VCS
  • Service Discovry and UDS
  • Various phone model factory reset procedures

 

 

Enjoy! 🙂

Advertisements
Tagged , , , , , , , , , ,

ExpressWay DMZ and NAT Design Considerations

There are a number of excellent documents on the subject of ExpressWay traversal DMZ design and handling NAT.  I must however commend Cisco on the updates on this topic in the X8.7 documentation release.

Please see the below:

http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-7/Cisco-Expressway-Basic-Configuration-Deployment-Guide-X8-7.pdf

 

Cisco discusses various DMZ deployment models:

  1. Dual-NIC Static NAT (Recommended)
  2. Single NIC Static NAT
  3. 3-Port Firewal Static NAT

 

There are other methods that include variations without NAT where a Public IP is placed on the Edge.  Personally, “It works” is not a good enough reason to deploy as such.  Avoid as far as possible.

 

Most specifically, I must highlight the following from the document:

  • Preferred Architecture dictates a dual-NIC Static NAT design
  • Dual-NIC design requires static routing on the Edge
  • Static NAT is definitely preferred to a Public IP on a ExpressWay-E box
  • Disable SIP ALG on your firewall – pretty standard stuff
  • Single NIC designs result in problematic implementation considerations that can relate to:
    • NAT Reflection – resultant asymmetric routing, security concerns and firewall support issues
    • Hair-pinned media
    • Excessive bandwidth consumption (3 times in fact!)
    • Public IP exposure in SIP signalling to B2BUA

Please see pp. 50-51 for excellent visual representations of the traffic flows for the the various implementations!

 

Some Useful Links:

 

Tagged , , , , , ,
Collaboration Engineer

All things Technology - Posts to save for when you need them

Gerry Keleghan's Blog

A Blog about Cisco Unified Communications

ccieme

my personal journey to ccie collaboration

Striving for greatness

Thoughts on emerging tech, open source, and life

Network Experts Blog

“Knowledge comes by eyes always open and working hands.”

SIP Adventures

A unified communications blog by Andrew Prokop

The Cloverhound Blog

Cloverhound Employees Talk Unified Communications and Contact Center

Warcop

Fog navigator. Get out of the clouds. Down to earth solutions. @Warcop

Cisco Collab Engineering Tips

Michael White - CCIE #26626

Darkroomstory

Photography by Manos,

afterthenumber

Thoughts and experiences of a Cisco Collaboration engineer after clearing the CCIE lab...

Longreads

The best longform stories on the web

The Daily Post

The Art and Craft of Blogging

The WordPress.com Blog

The latest news on WordPress.com and the WordPress community.