Network Enhancers - "Delivering Beyond Boundaries" Headline Animator

Showing posts with label Voice. Show all posts
Showing posts with label Voice. Show all posts

Monday, August 13, 2012

IP Telephony Basic Interview Definitions

Here's a quick primer with the latest IP Telephony expressions, VoIP terms and definitions of this rapidly growing industry. For specific assistance with business VoIP applications go to Business VoIP Solution.
ACD: Average Call Duration.  AHT (Average Hold Time): The average length of time between the moment a caller finishes dialing and the moment the call is answered or terminated.  ANI (Automatic Number Identification): A telephone function which transmits the billing number of the incoming call (Caller ID, for example).  ANSI (American National Standards Institute): The American standardization body known for interface recommendations and standardization of programming languages. ANSI is a non-profit making, government-independent organization.  AS (Autonomous System): A group of networks under mutual administration that share the same routing methodology.  ASP (Application Service Provider): An independent, third party provider of software-based services delivered to customers across a wide area network (WAN).  ASR (Answer-Seizure Ratio) : The ratio of successfully connected calls to attempted calls (also called 'Call Completion Rate').  ATA (Analogue Telephone Adapter): Used to connect a standard telephone to a high-speed modem to facilitate VoIP and/or fax calls over the Internet.  ATM (Asynchronous Transfer Mode): A technology for switched, connection-oriented transmission of voice, data and video. It makes high-speed dedicated connections possible between a theoretically unlimited number of network users and also to servers.  Asterisk: An open source that provides all the functionality of high-end business telephone systems. It is the world's most flexible and extensible telephone system, providing many features that are not yet available in even the most advanced proprietary systems. It is also the world's cheapest telephone system. The software is free and runs on inexpensive Linux servers.  Backbone: A high-speed network spanning the world from one major metropolitan area to another. Bad Frame Interpolation: Interpolates lost/corrupted packets by using the previously received voice frames. It increases voice quality by making the voice transmission more robust.  Bandwidth: The maximum data carrying capacity of a transmission link. For networks, bandwidth is usually expressed in bits per second (bps).  Billing Increment: A call duration measurement unit, usually expressed in seconds.  Broadband: A descriptive term for evolving digital technology that provides consumers a single switch facility offering integrated access to voice, high-speed data service, video demand services, and interactive delivery services.  CALEA (Communications Assistance for Law Enforcement Act): A 1994 act that requires telecommunications services to provide wiretapping access. The act specifically excludes information services, so the question is whether VoIP is a telecommunications service, and thus covered by the act, or an information service, and thus exempted. VoIP providers are receiving pressure to comply with the act.  Call Deflection: Call Deflection allows a called endpoint to redirect the unanswered call to another endpoint.  Call Detail Record (CDR): Information regarding a single call collected from the switch and available as an automatically generated downloadable report for a requested time period. The report contains information on the number of calls, call duration, call origination and destination, and billed amount.  Circuit-Switched: Communication system that establishes a dedicated channel for each transmission. The copper-wire telephone system (POTS) uses circuit-switching, as do PBX systems. Dedicated channels mean strong reliability and low latency, but the downside is that only one type of communication can use the channel at any given time.  CLEC (Competitive Local Exchange Carrier): A telephone company that competes with the larger incumbent carriers (ILECs) through reselling the ILEC services and/or creating services that use the ILEC's infrastructure. The Regional Bells are ILECs; local phone companies are frequently CLECs.  Codec (Compression-Decompression): In VoIP it is a voice compression-decompression algorithm that defines the rate of speech compression, quality of decompressed speech and processing power requirements. The most popular codecs in VoIP are G.723.1 and G.729.  Compression: VoIP uses various compression ratios, the highest approximately 12:1. Compression varies according to available bandwidth.  Congestion: The situation in which the traffic present on the network exceeds available network bandwidth/capacity.  CSMA/CD (Carrier Sense Multiple Access/Collision Detection): This is the access procedure to the Ethernet in which the participating stations physically monitor the traffic on the line. If no transmission is taking place at the time the particular station can transmit. If two stations attempt to transmit simultaneously this causes a collision that is detected by all participating stations. After a random time interval the stations that collided attempt to transmit again.  Dial-peer (Addressable Call Endpoint): A software structure that binds a dialed digit string to a voice port or IP address of the destination gateway. Several dial peers always exist on each router in the network, and at least two will be involved in making a call across the network, one on the originating end and one on the terminating end. In Voice over IP, there are two kinds of dial peers: POTS and VoIP. VoIP peers point to specific VoIP devices.  Dial-peer hunting: Process when the originating router tries to establish call on different dial peers if the originating router receives a user-busy invalid number or an unassigned-number disconnect cause code from a destination router.  DiffServ (Differentiated Services): A quality of service (QoS) protocol that prioritizes IP voice and data traffic to help preserve voice quality, even when network traffic is heavy.  DNIS (Dialed Number Identification Service): A telephone function which sends the dialed telephone number to the answering service.  DSP (Digital Signal Processors): All digital audio systems use DSP technology in order to differentiate between signal and noise. In telephone communication, too, much noise creates problems in maintaining connections, and in VoIP systems the DSP component provides features such as tone generation, echo cancellation, and buffering.  DTMF (Dual-Tone Multi Frequency): The type of audio signals generated when you press the buttons on a touch-tone telephone.  Dynamic Jitter Buffer: Collects voice packets, stores them, and shifts them to the voice processor in evenly spaced intervals to reduce any distortion in the sound.  E911 (Enhanced 911): Technology allowing 911 calls from cellular phones to be routed to the geographically correct emergency station (PSAP: Public Safety Answering Point). VoIP users currently have limited access to 911 services, and with some providers none, because VoIP is not geographically based.  FCC (Federal Communications Commission): The regulator of telephone and telecommunications services in the United States. It's not yet known the full extent to which the FCC will regulate VoIP communications. Part of the complication lies with determining the regulation of communications that begin or end on an FCC-regulated system, such as the standard telephone service.  Firewall: Security software or appliance that sits between the Internet and the individual PC or networked device. Firewalls can intercept traffic before it reaches network routers and switches, or between router/switch and PC, or both. Because the job of firewalls is to prevent access from specific packets over specific network ports, some must be specially configured to allow VoIP traffic to pass through.  FoIP (Fax over Internet Protocol): The fax counterpart to VoIP, available from some providers either free or at additional cost. FoIP is actually more reliable than VoIP because of its tolerance for poor latency.  H.323: The standard call protocol for voice and videoconferencing over LANs, WANs, and the Internet, allowing these activities on a real-time basis as opposed to a packet-switched network. Initially designed to allow multimedia to function over unreliable networks, it's the oldest and most established of the VoIP protocols. See also SIP and MGCP.  Latency: The time it takes for a packet to travel from its point of origin to its point of destination. In telephony, the lower the latency, the better the communication. Latency has always been an issue with telephone communication taking place over exceptionally long distances (the United States to Europe, for example). With VoIP, however, latency takes on a new form because of the splitting of the message into packets (see packet-switched) and network delay in general.  MGCP (Media Gateway Control Protocol): Another protocol competing with H.323 (see also SIP). MGCP handles the traffic between media gateways and their controllers. Especially useful in multimedia applications: the media gateway converts from various formats for the switched-circuit network, and the controller handles conversion for the packet-switched network. Designed to take the workload away from IP telephones themselves and thereby make IP phones less complex and expensive.  Packet-switched: Communication system that chops messages into small packets before sending them. All packets are addressed and coded so they can be recompiled at their destination. Each packet can follow its own path and therefore can work around problematic transmission segments. Packet switching is best when reaching a destination is the primary concern and latency is permissible, such as sending e-mail and loading Web pages.  PBX (Private Branch Exchange): A privately owned system for voice switching and other telephone related services. It routes calls from the public telephone system within an organization and allows direct internal calls.  PDD (Post Dial Delay): When a telecom switch is trying to establish the best possible route for the call.  POTS (Plain Old Telephone Service): Nothing more than a standard telephone line, the kind Ma Bell and then AT&T handled exclusively before the deregulation of the telephone industry. Upgrade your POTS to DSL, and you have broadband; add VoIP, and you have a system that uses POTS, the PSTN and the Internet in one seamless system.  PSTN (Public Switched Telephone Network): The network of wires, signals, and switches that lets one telephone connect to another anywhere in the world. Some VoIP services provide a gateway from the Internet to the PSTN and vice versa.  RTP (Real Time Protocol): Also known as Real Time Transport Protocol. Controls the transmission of packets of data that demands low latency (such as audio and video). Supports real-time transmission over IP networks and streaming as one means of delivery.  QoS (Quality of Service): Refers to the quality of the voice call over a VoIP network. A major issue in VoIP communications, because the high quality of telephone calls has always been taken for granted. Latency, packet loss, network jitter, and many other factors contribute to QOS measurements, and numerous solutions have been offered by vendors of routers and other network components.  SIP (Session Initiation Protocol): Communication protocol that operates similarly to H.323 but is less complex and more Internet- and Web-friendly. Fully modular and designed from the ground up for functioning over IP networks, it can be tailored more easily than H.323 for Internet applications. SIP and H.323 can and do coexist.  SoftPhone: A software app that gives you the ability to make and receive calls over the Internet using your PC and a headset or a microphone and speakers. A softphone's interface can look like a traditional phone dial pad or more like an IM client.  Universal Service: The availability of affordable telecommunications technology for all Americans, part of the 1966 Telecommunications Act, and regulated by the FCC. Current discussions revolve around the applicability of VoIP to universal services and whether or not VoIP providers should be taxed accordingly.  Virtual Phone Number: A feature of VoIP that allows you to attach additional phone numbers with different area codes to your basic VoIP service. This feature allows people to phone you without incurring long-distance charges from the same or adjacent nontoll area codes. All outgoing calls, however, are billed as if coming from your main phone number. Virtual phone numbers typically each cost a few extra dollars per month.  VoIP (Voice over Internet Protocol): The technology behind Internet phones. VoIP works by digitizing voice signals and sending them as packets through the same networking channels as your data.  Voip Escrow was created to provide a safe and secure platform for buyers and sellers of "minutes" to conduct business. This specificly applies to a segment of the industry (primarily non-US) dealing in call origination and termination points for VoIP traffic servicing targeted customer populations (e.g. Midle East, Eastern Europe, SE Asia). The service acts as a middle-man who protects the buyer by assuring the buyer they receive minutes they have ordered, and protecting the seller by ensure the money is available to him/her for minutes they have provided.

Monday, July 30, 2012

Introduction to Cisco Unified Communications Components

When getting started in the world of Cisco Unified Communications, it is easy to get overwhelmed with all of the available products, features and terms that encompass the Cisco unified communications world. This article takes a look at five of the most commonly used components available from Cisco:
  • Cisco Unified Communications Manager (CUCM)
  • Cisco Unified Communications Manager – Express (CME)
  • Cisco Unity Connection (CUC)
  • Cisco Unity Express (CUE)
  • Cisco Unified Presence (CUP)
If you’re thinking of going for your Cisco CCNA Voice Certification then this is a great place to start getting familiar with the different Cisco Unified Communications components.

Cisco Unified Communications Manager

One of the keystone products of Cisco’s Unified Communications products is Cisco Unified Communications Manager (CUCM). CUCM provides a product that enables the unification of voice, video, data and mobile application centralized through a single product. CUCM integrates into all of the other Cisco Unified products enabling support for a very large number of potential Unified Communication solutions. CUCM can be used as an appliance solution using Cisco’s 7800 Media Convergence Servers or Cisco Unified Computing System (UCS) B200 and C210 M2 Rack Mount and Blade Servers as well as installed on a number of different third party servers.

Cisco Unified Communications Manager – Express

The Cisco Unified Communications Manager – Express (CME) provides a scaled down version of CUCM that is able to be deployed on Cisco Integrated Servers Routers (ISR). CME is intended to be deployed in smaller businesses that don’t require the full CUCM solution or an enterprise branch offices that have limited connectivity into the main CUCM solution. CME provides most of the features that would be required in these offices and is a very popular solution in these situations. CME provides the ability to support many features that are conventionally associated with key systems and private branch exchanges (PBX) including IP telephony, voice gateway services, voicemail and auto attendant features (with Cisco Unity Express).

Cisco Unity Connection

Cisco Unity Connection (CUC) is a voice and unified messaging platform that provides the ability to access and manage voice messages in a number of different ways including through email, web browser, IP phone and smartphones. CUC also provides access to a powerful speech engine that is able to not only read text messages but also perform speech recognition. CUC can be installed on Cisco UCS B200 M2 and B210 Rack Mount servers and B200 M2 Blade servers.

Cisco Unity Express

The Cisco Unity Express (CUE) provides a subset of functionality that is provided by CUC in a smaller package that is deployed on Cisco Integrated Servers Routers (ISR). CUE can be integrated into a larger CUC and CUCM solution or implemented with only CME to a small business or office. CUE specifically provides local storage and processing of integrated messaging, voicemail, fax, auto attendant, and interactive voice response (IVR). CUE can be deployed in a couple of different form factors depending on the series of ISR being used. When being deployed in Cisco 2800 and 3800 series routers, CUE can be deployed using the Cisco Unity Express Network Module (NME-CUE) or Cisco Unity Express Advanced Integration Module (AIM-CUE or AIM2-CUE-K9). When being deployed in Cisco 2900 and 3900 series routers, CUE can be deployed using the Cisco Integrated Services-Ready Engine (ISM-SRE-900-K9) and Service Module Services-Ready Engine (SM-SRE-700, 710, 900, 910-K9).

Cisco Unified Presence

Cisco Unified Presence (CUP) provides an enterprise instant messaging (IM) and network based presence solution that integrates into the Cisco Unified Communications products. CUE provides the ability for clients to support many different features including instant messaging, presence, click to call, phone controls, voice, video, visual voicemail and web collaboration.

Summary

Cisco’s unified communications solutions provide an organization, regardless of size, several options to maintain communications and collaboration. This is vital in modern organizations. This article provides just a brief introduction of the most popular of these options, if deploying this type of solution, take the time to review Cisco’s full product offerings.

Monday, June 25, 2012

Benefits Of Hosted PBX Systems


A Hosted PBX generally involves installing some sort of remotely attachable handsets (usually VoIP based, in today's world, but "Centrex" service does this well in the analog world, too) at a site, then putting the 'brain' of the PBX, along with it's primary PSTN connections, into a different site, usually controlled by a vendor.

There are several pros and several cons involved, but a lot of the answer comes with your level of comfort with the vendor, and your level of cost involvement.

In the end, the golden rule of telephony development is this .... "Do Not Mess With Dial Tone". Users depend on it, every day- and businesses live and breathe by their phones. If you find a reliable, cost-effective solution, then that makes a good fit- any chance of unreliability, and you are risking the business.


In a hosted PBX, there is one extra moving part- the link between your site and the provider- that you *must* ensure. If that should fail, all your phones will be down (unless you have some sort of backup line arrangement and local PBX hardware to fall back on).


Specifically, here are some pro's and con's of hosted PBX's:

Pros .....

1. Generally, a hosted PBX is less expensive to the end user. Most hosted PBX vendors work out some sort of 'pay per minute' or 'pay per handset' plan, and, since they put many different customers on their enterprise-grade PBX at a central site, are able to pass on savings. For a small site, it's very hard to beat a hosted provider's cost model, unless you've got a large number of handsets, or specific application needs that drive up the price.

2. Maintenance is built in. Hosted PBXs today generally use VoIP hardware- so handset Move,Add,Change work is done by the end user with no more difficulty than moving a PC. The wiring at your site is your LAN, and LANs have a generally high reliability factor. Most changes, therefore, are done at the PBX level- and the vendor can again leverage economy of scale- the changes are generally simple and done via web browser, so they can include the 'maintenance' for free, and get some high-level support on every problem.

3. High reliability of trunk lines, and generally lower cost per minute. Again, through economy of scale, the provider can almost always get a better per-minute rate than a small office can negotiate with the local telco, and can easily afford to have redundant call and network/PSTN paths by sharing them with multiple customers. Having a trunk failure from a hosted PBX center would be horrific, affecting potentially thousands of customers- the vendor simply won't let that happen. (or shouldn't).

Con's .....

1. Loss of flexibility. The hosted PBX company makes their money by providing a fixed package of services and devices to it's customers. If you want telephony applications that aren't on the 'menu', the answer may very well be 'no'. Don't like your handsets- you can't change them (beyond a range). Need to change your long distance provider? Forget it- you won't have one to select. In some cases, the vendor will own your number, making it difficult to change vendors without changing your business telephone number.

2. Reliability. As I mentioned above, you're now dependant upon your local LAN and the WAN connection between your site and the vendor. If you've got a small office on a tight budget, failures of either one may take a few hours- or days- to resolve, as you won't have the local resources to apply to them. On top of this, the cheapest WAN method is seen as the Internet- and the Internet itself may not be reliable. Call quality may suffer if your office is doing a lot of Internet traffic, or your Internet provider is having problems.

3. Business reliability. The best rates for hosted PBX companies come from startups. This has it's ups and downs- sometimes, that can be great, providing personal service at a decent price. But, a lot of startups fail- and when they do, your phones go with them. Check your contracts carefully.

Hosted IP PBX's, Enterprise Solutions for Small To Medium Sized Businesses

With all of the different flavors of VOIP in the marketplace today, products like Vonage do not bode well for an office with more than a few employees. The other route is purchasing a VOIP enabled key system. Well, I would like to mention a third option that is often overlooked, the Hosted VOIP PBX.


The Hosted IP PBX is a great solution for many mid-sized companies looking for the advantages of an enterprise type of phone system but not wanting to spend the capital to acquire one. Plus you get many more inherent advantages a traditional phone system can not offer you. Let's look into detail what these advantages are in comparison to a traditional key or PBX phone system.


First, let's do a comparison of features between the different solutions. Typically, when buying a traditional system you are limited by the expansion of how many cards and ports the unit can acommodate and when making any changes like moves or adds, you need to pay a technician to come out and service the unit. With a hosted system the technology resides in the phone companies network, so any type of adds, moves or changes can be done easily by you through a web browser and a secure login website, this removes the cost of hiring someone to do this. It also adds tremendous power for redundancy and backup situations. For example, you have an awesome weather event such as a snow storm (which being from Buffalo is my point of reference) and most people can not make into the office, you can get on your broadband connection at home, login and forward all of your calls to any number in the world, like your cell phone or home phone. This way you still will be able to be productive.

Additionally, with a traditional phone system, you have to purchase additional software to get added features. In a hosted environment the upgrades are automatically propagated down to your phone giving you things like unified messaging (getting voicemail files on your computer and using your address book to dial phone numbers), hot desking (being able to go between offices and logging onto any phone and it will not only route all of your calls to you automatically, but will also bring over your speed dials and all of your custom phone settings to that other office phone) and any new enhancements that the software developer creates.

Finally, cost. A traditional system purchase includes phones, separate phone cabling, the box in the phone closet, a voice mail system and any additional cards or software you need to give it the features you want such as auto attendant, IVR functionality, etc. A hosted system only requires data cabling, the phones, a switch and a router. This allows approximately a 40% reduction in upfront expense versus traditional phone systems and at least a 60% reduction against a VoIP system that resides on site.


In summary, a hosted VOIP system is an excellent choice for the mid sized business due to the fact that they can achieve enterprise functionality at a fraction of the cost while also inheriting redundancy not heard of in this market segment. But, you should always consult with a professional to help guide you through advantages and disadvantages of the choices currently out there and find the solution that best suits your businesses current and future needs.

Monday, June 18, 2012

VoIP – Per Call Bandwidth Consumption


One of the most important factors to consider when you build packet voice networks is proper capacity planning. Within capacity planning, bandwidth calculation is an important factor to consider when you design and troubleshoot packet voice networks for good voice quality.


This document explains voice codec bandwidth calculations and features to modify or conserve bandwidth when Voice over IP (VoIP) is used.


http://www.cisco.com/en/US/tech/tk652/tk698/technologies_tech_note09186a0080094ae2.shtml

Thursday, December 22, 2011

Cisco Phone Cheat Codes

There are many things in this world that are hidden just beneath the surface that make our lives easier.  This is also the case when dealing with Cisco phones. There are three key combinations that will help you immensely when configuring these devices, provided you know what they are.

1. Unlock Settings – *, *, #. When you check the settings on a Cisco phone, you’ll notice that you can look at the values but you can’t change any of them. Many of these values are set at the Cisco Unified Communications Manager (CUCM) level. However, once common issue is the phone not being able to contact the CUCM server or the phone having the wrong address/TFTP server information from DHCP. While there are a multitude of ways to correct these issues in the network, there is a quick method to unlock the phone to change the settings.
  • Go to the Settings page of the phone
  • While in the settings page, press *, *, # (star, star, pound) about 1/2 second apart
  • The phone will display “Settings Unlocked” and allow you to make changes
It’s that easy. There won’t be a whole lot to do with the phone Telephony User Interface (TUI), but you can make quick changes to DHCP, IP address, or TFTP server address entries to verify the phone configuration is correct. By the way, when putting in an IP address via TUI, the “*” key can be used to put a period in an IP address. That should save you an extra keystroke or two.

2. Hard Reset – *,*,#,*,*. Sometimes, you just need to reboot. There are a variety of things that can cause a phone to need to be reset. Firmware updates, line changes, or even ring cadence necessitate reboots. While you can trigger these from the CUCM GUI, there are also times that they may need to be done from the phone itself in the event of a communications issue. Rebooting is also a handy method for beginning to troubleshoot issues.

Why not just pull the network cable from the back of the phone? Won’t disconnecting the power reboot?

True, it will. What if the phone is mounted to the wall? Or if the phone is running from an external power supply? Or positioned in such as way that only the keypad is visible? Better to know a different way to reboot just in case. Here’s where the reboot cheat code comes in handy.
  • Go to the settings page of the phone
  • Press *,*,#,*,* (star, star, pound, star, star) about 1/2 second apart
  • The phone will display “Resetting” and perform a hard reset
This sequence will cause the phone to reboot as if the power cable had been unplugged and force it to pull a new configuration from CUCM. Once common issue I find when entering this code is the keypresses not registering with the phone. Try it a couple of times until you develop a rhythm for entering it about 1/2 second apart. Much more than that and the phone won’t think you’re entering the code. Quicker than that and the keys might not all register.

3. Factory Reset – “1,2,3,4,5,6,7,8,9,*,0,#”. When all else fails, nuke the phone from orbit. It’s the only way to be sure. Some settings are so difficult to change that it’s not worth it. Or you’ve got a buggy firmware that needs to be erased. In those cases, there is a way to completely reset a phone back to the shipping configuration. You’ll need access to unplug the power cable, as well as enough dexterity to press buttons on the front as you plug it back in.
  • Unplug the power from the phone.
  • As you plug it back it, press and hold the “#” key. If performed correctly, the Headset, Mute, and Speaker buttons in the lower right corner will start to flash in sequence.
  • When those three buttons start flashing in sequence, enter the following code: 1,2,3,4,5,6,7,8,9,*,0,#. You’ll notice that’s every button on the keypad in sequence from left to right, top to bottom.
  • Phone will display “Upgrading” and erase the configuration.
Don’t worry if you press a key twice on accident. The phone will still accept the code. However, you do need to be quick about things. The phone will only accept the factory reset code for 60 seconds after the Headset, Mute, and Speaker buttons start flashing in sequence.

Wednesday, April 20, 2011

Configuring Calling Encryption Between Cisco IP Phones



By Paul Smith

This blog is one of four dealing with the encryption of various Cisco UC devices. This particular piece deals
with setting up encrypted calls between phones on a cluster. The other blogs in this series are Configuring CUCM with Secure LDAP, Configuring Secure Hardware Conferencing, and Configuring a Secure Voice Gateway. The information in the LDAP article stands on its own, but the steps herein must be followed before one can configure any of the items in the last two pieces.

The steps detailed in these blogs may not be the final word on all of the ins and outs of configuring the items. However, we discovered that there are very few, or no, articles dealing with these subjects written by someone who has actually performed the tasks. We, therefore, felt it would be a service to offer information about the steps that worked for us in our specific set of circumstances (particularly since we, apparently, fell into most of the traps).

Again, the following is for phone encryption, but these steps must also be followed first if one plans on configuring secure connections to voice gateways or plans on configuring secure conferencing.

1) Begin by ensuring that the Cisco Certificate Authority Proxy Function service is running on the Publisher, and that the CTL Provider service is running on every node that is also running the CallManager service.

2) Cluster security must be set to “Mixed Mode”. The cluster has 2 security modes, mixed or non-secure. With mixed mode, phones that support encryption, and which are configured for it, will set up encrypted calls between them. Phones that are not set for encryption will work, but will not have encrypted sessions between them. If a phone set for encryption calls a phone not set for encryption, the call will be completed but will not be encrypted.

3) To set the encryption level for the cluster, two “Hardware Security Keys” must first be obtained from Cisco (part number KEY-CCM-ADMIN-K9=). They look like typical USB memory sticks and they always come in pairs.
4) In the Plug-ins area of the CUCM Administration page, download the Cisco CTL Client. Once it’s downloaded, double-click on the file to install it on a PC.

5) Make sure that DNS is configured properly in the cluster and that the DNS name of the servers running the CallManager service are resolvable by the PC running the CTL Client.

6) Run the client. During the process, a prompt will be displayed that states that one of the keys must be plugged into the computer. Once information has been copied to and from the key, a prompt will state that the first key must be removed and the other key must be plugged into the computer. If you have two USB ports on the computer DO NOT insert both keys at the same time. If, at any point, a password is requested for the key, the default is “Cisco123” (case sensitive). Note: If, at any time, another individual set a different password for the keys, do not guess what that password may be. After 15 wrong attempts at guessing the password, the key locks and nothing will unlock it (this is part of the reason the keys come in pairs). If both keys get locked, another pair of keys must be obtained from Cisco.

7) The CTL Client program is easy to run, it’s mostly a “Fill in obvious information, click Next, click Next, click Finish” type of thing. However, one of the tasks that is accomplish by running the program is setting the security mode of the cluster to “Mixed”. This is the only way that Mixed-Mode security can be set. The other task that is accomplished by running the CTL Client is the creation of a CTL file that will be used by the phones for encryption.

8) After the CTL Client program has been run, restart the CallManager service and the TFTP service on every server in the cluster that has the services running.

9) The next thing that must happen is a security profile must be created for each model of phone that will support encrypted conversations. Go to System > Security Profile > Phone Security Profile and click “Add New”.

10) In the “Phone Security Profile Type” drop-down, select the model number of the phone for which a profile needs to be created. Click “Next”.

11) Select the protocol the phone will use (SCCP or SIP) and click “Next”.

12) Give the profile a Name and a Description. The Name will appear on the “Device Security” drop-down when a phone is created. In the “Device Security Mode” drop-down, select “Authenticated” if there is a simple need to authenticate the phone as being a device that’s supposed to attach to the CUCM cluster. Select “Encrypted” if there is a desire to encrypt the RTP and signaling streams to be unrecognizable to anyone who attempts to record and decipher them. We did Encrypted.

13) In the “Authentication Mode” drop-down, the possible selections are “By Authentication String”, “By Null String”, “By Existing Certificate (Precedence to LSC)”, and “By Existing Certificate (Precedence to MIC)”. This dictates how encrypted communication will happen between CUCM and the phone. Using the LSC is the most secure method (realize, however, that the LSC must be first downloaded to the phone using a less secure method which will be detailed below). Set the Authentication Mode and click “Save”.

14) Repeat the above three steps to create a profile for every model phone for which encryption will be configured.

15) The next step is the one that gets the LSC onto the phone. Add a new phone (or go to an existing phone). Initially, the phone will probably be added with no security. But in the area marked “Certificate Authority Proxy Function (CAPF) Information”, hit the drop-down for “Certificate Operation” and select “Install/Upgrade”. In the “Authentication Mode” drop-down, select “By Authentication String”. In the “Authentication String” field, either add a string of numbers, or click the “Generate String” button and allow one to be generated automatically (Note: This step is something that can be done using BAT, but it’s recommended to use the same string throughout). Make sure the “Operation Completes By” setting is for some time in the future. Click Save and Apply.

16) Go to the physical phone itself. Hit the “Settings” button and navigate to the security configuration area (getting to this area on a phone is different from model to model, but the goal is to find the section that mentions the LSC). The status of the LSC should be “uninstalled”. Unlock the phone with a **# and a softkey should appear that reads “Update”. Pressing this softkey will make the phone prompt for an Authorization String. Use the string of numbers that was selected or generated on the phone configuration page. Press the “Submit” softkey.

17) During the LSC download process, the phone should state that it’s updating. Once the download is complete, the phone may reset.  When the procedure is complete, the LSC will be listed as “Installed”.

18) Once installation is accomplished, go back into the phone’s configuration page in CUCM. In the “Protocol Specific Information” area, go to the “Device Security Profile” drop-down and select the secure profile that was configured for that model phone in a previous step. Once this is selected, the “Authentication Mode” (which is grayed out) will change from “By Authentication String” to “By Existing Certificate (Precedence LSC)”. Click Save and Apply. The phone will reset by itself.

19) This is the point where things could get dicey. The phone should come back and register with no problem. However, some phones will be stubborn. It’s sometimes the case that the process needs to be redone beginning with setting the phone’s security profile to non-secure, saving and applying, then setting it back to using the LSC. We haven’t had to delete the LSC and start over, but there are items on Cisco’s NetPro where people claimed they had to do so.

20) If the phone registers it’s probably ready to go. However, to check that the phone has been correctly configured for encryption, make a call between configured phones. If, once the call is answered, a padlock icon shows up next to the caller ID, the call is being encrypted correctly.

21) An important element to remember is the fact that there are some changes that might be made to a cluster which will cause encryption to begin to fail. If encryption has been working on the phones, and the phones suddenly drop their registration after some configuration changes, the suggested first step will be to do a bulk change in the phones to a non-secure profile, just to get them working again. Then, during a maintenance window, rerun the CTL Client. Then set the security profiles back to the ones the phones are supposed to have, set the “Certificate Operation” drop-down to “Install/Upgrade”, make sure the operation has a future date, and Save and Apply.

My Blog List

Networking Domain Jobs