Cisco TelePresence Administrator's Manual page 107

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Device authentication
Policy
Trust
In local domain
On
Messages are not challenged for
authentication.
All messages are classified as
authenticated.
Messages with an existing P-Asserted-
Identity header are passed on unchanged.
Messages without an existing P-Asserted-
Identity header have one inserted.
Subzone-level authentication policy
Authentication policy is configurable for the Default Subzone and any other configured subzone.
To configure a subzone's Authentication policy, go to
click View/Edit or the name of the subzone. The policy is set to Do not check credentials by default when a
new subzone is created.
The behavior varies for H.323 and SIP messages as shown in the tables below:
H.323
Policy
Behavior
Check
Messages are classified as either authenticated or unauthenticated depending on whether any
credentials
credentials in the message can be verified against the authentication database. Messages that
pass authentication are classified as authenticated.
If no credentials are supplied, the message is always classified as unauthenticated.
Note that unauthenticated registration requests are rejected.
Do not check
Message credentials are not checked and all messages are classified as unauthenticated.
credentials
Treat as
Message credentials are not checked and all messages are classified as authenticated.
authenticated
SIP
The behavior for SIP messages depends upon whether the message was received from a local domain (a
domain for which the VCS is authoritative) or a non-local domain.
Policy
In local domain
Check
Messages are challenged for authentication and those that pass
credentials
are classified as authenticated.
Messages (including registration requests) that fail
authentication are rejected.
Do not check
Messages are not challenged for authentication.
credentials
All messages are classified as unauthenticated.
Treat as
Messages are not challenged for authentication.
authenticated
All messages are classified as authenticated.
Cisco VCS Administrator Guide (X8.1.1)
Outside local domain
Messages are not challenged for
authentication.
Messages with an existing P-Asserted-
Identity header are classified as
authenticated, and the header is passed
on unchanged.
Messages without an existing P-Asserted-
Identity header are classified as
unauthenticated.
Configuration > Local Zone >
Outside local domain
SIP messages received from
non-local domains are all
treated in the same manner,
regardless of the subzone's
Authentication policy
setting:
Messages are not
challenged for
authentication.
All messages are classified
as unauthenticated.
About device authentication
Subzones, then
Page 107 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents