Device Authentication Configuration; Authentication Database; Endpoint Credentials Used For Authentication - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Device authentication configuration

The
Device authentication configuration
Configuration) is used to control the types of mechanisms used by the VCS to verify the authentication
credentials used by systems and devices that attempt to communicate with the VCS.

Authentication database

To verify the identity of a device, the VCS needs access to a database on which all authentication credential
information (usernames, passwords, and other relevant information) is stored. This database may be located
either locally on the VCS, or on an LDAP Directory Server. The VCS looks up the endpoint's username in the
database and retrieves the authentication credentials for that entry. If the credentials match those supplied
by the endpoint, the registration is allowed to proceed.
The Database type setting determines which database the VCS uses during authentication:
Local database: the local authentication database is used. You must configure the
n
database
to use this option. This is the default option.
LDAP database: a remote LDAP database is used. You must configure the
n
Note that:
If the VCS is acting as a traversal server, you must ensure that each traversal client's authentication
n
credentials are entered into the selected database.
The VCS supports the
n
with which it communicates.
The NTLM protocol challenges setting controls whether or not the VCS sends NTLM protocol challenges
to the Active Directory Service when authenticating devices over SIP:
Auto: the VCS decides, based on the device type, whether to send NTLM challenges. This is the default
n
setting.
Off: NTLM challenges are never sent.
n
On: NTLM challenges are always sent.
n

Endpoint credentials used for authentication

An endpoint must supply the VCS with a username and password if it is required to authenticate with the
VCS, for example when attempting to register and the relevant subzone's Authentication Policy is set to
Check credentials.
For Cisco endpoints using H.323, the username is typically the endpoint's Authentication ID; for Cisco
endpoints using SIP it is typically the endpoint's Authentication username.
See the relevant endpoint manual for details about how to configure the endpoint's credentials.
Cisco VCS Administrator Guide (X7.1)
page
(VCS configuration > Authentication > Devices >
ITU H.235 specification
for authenticating the identity of H.323 network devices
Device authentication
Local authentication
LDAP server
to use this option.
Page 103 of 479

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.1

Table of Contents