Cisco TelePresence Administrator's Manual page 120

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Field
Description
Username
The AD domain administrator username
and
and password.
Password
The current status of the connection to the Active Directory Service is displayed at the bottom of the page.
Note that:
The domain administrator username and password are not stored in VCS; they are only required to join an
n
AD domain (or to leave a domain).
The VCS only needs to join the AD domain once, even if the connection to the Active Directory Service is
n
disabled and turned back on again. The only time a join is needed again is if the VCS leaves the domain or
needs to join a different domain.
In a clustered system, each VCS must join the AD domain separately.
n
SPNEGO
SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) is a mechanism used by client
applications when they seek to authenticate with a remote server. It allows the client and server to identify
which authentication protocols they both support and decide which protocol to use.
By default the VCS uses SPNEGO when communicating with an AD Domain Controller. It can only be
enabled or disabled through the CLI by using the command xConfiguration Authentication ADS
SPNEGO.
Ports
The process of joining domains and authenticating credentials involves communications with many services
over different protocols. The following table summarizes the ports used:
Service/protocol
DNS server
Kerberos Key Distribution Center
CLDAP communications with the Domain Controller
LDAP communications with the Domain Controller
Microsoft-DS RPC communications with the Domain
Controller (used for the authentication of client
credentials)
Cisco VCS Administrator Guide (X7.2)
Usage tips
The username and password credentials of the
domain administrator are required only when you
attempt to join a domain. The VCS only needs to join
the domain once, after which the connection can be
enabled or disabled as required.
Note: for security purposes, the AD domain
administrator username and password are not stored
on the VCS. This is why you must enter the
credentials every time you attempt to join the domain.
Default destination port
UDP/53
UDP/88
Note that Kerberos also uses TCP/88.
UDP/389
TCP/389
TCP/445
Note that if TCP/445 cannot be reached, the system
falls back to using TCP/139.
Device authentication
Page 120 of 498

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.2

Table of Contents