Video Communication Server Administrator Guide
System Configuration
Getting Started
Table of Contents
Administrator Policy
Using TANDBERG’s FindMe
Call Processing
User Policy
Enum Dialing Disconnecting calls
Calls to and from Unregistered Endpoints
Fallback Alias
Firewall Traversal
Maintenance
DNS Configuration 79
Ldap Configuration 80
Regular Expression Reference 78
Trademarks and Copyright
Copyright 2007, Tandberg
Patent Information
Disclaimer, Copyrights and License Agreements
Disclaimer
Approvals
Safety Instructions and Approvals
Safety Instructions
Environmental Issues
Environmental Issues
Main Product Features
Standard Features
Optional Features
Introduction
Tandberg VCS
Connecting the Cables
Getting Started
Powering on the VCS
Initial Configuration via Serial Cable
System Administrator Access
Using the Web Interface
Supported Browsers
Using the Command Line Interface CLI
Understanding the Overview
ViewingText goesSystemhere Overview
Viewing the Overview
Systemtext Configuration
Configuring System Settings
About Admin Access settings
System Administration Configuration
Configuring Ethernet Settings
Ethernet Configuration
XConfiguration Ethernet
About Ethernet Speed
Configuring IP Settings
IP Configuration
XConfiguration IP XConfiguration IPProtocol
About IPv4 to IPv6 Gatewaying
DNS Configuration
Configuring DNS Settings
XConfiguration IP DNS
About DNS Servers
Configuring NTP Settings
Setting the Time Zone
NTP Configuration
XConfiguration NTP Address XConfiguration TimeZone Name
Configuring Snmp Settings
About Snmp Settings
Snmp Configuration
XConfiguration Snmp
Configuring External Manager Settings
External Manager Configuration
XConfiguration ExternalManager
About the External Manager
Backing up Configuration Settings
Logging
Logging Overview
Viewing the Event Log
Event Log
Event Log Format
Message Details Field
Events Logged at Level
DNS
Events Logged at Level 1
Event Data Fields
TCP UDP TLS
SIP
225 245
For Register requests the AOR for the Register request
Number of bytes sent/received in the message
Request/granted registration expiry duration
Limitations of standard syslog timestamps
WorkingText goeswithhereH.323
Overview Endpoint Registration
Configuring H.323
XConfiguration H323
WorkingText goeswithhereSIP
SIP Overview
Configuring SIP Registrations, Protocols and Ports
XConfiguration SIP
Configuring SIP Domains
XCommand DomainAdd XConfiguration SIP Domains
Configuring Interworking
XConfiguration Interworking Mode
InterworkingesText here
Overview
MCU, Gateway and Content Server Registration
RegistrationText goes hereControl
Endpoint Registration
Registration Overview
Finding a VCS with which to Register
323
Preventing automatic registrations
H323 Gatekeeper AutoDiscovery
About Authentication
Authentication
Configuring Authentication
XConfiguration Authentication
Authentication using an Ldap Server
Alias Origin Setting
Configuring the Ldap Server Directory
Securing the Ldap Connection with TLS
Configuring Ldap Server settings
XConfiguration Ldap XConfiguration Authentication
Authentication using a Local Database
Configuring the Local Database
New
Create Credential
Attempts to Register using an Existing Alias
About Alias Registration
Registering Aliases
Alias Registration
XConfiguration Registration RestrictionPolicy
About Allow and Deny Lists
Patterns and Pattern Types
Allow and Deny Lists
XCommand AllowListAdd XConfiguration Registration AllowList
Managing Entries in the Allow List
XCommand DenyListAdd XConfiguration Registration DenyList
Managing Entries in the Deny List
Add Deny List Pattern
Registration Deny List
Example
Managing Zones, Neighbors and Alternates
About your Video Communications Network
About the Local Zone and its Subzones
Configuring the Local Zone and its Subzones
Local Zone and Subzones
Zones
Adding Zones Configuring Zones
XCommand ZoneAdd
XConfiguration Zones Zone
Create Zone
Match1 Match5
Configuring Zones All Types
Hop count
Configuring Neighbor Zones
SIP port
Configuring Traversal Client Zones
Retry interval
Protocol
SIP transport
Configuring Traversal Server Zones
Configuring Enum Zones
Configuring DNS Zones
DNS suffix
Determines whether H.323 calls will be allowed to this zone
Alternate 1 to Alternate 5 IP address
About Alternates Configuring Alternates
XConfiguration Alternates
Setting up a Dial Plan
About Dial Plans
Flat Dial Plan
Structured Dial Plan
Process
CallText Processinggoeshere
Locating a Destination Endpoint
Dialing by Address Types
Configuring Hop Counts
XConfiguration Zones Zone 1..200 HopCount
About Hop Counts
Hop Counts
Administrator Policy
About Administrator Policy
Administrator Policy and Authentication
Authentication Mode On
Enabling the use of Administrator Policy
To enable Administrator Policy
Administrator Policy Mode
Administrator Policy Mode to take effect
Configuring Administrator Policy via the Web Interface
Configuring Administrator Policy via a CPL script
Uploading a CPL Script
About CPL XSD files
Downloading policy files
UserText goesPolicyhere
About User Policy
Configuring User Policy Manager
XConfiguration Policy UserPolicy
Enabling User Policy on the VCS
Username
Creating a New User Account
About User Accounts
Managing FindMe User Accounts
Changing a User Password
Viewing Existing User Account Settings
Deleting a User Account
To change delete a FindMe user account
Tick the box next to the account you wish to delete
Click here to delete the selected accounts
Using TANDBERG’s FindMe
FindMe User Accounts Accessing the FindMe Configuration
About your FindMe User Account
About FindMe
Configuring your FindMe User Account
AliasText goSearchingshere and Transforming
Configuring Local Alias Transforms
XConfiguration Transform
Zone Searching and Transforming
Zone searching and alias transforming configuration
Configuring Zone Searches and Transforms
Default Settings
Combining Match Types and Priorities
Examples
Never Query a Zone
Always Query a Zone, Never Apply Transforms
User@example.com User@exampleusa.com
Filter Queries to a Zone Without Transforming
Changing the Prefix or Suffix Before Querying
Query a Zone for Both Original and Transformed Alias
Query a Zone for Two or More Transformed Aliases
URITextDialinggoeshere
URI Dialing Overview
An AlwaysMatch, or
Configuring Matches for DNS Zones
URI Dialing for Outgoing Calls
Adding and Configuring DNS Zones
XCommand ZoneAdd XConfiguration Zones Zone
Click Create Zone
Assigns a name to this zone
Configuring DNS Servers
XConfiguration IP DNS Server
URI Dialing for Incoming Calls
URI Dialing and Firewall Traversal
Example DNS Record Configuration
Recommended Configuration
ENUMText goesDialinghere
About Enum Dialing
Enum Dialing Overview
Enum Process
Prerequisites
Enum Dialing for Outgoing Calls
Mode of PatternMatch Pattern string Pattern type of Prefix
Configuring Matches for Enum Zones
Configuring Transforms for Enum Zones
Configuring Enum Zones
For Enum zones, this will be Enum
Configuring DNS Servers
Enum Dialing for Incoming Calls
Configuring DNS Naptr Records
About DNS Domains for Enum
Configuration
Recommended Configuration for Firewall Traversal
CallsText gtoesandherefrom Unregistered Endpoints
Calls to an Unregistered Endpoint
XConfiguration Call Services Fallback Alias
FallbackText goesAliashere
Fallback Alias
Example Use of a Fallback Alias
DisconnectingText goes herecalls
Identifying a Particular Call
Disconnecting a Call via the Web Interface
Disconnecting a Call via the CLI
Issues when Disconnecting SIP Calls
Disconnect
Firewall Traversal
Firewall Traversal Overview
About Firewall Traversal VCS as a Firewall Traversal Client
VCS as a Firewall Traversal Server
Firewall Traversal Protocols and Ports
323
Ports for Connections out to the Public Internet
Stun Ports
Firewall Traversal and Authentication
VCS
Configuring the VCS as a Traversal Client
Adding a New Traversal Client Zone
From the Type drop-down menu, select
TraversalClient Create Zone
Configuring a Traversal Client Zone
Alternate 1 Alternate 5 Address
TraversalServer Create Zone
Configuring the VCS as a Traversal Server
Adding a New Traversal Server Zone
TCP retry count Interval
Configuring a Traversal Server Zone
Demux mode
Configuring Traversal for Endpoints
XConfiguration Zones LocalZone Traversal H323
Configuring Traversal Server Ports
Assent call signaling port
323 H.460.18 call signaling port
Media demultiplexing RTP port
Stun Services
About Stun
Stun Binding Discovery
Stun Relay
Configuring Stun Services
XConfiguration Traversal Server
Example Network Deployment
Bandwidthth Controll
About Bandwidth Control
Subzones
Creating a Subzone
XCommand SubZoneAdd
BandwidthControl
Configuring a Subzone
To configure a subzone
XConfiguration Zones LocalZone SubZone
Subnet 2
Applying Bandwidth Limitations to Subzones
Types of Limitations
How Different Bandwidth Limitations are Managed
Per call inter Limits the bandwidth of any individual call
XCommand PipeAdd
About Pipes
Creating a new pipe
Creating Pipes
Editing Pipes
XConfiguration Bandwidth Pipe
Editing an Existing Pipe
Default Links
XCommand LinkAdd
About Links Creating Links
Creating a New Link
Editing Links
XConfiguration Bandwidth Link
Editing Links
Applying Pipes to Links
Default Links
Bandwidth Control
About Downspeeding
About the Default Call Bandwidth
Configuring the Default Call Bandwidth and Downspeeding
Bandwidth Control Examples
Example Without a Firewall
Example With a Firewall
VCS Border Controller Subzone Configuration
Enterprise VCS Subzone Configuration
MaintenanceText goes here
Backing up the Existing Configuration Before Upgrading
Upgrading Using SCP/PSCP
Upgrading Software
Upgrading via the Web Interface
Upgrading
XConfiguration Option 1..64 Key S 0
Option Keys
About Adding Extra Options
Adding Options via the CLI
Add Option Click Add Option
Adding Options via the Web Interface
Add option key
Security
About Security
Enabling Security
Passwords
System Snapshot
About the System Snapshot
Creating a System Snapshot
XCommand Boot
Restarting
About Restarting
About Shutting Down
CommandText goes hereReference xConfiguration
Http
Https
SSH
Total Mode On/Off
AliasOrigin LDAP/Endpoint/Combined
Request
Off the call will be rejected
One call
Far end were registered directly to the local system
Fallback Alias S 0
Port
H323 Gatekeeper CallSignaling
TCP
NTP
Option Key S 0
Off the VCS will not act as a SIP registrar
Tration will not be permitted
On the VCS will act as a DIP registrar
137
Snmp
CommunityName S 0
Stun
Rtcp
RTP
For any one call to or from an endpoint in the Default
Between two endpoints within the Default Subzone
Traversal Server
For any one call between two endpoints within
Intra Mode None/Limited/Unlimited
To or from an endpoint in this subzone
Name S 1 Assigns a name to this subzone Subnet Address S 0
Limit
Sets the total bandwidth limit in kbps of this subzone
Zones LocalZone Traversal H323 Cont
Order to keep the firewall’s NAT bindings open
RetryCount
VCS will attempt to send a TCP probe to the VCS
Enum
145
TLS TLS will be used
Transport TCP/TLS
TCP TCP will be used
Off Each call will use a separate pair of ports for
Plexing mode for calls from the traversal client
Zones TraversalClient
Zones TraversalServer TCPProbe KeepAliveInterval Cont
CommandText goes hereReference xCommand
XCommand Description Parameters
List, the registration will be permitted
PatternType Exact/Prefix/Suffix/Regex
List, the registration will not be permitted
XCommand
Description Parameters
Event/AuthenticationFailure
Status/Ethernet
Status/NTP
Status/LDAP
Pipe2 S 1
LinkAdd LinkDelete Locate OptionKeyAdd OptionKeyDelete
Pipe1 S 1
153
SubZoneAdd SubZoneDelete
PerCallInterMode None/Limited/Unlimited
PerCallInter
To Limited
TransformAdd TransformDelete ZoneAdd ZoneDelete
Each transform
ZoneList
CommandText goes hereReference xStatus
Option Key S 1 Description S 1
Server Address IPv4Addr/IPv6Addr Domain S 0
NTP
External Manager
Status On/Off URL S 1,255 Expression S 1,127 0..15 entries
160
161
Contact S 1,255 Path URI 1..10 S 1,255
Zones
163
164
165
166
167
IPv4
Status Active/Inactive/Failed Address IPv4Addr
Status Active/Inactive/Failed Address IPv4Addr IPv6
Status Active/Inactive/Failed Address IPv6Addr
169
Address-switch node
CPLText Referencgoeshere
Address
Otherwise node
Field
Authentication Mode On
Setup
Url-ID 323 ID H323-ID Dialled Digits DialedDigits
Subfield
URI
Rule-switch
CPL Script Actions Location
Unsupported CPL Elements
Proxy
Call Screening of Authenticated Users
CPL Examples
Call Screening Based on Alias
Vpengineering
Call Screening Based on Domain
Change of Domain Name
Block Calls from Default Zone and Default Subzone
Allow Calls from Locally Registered Endpoints Only
Restricting Access to a Local Gateway
RegularText goesExpressionhere Reference
About Regular Expressions
Will match against any sequence of characters
For a detailed description of regular expression syntax see
DNSText goesConfiguhereation
Overview Microsoft DNS Server
Verifying the SRV Record
Bind 8
LDAPText goesConfigurationhere
About the Ldap Databases Downloading the H.350 schemas
Installing the H.350 Schemas
Microsoft Active Directory
Adding H.350 Objects
Securing with TLS
. Copy the OpenLDAP files to the OpenLDAP schema directory
. Add the ldif file to the server using the command
OpenLDAP
Add the H.350 Objects
Bibliography
Reference Title Link
Glossary
Term Definition
IRQ
LAN
LRQ
NAT
Session Initiation Protocol
Protocol used to monitor network devices
Firewall NAT traversal for SIP. Defined by RFC 3489
Reliable communication protocol defined by RFC 791
187