Video Communication Server Administrator Guide
System Configuration
Getting Started
Table of Contents
Administrator Policy
Using TANDBERG’s FindMe
Call Processing
User Policy
Enum Dialing Disconnecting calls
Calls to and from Unregistered Endpoints
Fallback Alias
Firewall Traversal
Maintenance
DNS Configuration 79
Ldap Configuration 80
Regular Expression Reference 78
Trademarks and Copyright
Copyright 2007, Tandberg
Disclaimer
Disclaimer, Copyrights and License Agreements
Patent Information
Safety Instructions
Safety Instructions and Approvals
Approvals
Environmental Issues
Environmental Issues
Main Product Features
Standard Features
Optional Features
Introduction
Getting Started
Connecting the Cables
Tandberg VCS
Powering on the VCS
Initial Configuration via Serial Cable
System Administrator Access
Using the Web Interface
Supported Browsers
Using the Command Line Interface CLI
Viewing the Overview
ViewingText goesSystemhere Overview
Understanding the Overview
Systemtext Configuration
Configuring System Settings
About Admin Access settings
System Administration Configuration
Configuring Ethernet Settings
Ethernet Configuration
XConfiguration Ethernet
About Ethernet Speed
Configuring IP Settings
IP Configuration
XConfiguration IP XConfiguration IPProtocol
About IPv4 to IPv6 Gatewaying
DNS Configuration
Configuring DNS Settings
XConfiguration IP DNS
About DNS Servers
Configuring NTP Settings
Setting the Time Zone
NTP Configuration
XConfiguration NTP Address XConfiguration TimeZone Name
Configuring Snmp Settings
About Snmp Settings
Snmp Configuration
XConfiguration Snmp
Configuring External Manager Settings
External Manager Configuration
XConfiguration ExternalManager
About the External Manager
Backing up Configuration Settings
Logging
Logging Overview
Viewing the Event Log
Event Log
Event Log Format
Message Details Field
Events Logged at Level
DNS
Events Logged at Level 1
Event Data Fields
TCP UDP TLS
SIP
225 245
For Register requests the AOR for the Register request
Number of bytes sent/received in the message
Request/granted registration expiry duration
Limitations of standard syslog timestamps
WorkingText goeswithhereH.323
Overview Endpoint Registration
Configuring H.323
XConfiguration H323
WorkingText goeswithhereSIP
SIP Overview
Configuring SIP Registrations, Protocols and Ports
XConfiguration SIP
Configuring SIP Domains
XCommand DomainAdd XConfiguration SIP Domains
Configuring Interworking
XConfiguration Interworking Mode
InterworkingesText here
Overview
MCU, Gateway and Content Server Registration
RegistrationText goes hereControl
Endpoint Registration
Registration Overview
Finding a VCS with which to Register
323
Preventing automatic registrations
H323 Gatekeeper AutoDiscovery
About Authentication
Authentication
Configuring Authentication
XConfiguration Authentication
Authentication using an Ldap Server
Alias Origin Setting
Configuring the Ldap Server Directory
Securing the Ldap Connection with TLS
Configuring Ldap Server settings
XConfiguration Ldap XConfiguration Authentication
Authentication using a Local Database
Configuring the Local Database
New
Create Credential
Attempts to Register using an Existing Alias
About Alias Registration
Registering Aliases
Alias Registration
XConfiguration Registration RestrictionPolicy
About Allow and Deny Lists
Patterns and Pattern Types
Allow and Deny Lists
XCommand AllowListAdd XConfiguration Registration AllowList
Managing Entries in the Allow List
XCommand DenyListAdd XConfiguration Registration DenyList
Managing Entries in the Deny List
Add Deny List Pattern
Registration Deny List
About your Video Communications Network
Managing Zones, Neighbors and Alternates
Example
Local Zone and Subzones
Configuring the Local Zone and its Subzones
About the Local Zone and its Subzones
Zones
Adding Zones Configuring Zones
XCommand ZoneAdd
XConfiguration Zones Zone
Create Zone
Hop count
Configuring Zones All Types
Match1 Match5
Configuring Neighbor Zones
SIP port
Configuring Traversal Client Zones
Retry interval
Protocol
SIP transport
Configuring Traversal Server Zones
Configuring Enum Zones
Configuring DNS Zones
DNS suffix
Determines whether H.323 calls will be allowed to this zone
XConfiguration Alternates
About Alternates Configuring Alternates
Alternate 1 to Alternate 5 IP address
Setting up a Dial Plan
About Dial Plans
Flat Dial Plan
Structured Dial Plan
Locating a Destination Endpoint
CallText Processinggoeshere
Process
Dialing by Address Types
Configuring Hop Counts
XConfiguration Zones Zone 1..200 HopCount
About Hop Counts
Hop Counts
Administrator Policy
About Administrator Policy
Administrator Policy and Authentication
Authentication Mode On
Enabling the use of Administrator Policy
To enable Administrator Policy
Administrator Policy Mode
Administrator Policy Mode to take effect
Configuring Administrator Policy via the Web Interface
Configuring Administrator Policy via a CPL script
Uploading a CPL Script
About CPL XSD files
Downloading policy files
UserText goesPolicyhere
About User Policy
Configuring User Policy Manager
XConfiguration Policy UserPolicy
Enabling User Policy on the VCS
Username
Managing FindMe User Accounts
About User Accounts
Creating a New User Account
Changing a User Password
Viewing Existing User Account Settings
Deleting a User Account
To change delete a FindMe user account
Tick the box next to the account you wish to delete
Click here to delete the selected accounts
Using TANDBERG’s FindMe
FindMe User Accounts Accessing the FindMe Configuration
About your FindMe User Account
About FindMe
Configuring your FindMe User Account
AliasText goSearchingshere and Transforming
Configuring Local Alias Transforms
XConfiguration Transform
Zone Searching and Transforming
Default Settings
Configuring Zone Searches and Transforms
Zone searching and alias transforming configuration
Combining Match Types and Priorities
Examples
Never Query a Zone
Always Query a Zone, Never Apply Transforms
Changing the Prefix or Suffix Before Querying
Filter Queries to a Zone Without Transforming
User@example.com User@exampleusa.com
Query a Zone for Both Original and Transformed Alias
Query a Zone for Two or More Transformed Aliases
URITextDialinggoeshere
URI Dialing Overview
URI Dialing for Outgoing Calls
Configuring Matches for DNS Zones
An AlwaysMatch, or
Adding and Configuring DNS Zones
XCommand ZoneAdd XConfiguration Zones Zone
Click Create Zone
Assigns a name to this zone
Configuring DNS Servers
XConfiguration IP DNS Server
URI Dialing for Incoming Calls
Recommended Configuration
Example DNS Record Configuration
URI Dialing and Firewall Traversal
ENUMText goesDialinghere
About Enum Dialing
Enum Dialing Overview
Enum Process
Prerequisites
Enum Dialing for Outgoing Calls
Configuring Transforms for Enum Zones
Configuring Matches for Enum Zones
Mode of PatternMatch Pattern string Pattern type of Prefix
Configuring Enum Zones
For Enum zones, this will be Enum
Configuring DNS Servers
About DNS Domains for Enum
Configuring DNS Naptr Records
Enum Dialing for Incoming Calls
Configuration
Recommended Configuration for Firewall Traversal
CallsText gtoesandherefrom Unregistered Endpoints
Calls to an Unregistered Endpoint
XConfiguration Call Services Fallback Alias
FallbackText goesAliashere
Fallback Alias
Example Use of a Fallback Alias
DisconnectingText goes herecalls
Identifying a Particular Call
Disconnecting a Call via the Web Interface
Disconnecting a Call via the CLI
Issues when Disconnecting SIP Calls
Disconnect
Firewall Traversal
Firewall Traversal Overview
About Firewall Traversal VCS as a Firewall Traversal Client
VCS as a Firewall Traversal Server
Firewall Traversal Protocols and Ports
Stun Ports
Ports for Connections out to the Public Internet
323
Firewall Traversal and Authentication
VCS
Configuring the VCS as a Traversal Client
Adding a New Traversal Client Zone
From the Type drop-down menu, select
TraversalClient Create Zone
Configuring a Traversal Client Zone
Alternate 1 Alternate 5 Address
Adding a New Traversal Server Zone
Configuring the VCS as a Traversal Server
TraversalServer Create Zone
Demux mode
Configuring a Traversal Server Zone
TCP retry count Interval
Configuring Traversal for Endpoints
XConfiguration Zones LocalZone Traversal H323
Configuring Traversal Server Ports
Assent call signaling port
323 H.460.18 call signaling port
Media demultiplexing RTP port
Stun Services
About Stun
Stun Binding Discovery
Stun Relay
Configuring Stun Services
XConfiguration Traversal Server
About Bandwidth Control
Bandwidthth Controll
Example Network Deployment
Subzones
BandwidthControl
XCommand SubZoneAdd
Creating a Subzone
Configuring a Subzone
To configure a subzone
XConfiguration Zones LocalZone SubZone
Subnet 2
Applying Bandwidth Limitations to Subzones
Types of Limitations
How Different Bandwidth Limitations are Managed
Per call inter Limits the bandwidth of any individual call
XCommand PipeAdd
About Pipes
Creating a new pipe
Creating Pipes
Editing an Existing Pipe
XConfiguration Bandwidth Pipe
Editing Pipes
Default Links
XCommand LinkAdd
About Links Creating Links
Creating a New Link
Editing Links
XConfiguration Bandwidth Link
Editing Links
Bandwidth Control
Default Links
Applying Pipes to Links
Configuring the Default Call Bandwidth and Downspeeding
About the Default Call Bandwidth
About Downspeeding
Bandwidth Control Examples
Example Without a Firewall
Enterprise VCS Subzone Configuration
VCS Border Controller Subzone Configuration
Example With a Firewall
MaintenanceText goes here
Backing up the Existing Configuration Before Upgrading
Upgrading Using SCP/PSCP
Upgrading Software
Upgrading via the Web Interface
Upgrading
XConfiguration Option 1..64 Key S 0
Option Keys
About Adding Extra Options
Adding Options via the CLI
Add option key
Adding Options via the Web Interface
Add Option Click Add Option
Enabling Security
About Security
Security
Passwords
System Snapshot
About the System Snapshot
Creating a System Snapshot
XCommand Boot
Restarting
About Restarting
About Shutting Down
CommandText goes hereReference xConfiguration
Http
Https
SSH
Total Mode On/Off
AliasOrigin LDAP/Endpoint/Combined
Request
Off the call will be rejected
One call
Far end were registered directly to the local system
Fallback Alias S 0
TCP
H323 Gatekeeper CallSignaling
Port
NTP
Option Key S 0
On the VCS will act as a DIP registrar
Tration will not be permitted
Off the VCS will not act as a SIP registrar
137
Snmp
CommunityName S 0
RTP
Rtcp
Stun
For any one call to or from an endpoint in the Default
Between two endpoints within the Default Subzone
Traversal Server
For any one call between two endpoints within
Intra Mode None/Limited/Unlimited
To or from an endpoint in this subzone
Sets the total bandwidth limit in kbps of this subzone
Limit
Name S 1 Assigns a name to this subzone Subnet Address S 0
Zones LocalZone Traversal H323 Cont
Order to keep the firewall’s NAT bindings open
RetryCount
VCS will attempt to send a TCP probe to the VCS
Enum
145
TCP TCP will be used
Transport TCP/TLS
TLS TLS will be used
Zones TraversalClient
Plexing mode for calls from the traversal client
Off Each call will use a separate pair of ports for
Zones TraversalServer TCPProbe KeepAliveInterval Cont
CommandText goes hereReference xCommand
XCommand Description Parameters
List, the registration will be permitted
PatternType Exact/Prefix/Suffix/Regex
Description Parameters
XCommand
List, the registration will not be permitted
Event/AuthenticationFailure
Status/Ethernet
Status/NTP
Status/LDAP
Pipe1 S 1
LinkAdd LinkDelete Locate OptionKeyAdd OptionKeyDelete
Pipe2 S 1
153
SubZoneAdd SubZoneDelete
PerCallInterMode None/Limited/Unlimited
PerCallInter
To Limited
TransformAdd TransformDelete ZoneAdd ZoneDelete
Each transform
ZoneList
CommandText goes hereReference xStatus
Option Key S 1 Description S 1
Server Address IPv4Addr/IPv6Addr Domain S 0
NTP
External Manager
Status On/Off URL S 1,255 Expression S 1,127 0..15 entries
160
161
Contact S 1,255 Path URI 1..10 S 1,255
Zones
163
164
165
166
167
IPv4
Status Active/Inactive/Failed Address IPv4Addr
Status Active/Inactive/Failed Address IPv4Addr IPv6
Status Active/Inactive/Failed Address IPv6Addr
169
Address-switch node
CPLText Referencgoeshere
Address
Otherwise node
Setup
Authentication Mode On
Field
URI
Subfield
Url-ID 323 ID H323-ID Dialled Digits DialedDigits
Rule-switch
CPL Script Actions Location
Unsupported CPL Elements
Proxy
Call Screening of Authenticated Users
CPL Examples
Call Screening Based on Alias
Vpengineering
Call Screening Based on Domain
Change of Domain Name
Block Calls from Default Zone and Default Subzone
Allow Calls from Locally Registered Endpoints Only
Restricting Access to a Local Gateway
RegularText goesExpressionhere Reference
About Regular Expressions
Will match against any sequence of characters
For a detailed description of regular expression syntax see
DNSText goesConfiguhereation
Overview Microsoft DNS Server
Verifying the SRV Record
Bind 8
LDAPText goesConfigurationhere
About the Ldap Databases Downloading the H.350 schemas
Installing the H.350 Schemas
Microsoft Active Directory
Adding H.350 Objects
Securing with TLS
. Copy the OpenLDAP files to the OpenLDAP schema directory
. Add the ldif file to the server using the command
OpenLDAP
Add the H.350 Objects
Bibliography
Reference Title Link
Glossary
Term Definition
IRQ
LAN
LRQ
NAT
Session Initiation Protocol
Protocol used to monitor network devices
Firewall NAT traversal for SIP. Defined by RFC 3489
Reliable communication protocol defined by RFC 791
187