Video Communication Server Administrator Guide
Getting Started
System Configuration
Table of Contents
Using TANDBERG’s FindMe
Administrator Policy
Call Processing
User Policy
Calls to and from Unregistered Endpoints
Enum Dialing Disconnecting calls
Fallback Alias
Firewall Traversal
DNS Configuration 79
Maintenance
Ldap Configuration 80
Regular Expression Reference 78
Copyright 2007, Tandberg
Trademarks and Copyright
Patent Information
Disclaimer, Copyrights and License Agreements
Disclaimer
Approvals
Safety Instructions and Approvals
Safety Instructions
Environmental Issues
Environmental Issues
Standard Features
Main Product Features
Optional Features
Introduction
Tandberg VCS
Connecting the Cables
Getting Started
Initial Configuration via Serial Cable
Powering on the VCS
System Administrator Access
Supported Browsers
Using the Web Interface
Using the Command Line Interface CLI
Understanding the Overview
ViewingText goesSystemhere Overview
Viewing the Overview
Configuring System Settings
Systemtext Configuration
About Admin Access settings
System Administration Configuration
Ethernet Configuration
Configuring Ethernet Settings
XConfiguration Ethernet
About Ethernet Speed
IP Configuration
Configuring IP Settings
XConfiguration IP XConfiguration IPProtocol
About IPv4 to IPv6 Gatewaying
Configuring DNS Settings
DNS Configuration
XConfiguration IP DNS
About DNS Servers
Setting the Time Zone
Configuring NTP Settings
NTP Configuration
XConfiguration NTP Address XConfiguration TimeZone Name
About Snmp Settings
Configuring Snmp Settings
Snmp Configuration
XConfiguration Snmp
External Manager Configuration
Configuring External Manager Settings
XConfiguration ExternalManager
About the External Manager
Backing up Configuration Settings
Logging Overview
Logging
Event Log
Viewing the Event Log
Event Log Format
Message Details Field
DNS
Events Logged at Level
Events Logged at Level 1
TCP UDP TLS
Event Data Fields
SIP
225 245
Number of bytes sent/received in the message
For Register requests the AOR for the Register request
Request/granted registration expiry duration
Limitations of standard syslog timestamps
Overview Endpoint Registration
WorkingText goeswithhereH.323
XConfiguration H323
Configuring H.323
SIP Overview
WorkingText goeswithhereSIP
XConfiguration SIP
Configuring SIP Registrations, Protocols and Ports
XCommand DomainAdd XConfiguration SIP Domains
Configuring SIP Domains
XConfiguration Interworking Mode
Configuring Interworking
InterworkingesText here
Overview
RegistrationText goes hereControl
MCU, Gateway and Content Server Registration
Endpoint Registration
Registration Overview
323
Finding a VCS with which to Register
Preventing automatic registrations
H323 Gatekeeper AutoDiscovery
Authentication
About Authentication
Configuring Authentication
XConfiguration Authentication
Alias Origin Setting
Authentication using an Ldap Server
Configuring the Ldap Server Directory
Securing the Ldap Connection with TLS
XConfiguration Ldap XConfiguration Authentication
Configuring Ldap Server settings
Configuring the Local Database
Authentication using a Local Database
New
Create Credential
About Alias Registration
Attempts to Register using an Existing Alias
Registering Aliases
Alias Registration
About Allow and Deny Lists
XConfiguration Registration RestrictionPolicy
Patterns and Pattern Types
Allow and Deny Lists
Managing Entries in the Allow List
XCommand AllowListAdd XConfiguration Registration AllowList
Managing Entries in the Deny List
XCommand DenyListAdd XConfiguration Registration DenyList
Add Deny List Pattern
Registration Deny List
Example
Managing Zones, Neighbors and Alternates
About your Video Communications Network
About the Local Zone and its Subzones
Configuring the Local Zone and its Subzones
Local Zone and Subzones
Zones
XCommand ZoneAdd
Adding Zones Configuring Zones
XConfiguration Zones Zone
Create Zone
Match1 Match5
Configuring Zones All Types
Hop count
SIP port
Configuring Neighbor Zones
Retry interval
Configuring Traversal Client Zones
Protocol
SIP transport
Configuring Traversal Server Zones
Configuring DNS Zones
Configuring Enum Zones
DNS suffix
Determines whether H.323 calls will be allowed to this zone
Alternate 1 to Alternate 5 IP address
About Alternates Configuring Alternates
XConfiguration Alternates
About Dial Plans
Setting up a Dial Plan
Flat Dial Plan
Structured Dial Plan
Process
CallText Processinggoeshere
Locating a Destination Endpoint
Dialing by Address Types
XConfiguration Zones Zone 1..200 HopCount
Configuring Hop Counts
About Hop Counts
Hop Counts
About Administrator Policy
Administrator Policy
Administrator Policy and Authentication
Authentication Mode On
To enable Administrator Policy
Enabling the use of Administrator Policy
Administrator Policy Mode
Administrator Policy Mode to take effect
Configuring Administrator Policy via the Web Interface
Uploading a CPL Script
Configuring Administrator Policy via a CPL script
About CPL XSD files
Downloading policy files
About User Policy
UserText goesPolicyhere
XConfiguration Policy UserPolicy
Configuring User Policy Manager
Enabling User Policy on the VCS
Username
Creating a New User Account
About User Accounts
Managing FindMe User Accounts
Viewing Existing User Account Settings
Changing a User Password
To change delete a FindMe user account
Deleting a User Account
Tick the box next to the account you wish to delete
Click here to delete the selected accounts
FindMe User Accounts Accessing the FindMe Configuration
Using TANDBERG’s FindMe
About your FindMe User Account
About FindMe
Configuring your FindMe User Account
AliasText goSearchingshere and Transforming
XConfiguration Transform
Configuring Local Alias Transforms
Zone Searching and Transforming
Zone searching and alias transforming configuration
Configuring Zone Searches and Transforms
Default Settings
Examples
Combining Match Types and Priorities
Never Query a Zone
Always Query a Zone, Never Apply Transforms
User@example.com User@exampleusa.com
Filter Queries to a Zone Without Transforming
Changing the Prefix or Suffix Before Querying
Query a Zone for Two or More Transformed Aliases
Query a Zone for Both Original and Transformed Alias
URI Dialing Overview
URITextDialinggoeshere
An AlwaysMatch, or
Configuring Matches for DNS Zones
URI Dialing for Outgoing Calls
XCommand ZoneAdd XConfiguration Zones Zone
Adding and Configuring DNS Zones
Click Create Zone
Assigns a name to this zone
XConfiguration IP DNS Server
Configuring DNS Servers
URI Dialing for Incoming Calls
URI Dialing and Firewall Traversal
Example DNS Record Configuration
Recommended Configuration
About Enum Dialing
ENUMText goesDialinghere
Enum Dialing Overview
Enum Process
Enum Dialing for Outgoing Calls
Prerequisites
Mode of PatternMatch Pattern string Pattern type of Prefix
Configuring Matches for Enum Zones
Configuring Transforms for Enum Zones
For Enum zones, this will be Enum
Configuring Enum Zones
Configuring DNS Servers
Enum Dialing for Incoming Calls
Configuring DNS Naptr Records
About DNS Domains for Enum
Recommended Configuration for Firewall Traversal
Configuration
CallsText gtoesandherefrom Unregistered Endpoints
Calls to an Unregistered Endpoint
FallbackText goesAliashere
XConfiguration Call Services Fallback Alias
Fallback Alias
Example Use of a Fallback Alias
Identifying a Particular Call
DisconnectingText goes herecalls
Disconnecting a Call via the CLI
Disconnecting a Call via the Web Interface
Issues when Disconnecting SIP Calls
Disconnect
Firewall Traversal Overview
Firewall Traversal
About Firewall Traversal VCS as a Firewall Traversal Client
VCS as a Firewall Traversal Server
Firewall Traversal Protocols and Ports
323
Ports for Connections out to the Public Internet
Stun Ports
VCS
Firewall Traversal and Authentication
Adding a New Traversal Client Zone
Configuring the VCS as a Traversal Client
From the Type drop-down menu, select
TraversalClient Create Zone
Alternate 1 Alternate 5 Address
Configuring a Traversal Client Zone
TraversalServer Create Zone
Configuring the VCS as a Traversal Server
Adding a New Traversal Server Zone
TCP retry count Interval
Configuring a Traversal Server Zone
Demux mode
XConfiguration Zones LocalZone Traversal H323
Configuring Traversal for Endpoints
Assent call signaling port
Configuring Traversal Server Ports
323 H.460.18 call signaling port
Media demultiplexing RTP port
About Stun
Stun Services
Stun Binding Discovery
Stun Relay
XConfiguration Traversal Server
Configuring Stun Services
Example Network Deployment
Bandwidthth Controll
About Bandwidth Control
Subzones
Creating a Subzone
XCommand SubZoneAdd
BandwidthControl
To configure a subzone
Configuring a Subzone
XConfiguration Zones LocalZone SubZone
Subnet 2
Types of Limitations
Applying Bandwidth Limitations to Subzones
How Different Bandwidth Limitations are Managed
Per call inter Limits the bandwidth of any individual call
About Pipes
XCommand PipeAdd
Creating a new pipe
Creating Pipes
Editing Pipes
XConfiguration Bandwidth Pipe
Editing an Existing Pipe
XCommand LinkAdd
Default Links
About Links Creating Links
Creating a New Link
Editing Links
XConfiguration Bandwidth Link
Editing Links
Applying Pipes to Links
Default Links
Bandwidth Control
About Downspeeding
About the Default Call Bandwidth
Configuring the Default Call Bandwidth and Downspeeding
Example Without a Firewall
Bandwidth Control Examples
Example With a Firewall
VCS Border Controller Subzone Configuration
Enterprise VCS Subzone Configuration
Backing up the Existing Configuration Before Upgrading
MaintenanceText goes here
Upgrading Using SCP/PSCP
Upgrading Software
Upgrading
Upgrading via the Web Interface
Option Keys
XConfiguration Option 1..64 Key S 0
About Adding Extra Options
Adding Options via the CLI
Add Option Click Add Option
Adding Options via the Web Interface
Add option key
Security
About Security
Enabling Security
System Snapshot
Passwords
About the System Snapshot
Creating a System Snapshot
Restarting
XCommand Boot
About Restarting
About Shutting Down
Http
CommandText goes hereReference xConfiguration
Https
SSH
AliasOrigin LDAP/Endpoint/Combined
Total Mode On/Off
Request
Off the call will be rejected
One call
Fallback Alias S 0
Far end were registered directly to the local system
Port
H323 Gatekeeper CallSignaling
TCP
NTP
Option Key S 0
Off the VCS will not act as a SIP registrar
Tration will not be permitted
On the VCS will act as a DIP registrar
137
CommunityName S 0
Snmp
Stun
Rtcp
RTP
Between two endpoints within the Default Subzone
For any one call to or from an endpoint in the Default
Traversal Server
For any one call between two endpoints within
To or from an endpoint in this subzone
Intra Mode None/Limited/Unlimited
Name S 1 Assigns a name to this subzone Subnet Address S 0
Limit
Sets the total bandwidth limit in kbps of this subzone
Order to keep the firewall’s NAT bindings open
Zones LocalZone Traversal H323 Cont
RetryCount
VCS will attempt to send a TCP probe to the VCS
Enum
145
TLS TLS will be used
Transport TCP/TLS
TCP TCP will be used
Off Each call will use a separate pair of ports for
Plexing mode for calls from the traversal client
Zones TraversalClient
Zones TraversalServer TCPProbe KeepAliveInterval Cont
XCommand Description Parameters
CommandText goes hereReference xCommand
List, the registration will be permitted
PatternType Exact/Prefix/Suffix/Regex
List, the registration will not be permitted
XCommand
Description Parameters
Status/Ethernet
Event/AuthenticationFailure
Status/NTP
Status/LDAP
Pipe2 S 1
LinkAdd LinkDelete Locate OptionKeyAdd OptionKeyDelete
Pipe1 S 1
153
PerCallInterMode None/Limited/Unlimited
SubZoneAdd SubZoneDelete
PerCallInter
To Limited
Each transform
TransformAdd TransformDelete ZoneAdd ZoneDelete
ZoneList
Option Key S 1 Description S 1
CommandText goes hereReference xStatus
NTP
Server Address IPv4Addr/IPv6Addr Domain S 0
Status On/Off URL S 1,255 Expression S 1,127 0..15 entries
External Manager
160
161
Zones
Contact S 1,255 Path URI 1..10 S 1,255
163
164
165
166
167
Status Active/Inactive/Failed Address IPv4Addr
IPv4
Status Active/Inactive/Failed Address IPv4Addr IPv6
Status Active/Inactive/Failed Address IPv6Addr
169
CPLText Referencgoeshere
Address-switch node
Address
Otherwise node
Field
Authentication Mode On
Setup
Url-ID 323 ID H323-ID Dialled Digits DialedDigits
Subfield
URI
CPL Script Actions Location
Rule-switch
Unsupported CPL Elements
Proxy
CPL Examples
Call Screening of Authenticated Users
Call Screening Based on Alias
Vpengineering
Change of Domain Name
Call Screening Based on Domain
Allow Calls from Locally Registered Endpoints Only
Block Calls from Default Zone and Default Subzone
Restricting Access to a Local Gateway
About Regular Expressions
RegularText goesExpressionhere Reference
Will match against any sequence of characters
For a detailed description of regular expression syntax see
Overview Microsoft DNS Server
DNSText goesConfiguhereation
Verifying the SRV Record
Bind 8
About the Ldap Databases Downloading the H.350 schemas
LDAPText goesConfigurationhere
Microsoft Active Directory
Installing the H.350 Schemas
Adding H.350 Objects
Securing with TLS
. Add the ldif file to the server using the command
. Copy the OpenLDAP files to the OpenLDAP schema directory
OpenLDAP
Add the H.350 Objects
Reference Title Link
Bibliography
Term Definition
Glossary
LAN
IRQ
LRQ
NAT
Protocol used to monitor network devices
Session Initiation Protocol
Firewall NAT traversal for SIP. Defined by RFC 3489
Reliable communication protocol defined by RFC 791
187