Cisco Systems OL-14619-01 Network Router User Manual


 
6-15
Design Guide for Cisco Unity Release 5.x
OL-14619-01
Chapter 6 Integrating Cisco Unity with the Phone System
Integrating with Cisco Unified Communications Manager (by Using SCCP or SIP)
The process of authentication and encryption of Cisco Unity voice messaging ports is as follows:
1. Each Cisco Unity voice messaging port connects to the TFTP server, downloads the CTL file, and
extracts the certificates for all Cisco Unified
CM servers.
2. Each Cisco Unity voice messaging port establishes a network connection to the Cisco Unified CM
TLS port through Winsock. By default, the TLS port is 2443, though the port number is
configurable.
3. Each Cisco Unity voice messaging port establishes a TLS connection to the Cisco Unified CM
server, verifies the device certificate, and authenticates the voice messaging port.
4. Each Cisco Unity voice messaging port registers with the Cisco Unified CM server, specifying
whether the voice messaging port will also use media encryption.
When Data Is Encrypted
When a call is made between Cisco Unity and Cisco Unified CM, the call-signaling messages and the
media stream are handled in the following manner:
If both end points are set for encrypted mode, the call-signaling messages and the media stream are
encrypted.
If one end point is set for authenticated mode and the other end point is set for encrypted mode, the
call-signaling messages are authenticated, but neither the call-signaling messages nor the media
stream are encrypted.
If one end point is set for non-secure mode and the other end point is set for encrypted mode, neither
the call-signaling messages nor the media stream are encrypted.
Cisco Unified Communications Manager Cluster Security Mode Settings in Cisco Unity
The Cisco Unified CM cluster security mode settings in the Cisco Unity Telephony Integration Manager
(UTIM) determine how the ports handle call-signaling messages and whether encryption of the media
stream is possible.
Table 6-4 describes the effect of the Cluster Security Mode settings in UTIM.
Table 6-4 Cisco Unified Communications Manager Cluster Security Mode Settings for Voice Messaging Ports
Setting Effect
Non-secure The integrity and privacy of call-signaling messages will not be ensured because call-signaling
messages will be sent as clear (unencrypted) text and will be connected to Cisco Unified
CM through
a non-authenticated port rather than an authenticated TLS port.
The media stream is not encrypted.