Cucm 8.6 to 10.5 and cisco phone 7911
Hi,
WE will upgrade to cucm 8.6 to 10.5.
We have a lot of sccp 7911 phone.
Can we use this phone with 10.5 ?
Will we find the software for this phone in the 10.5 devicepack ?
If not can i install cmterm-7911_7906-sccp.9-4-2-1.cop.sgn to cucm 10.5
Tanks
Yes, we have not removed any phones from the drop down
If you want to know what FW is included in a DevPack, read the DevPack documentation.
Same for device FW, if you review the info on downloads (see below), or FW documentation, you'll find compatibility
7911/7906 SCCP IP Phone load - Compatible CUCM Versions: 5.0.4, 5.1.3, 6.0.1, 6.1.3, 6.1.4, 7.0.2, 7.1.2 and above
cmterm-7911_7906-sccp.9-4-2-1.cop.sgn
Similar Messages
-
Cdr doesn't bill Cisco phone 6901 Call Manager release 9
Hello Engineers,
Actually I opened a TAC for a problem that I got in my customer's environment.
I have CUCM release 9 and Cisco phone 6901 - firmware: SCCP6901.9-3-2.loads
When I tried to see the calls from CAR I didn't get output from the CAR/CDR.
I did an upload to the firmware SCCP6901.9-3-1-SR1-3.loads.
After that all calls were ok.
I hope this post can help anothers engineersHi Karina,
Thanks for taking time out of your busy schedule to help others
here @ CSC Much appreciated!
Cheers!
Rob
"Seek it out and ye shall find "
- OneRepublic -
How to create multiple sip trunks between cucm and cisco unified sip proxy
Dear Expert,
Is there a way to create multiple sip trunks between CUCM and Cisco Unified SIP Proxy (CUSP)? How to achieve it without creating multiple IP interfaces on the CUSP module.
CUCM: 8.5.1.10000-9
CUSP: 8.5.2
Thank you,
.wanHello Michael,
This SIP trunk is part of UCCE solution, which used between CVP, CUSP, and CUCM.
The requirements:
1) To have different codecs for different type of calls, as the phones are at few countries
2) To pass different number of digits from CUSP to CUCM for different call treatments
.wan -
Cisco phone proxy will support on cucm 8.6 or not
Hi as per document i can see that Cisco phone proxy . Without using vpn connect . Customer want to keep configured Cucm on there Jabber or cisco mobile on the iphone and need to get connected when ever they have an internet access .
And also by keeping a small end router at branches havin only one cisco phone needs to connect to the corprate office using proxy.
Is that possible and also is it possible on 8.6 cucm version . Here am just attaching a document info which says version supported
Supported Cisco UCM and IP Phones for the Phone Proxy
Cisco Unified Communications Manager
The following release of the Cisco Unified Communications Manager are supported with the phone proxy:
•Cisco Unified CallManager Version 4.x
•Cisco Unified CallManager Version 5.0
•Cisco Unified CallManager Version 5.1
•Cisco Unified Communications Manager 6.1
•Cisco Unified Communications Manager 7.0I understand the VPN solution is a good one, but we have already 100 proxy phones deployed and from what I read I'd need to first set up a VPN phone on the cluster before deploying it in the field. This would be difficult to do with users all over the country. Or am I missing something?
I have a question about our ASA though if anyone can answer it. We have to move from an ASA 5510 to a 5520 due to the 100 UC proxy-phone license limitation (even though we have 70 phones it appears that a UC license is taken up for each TFTP server configured on the phone - primary and secondary). When I configured the 5520 I can register new phones no problem. None of the existing phones will register until the CTL file is manually deleted on each phone. Is there a way to seamlessly migrate to the 5520? Such as using the same certs, CTL file etc.. on the 5520? When I configured it it generated it's own self-signed key and CTL file. I did import the certificates from CUCM... -
Hi community,
I am trying to integrate Cisco Unified Presence 8.6.1.10000-34 with IBM Lotus Notes 8.5.2 with the integrated Sametime Client version 8.0.2 via the Cisco Plugins 8.6.1.1185.
Phone control is working fine, whereas the presence status is not shown (= no handset symbol next to the Sametime user). When I look in the preferences of the plugin, I can see that the plugin has connected successfully to the CUCM (8.6.2.20000-2),whereas the connection to the CUPS has not been established.
The user id as well as the password are all the same on all systems. Here is a description of what I have configured via the ciscocfg.exe tool:
Feature Control:
- Enable Phone Status -> checked
- Enable Dial Using Cisco IP Communicator -> unchecked (not required)
- Enable Control Desk Phone -> checked
- Default Mode -> Control Desk Phone
Control Desk Phone Settings:
- Voicemail Pilot Number -> left blank (no voicemail)
- Cisco Unified Communications Manager
- Servers -> IP address of CUCM
- Read Only -> unchecked
- Use as Default CUCM -> checked
- Synchronize Credentials -> checked
- Use Sametime Credentials -> checked
Use Secure Connection: -> not required
LDAP Phone Attributes: -> not required
Phone Status Settings:
- Cisco Unified Presence Servers -> IP address of CUPS
- Read Only -> unchecked
- Synchronize Credentials -> checked
- Use Sametime Credentials -> checked
- Sametime User ID Mapping
- Use Business Card Attribute -> MailAddress
- Remove Domain -> checked
- Display Off-Hook Status Only -> unchecked
At the moment I don't see an error in the configuration, but maybe I am wrong. Could anyone please tell me what the error could be?
Thanks a lot in advance!
Kind regards,
IgorHi all,
here are some additions to my above post:
Servers and clients used:
1x CUCM 8.6.2.20000-2
1x CUPS 8.6.1.10000-34
1x IBM Lotus Domino Messaging Express Server 8.5.2
1x Sametime Entry Server 8.5.2 (on top of the Domino server)
2x IBM Lotus Notes 8.5.2 with integrated Sametime 8.0.2
2x Cisco Phone Control and Presence with Lotus Sametime (PCAP) 8.6.1.1185
2x Cisco Unified Personal Communicator 8.5.5.19839
Setup:
- CUCM, CUPS and CUPC are working fine, i.e. Desk Phone control via CUPC, as well as availability and presence status are working without issues
- IBM Lotus Domino server is the LDAP Directory, the Sametime Entry Server is installed on top of the Domino server and uses the Domino Directory
- User ID and password on CUCM/CUPS match the ShortName field and password in Domino
- The PCAP plug-in has been manually deployed to both Notes clients with the following configuration:
- Enable Phone Status -> active
- Desk Phone Control -> active
- no credential synchronization for CUCM and CUPS, i.e. every user must fill the user details himself
- Sametime User ID Mapping is implemented via the LDAP Attribute uid (which is equal to the user id in CUCM)
- LDAP configuration filled in with details of the Domino server
Phone Control is working fine, also the connection to the LDAP server (Domino) is fine. However, when I type in the credentials for the CUPS server login, I can see (in Troubleshooting pane) that the user (pparker) is connected to the CUPS server for a short period of time and then gets disconnected. After that no connection is possible to the CUPS server, i.e. status is always disconnected.
I have collected the Tomcat (EPASSoap00010.log and security00010.log) logs via RTMT and compared them to the logs from the PCAP plugin. The relevant time period is from 15:14 to 15:17. In the Tomcat logs I can see that the authentication is successful (see attached files), however in the log of PCAP plugin I can see the following messages:
2012/02/03 15:14:35.281 WARNUNG Credential is rejected. Nothing to retry ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.answerChallenge() ::thread=CT_CALLBACK.1 ::loggername=com.cisco.sametime.phonestatus.cup
2012/02/03 15:14:35.281 WARNUNG #### Connection rejected presence server ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.onPresenceServerConnectionRejected() ::thread=CT_CALLBACK.1 ::loggername=com.cisco.sametime.phonestatus.cup
2012/02/03 15:14:35.281 WARNUNG Credential is rejected. Nothing to retry ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.answerChallenge() ::thread=CT_CALLBACK.2 ::loggername=com.cisco.sametime.phonestatus.cup
2012/02/03 15:14:35.281 WARNUNG #### Connection rejected presence server ::class.method=com.cisco.sametime.phonestatus.cup.CUPPresenceWatcher.onPresenceServerConnectionRejected() ::thread=CT_CALLBACK.2 ::loggername=com.cisco.sametime.phonestatus.cup
I don't understand why the connection is rejected although the Sametime Internal ID and CUPS User ID match. Does anyone know what the issue could be?
All posts are very much appreciated!
Thanks a lot in advance!
Kind regards,
Igor -
CUCM 10 Barge/CBarge with shared line between phone and a remote device
Is it possible to configure CBARGE/BARGE feature if shared line is between a cisco phone and a remote device.
When remote device picks up the phone, red light comes up on the phone, if we press the line button to Cbarge, dial tone comes up and the call does not go into a conference.
Has anyone used that feature? Can it be configured?We are using Lync for tesing purposes.
we tried scenario with Remote device as a mobile phone. Where calls are being sent through SIP trunk to CUBE and then to our provider. Maybe I should add some commands on CUBE router?
Is that feature (CBARGE) designed to work in that scenario when shared line is answered via remote device on CUCM 10.5.1.10000-7. I am suspecting that its not designed to work that way (If its designed to work that way, we will continue on with collecting traces, etc). -
Recording for Cisco IP Phones and Cisco C90 Codec
Hello
We are looking for a solution that is capable to record both Cisco IP Phones and Cisco Codec C90.
We are using CUCM 9.X for IP Phones and VCS 7.X for Cisco Codecs.
Is their any third party solution available for both the requirements or do i have to go with TCS and any other third party recording solution.
Thanks & Regards
Aniket PatilMy reply may be too late to be of any help to you, but for the benefit of others:
Be sure you understand the different types of PoE out there. The Linksys PoE switch only supports the newer IEEE 802.3af PoE standard.
The 7940, 7960, 7905 and other older Cisco phones only support Cisco pre-standard PoE and thus will not work with the 802.3af Linksys Switch.
To use this switch, you will need to make sure you are using the newer 7070, 7961, 7941 phones with support both pre-standard and 802.3af PoE.
All the best,
John -
Routing issue between Cisco Nexus and Cisco 4510 R+E Chassis
We have configured Cisco Nexus 7K9 as core and Cisco 4510 R+E as access switches for Server connectivity.
We are experiencing problem in terms of ARP learning and Ping issues between Cisco Nexus and end hosts.Hi,
So you have N7k acting as L3 with servers connected to 4510?.
Do you see the MAC associated with failing ARP in 4510?. Is it happening with all or few servers?. Just to verify if it is connectivity issue between N7k and 4510, you can configure an SVI on 4510 and assign address from same raneg (server/core range) and perform a ping.
This will help narrow down if issue is between server to 4510 or 4510 to N7k.
Thanks,
Nagendra -
Mavericks VPN dropouts with native VPN client and Cisco IPSec
Since update to Maverics I am experiencing VPN dropouts with native VPN client and Cisco IPSec
I am connecting via a WIFI router to a remote VPN server
The conenction is good for a while but eventually it drops out.
I had Zero issues in mountain lion and only have issues since the update to 10.9
I had similar issues in teh past with an unrelaibel wifi router but i am using a Verizon Fios router and it has worked impecably until mavericks
My thoughts are:
1 -issue with mavericks ( maybe the app sleep funciton affecting eithe VPN or WIFI daemons)
2- Issue with cisco router compaitibility or timing with Cisco IPSEC
3- Issue with WIFI itself on mavericks - some sort of WIFI software bug
Any thousuggestions?Since update to Maverics I am experiencing VPN dropouts with native VPN client and Cisco IPSec
I am connecting via a WIFI router to a remote VPN server
The conenction is good for a while but eventually it drops out.
I had Zero issues in mountain lion and only have issues since the update to 10.9
I had similar issues in teh past with an unrelaibel wifi router but i am using a Verizon Fios router and it has worked impecably until mavericks
My thoughts are:
1 -issue with mavericks ( maybe the app sleep funciton affecting eithe VPN or WIFI daemons)
2- Issue with cisco router compaitibility or timing with Cisco IPSEC
3- Issue with WIFI itself on mavericks - some sort of WIFI software bug
Any thousuggestions? -
Communication problem between Cisco 3560 and Cisco SG300.
Dear Support,
I have a Cisco SG300 and Cisco 3560 switches.
3560 is my Core Switch and SG300 is access switch.
From 3560 VLAN information is not passed to SG300.
3560 Configuration:
interface GigabitEthernet0/23
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2,10,11
switchport mode trunk
SG300 Configuration:
interface gigabitethernet49
spanning-tree link-type point-to-point
switchport mode general
switchport general allowed vlan add 2,10-11 tagged
macro description switch
Please suggest how this issue is resolve.
Regards,
JItesh Mahajan.Dear Aleksandra,
Below Configuration is right or wrong for 3560 and SG300.
3560 Configuration:
interface GigabitEthernet0/23
switchport trunk encapsulation dot1q
switchport trunk allowed vlan remove VLAN 1
switchport native vlan 1
switchport trunk allowed vlan 1,2,10,11
switchport mode trunk
SG300 Configuration:
interface gigabitethernet49
spanning-tree link-type point-to-point
switchport mode general
switchport general allowed vlan add 2,10-11 tagged
macro description switch
Regards,
JItesh Mahajan. -
Hi, I'm trying to create Site-to-Site VPN between Cisco ASA 5505 and Cisco Router 3945.
I've tried create configuration with and without ASA wizard, but anyway it doesn't work.
Please help me to find where is the issue.
I have two sites and would like to get access from 192.168.83.0 to 192.168.17.0
192.168.17.0 --- S1.S1.S1.S1 (IOS Router) ==================== S2.S2.S2.S2 (ASA 5505) --- 192.168.83.0
Here is my current configuration.
Thanks for your help.
IOS Configuration
version 15.2
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp key cisco address 198.0.183.225
crypto isakmp invalid-spi-recovery
crypto ipsec transform-set AES-SET esp-aes esp-sha-hmac
mode transport
crypto map static-map 1 ipsec-isakmp
set peer S2.S2.S2.S2
set transform-set AES-SET
set pfs group2
match address 100
interface GigabitEthernet0/0
ip address S1.S1.S1.S1 255.255.255.240
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
crypto map static-map
interface GigabitEthernet0/1
ip address 192.168.17.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
access-list 100 permit ip 192.168.17.0 0.0.0.255 192.168.83.0 0.0.0.255
ASA Configuration
ASA Version 8.4(3)
interface Ethernet0/0
switchport access vlan 2
interface Vlan1
nameif inside
security-level 100
ip address 192.168.83.1 255.255.255.0
interface Vlan2
nameif outside
security-level 0
ip address S2.S2.S2.S2 255.255.255.248
ftp mode passive
same-security-traffic permit intra-interface
object network inside-network
subnet 192.168.83.0 255.255.255.0
object network datacenter
host S1.S1.S1.S1
object network datacenter-network
subnet 192.168.17.0 255.255.255.0
object network NETWORK_OBJ_192.168.83.0_24
subnet 192.168.83.0 255.255.255.0
access-list outside_access_in extended permit icmp any any echo-reply
access-list outside_access_in extended deny ip any any log
access-list outside_cryptomap extended permit ip 192.168.83.0 255.255.255.0 object datacenter-network
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
ip local pool vpn_pool 192.168.83.200-192.168.83.254 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
nat (inside,outside) source dynamic inside-network interface
nat (inside,outside) source static inside-network inside-network destination static inside-network inside-network no-proxy-arp route-lookup
nat (inside,outside) source static inside-network inside-network destination static datacenter-network datacenter-network no-proxy-arp route-lookup
nat (inside,outside) source static NETWORK_OBJ_192.168.83.0_24 NETWORK_OBJ_192.168.83.0_24 destination static datacenter-network pdatacenter-network no-proxy-arp route-lookup
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 DEFAULT_GATEWAY 1
crypto ipsec ikev1 transform-set vpn-transform-set esp-3des esp-sha-hmac
crypto ipsec ikev1 transform-set vpn-transform-set mode transport
crypto ipsec ikev1 transform-set L2L_SET esp-aes esp-sha-hmac
crypto ipsec ikev1 transform-set L2L_SET mode transport
crypto dynamic-map dyno 10 set ikev1 transform-set vpn-transform-set
crypto map vpn 1 match address outside_cryptomap
crypto map vpn 1 set pfs
crypto map vpn 1 set peer S1.S1.S1.S1
crypto map vpn 1 set ikev1 transform-set L2L_SET
crypto map vpn 20 ipsec-isakmp dynamic dyno
crypto map vpn interface outside
crypto isakmp nat-traversal 3600
crypto ikev1 enable outside
crypto ikev1 policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
crypto ikev1 policy 20
authentication pre-share
encryption aes-256
hash sha
group 2
lifetime 86400
group-policy GroupPolicy_S1.S1.S1.S1 internal
group-policy GroupPolicy_S1.S1.S1.S1 attributes
vpn-tunnel-protocol ikev1
group-policy remote_vpn_policy internal
group-policy remote_vpn_policy attributes
vpn-tunnel-protocol ikev1 l2tp-ipsec
username artem password 8xs7XK3To4s5WfTvtKAutA== nt-encrypted
username admin password rqiFSVJFung3fvFZ encrypted privilege 15
tunnel-group DefaultRAGroup general-attributes
address-pool vpn_pool
default-group-policy remote_vpn_policy
tunnel-group DefaultRAGroup ipsec-attributes
ikev1 pre-shared-key *****
tunnel-group DefaultRAGroup ppp-attributes
authentication ms-chap-v2
tunnel-group S1.S1.S1.S1 type ipsec-l2l
tunnel-group S1.S1.S1.S1 general-attributes
default-group-policy GroupPolicy_S1.S1.S1.S1
tunnel-group S1.S1.S1.S1 ipsec-attributes
ikev1 pre-shared-key *****
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect icmp
service-policy global_policy global
prompt hostname context
no call-home reporting anonymous
Cryptochecksum:f55f10c19a0848edd2466d08744556eb
: endThanks for helping me again. I really appreciate.
I don't hve any NAT-exemptions in Cisco IOS Router. Transform-set I will change soon, but I've tried with tunnel mode and it didn't work.
Maybe NAT-exemptions is the issue. Can you advice me which exemptions should be in Cisco IOS Router?
Because on Cisco ASA I guess I have everything.
Here is show crypto session detail
router(config)#do show crypto session detail
Crypto session current status
Code: C - IKE Configuration mode, D - Dead Peer Detection
K - Keepalives, N - NAT-traversal, T - cTCP encapsulation
X - IKE Extended Authentication, F - IKE Fragmentation
Interface: GigabitEthernet0/0
Session status: DOWN
Peer: 198.0.183.225 port 500 fvrf: (none) ivrf: (none)
Desc: (none)
Phase1_id: (none)
IPSEC FLOW: permit ip 192.168.17.0/255.255.255.0 192.168.83.0/255.255.255.0
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0
Should I see something in crypto isakmp sa?
pp-border#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
IPv6 Crypto ISAKMP SA
Thanks again for your help. -
Transfer VOIP Calls Between Cisco Desk Phone and Cisco Jabber For IPhone 9.5
Does anyone know how to transfer an active voip call from a Cisco IP Desk Phone to Cisco Jabber for IPhone? I can transfer a call from Cisco Jabber for IPhone to my Cisco IP Desk Phone no problem. I put the call on hold and then click "Resume" on my Cisco IP Desk Phone. However I cannot do the same but the other way around. If I put the call on hold on my Cisco IP Desk Phone, I see "no active call" on my Jabber client. The only information I could find slighlty relevant was using the Mobility Key/Remote Destination Profile feature however this defeats the object as this will forward to an external number, e.g. mobile and I just want to transfer the call within the VOIP environment between the two devices that are using the same directory number.
I am using Cisco Call Manager 9.1(2), Cisco Presence 9.1 and Cisco Jabber for IPhone 9.5.
Any help would be greatly appreciated.
Kind Regards,
Paul Parker.Did you ever find an answer to this ?
I am seeing the same behavior and trying so see if I can put calls on hold and pick them up both ways also.
The only answer I seem to have found is to use park instead
That would/should work but I would just prefer to hold/unhold
Just not sure why we would not be able to hold/unhold on what is essentially a "shared" line
Does anyone have this working for them ? -
Cisco ISE 1.2 and Cisco ACS 5.4 patch 6 and support for snmp version 3
does anyone know if cisco ISE version 1.2 patch 8 and Cisco ACS 5.4 patch 6 support snmp version 3?
ciscoISE/admin(config)# snmp-server ?
community Set community string
contact Text for mib object sysContact
host Specify hosts to receive SNMP notifications
location Text for mib object sysLocation
ciscoISE/admin(config)# snmp-server
Ciscoacs/admin(config)# snmp-server ?
community Set community string
contact Text for mib object sysContact
host Specify hosts to receive SNMP notifications
location Text for mib object sysLocation
Ciscoacs/admin(config)# snmp-serverNo support SNMP v3 on ISE v1.2 and 1.3 except for profilling
http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/cli_ref_guide/ise_cli/ise_cli_app_a.html#12768
http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/cli_ref_guide/b_ise_CLIReferenceGuide/b_ise_CLIReferenceGuide_chapter_0100.html#ID-1364-00000d30 -
Problem VOFR cisco 3810 and Cisco 1750
-I have a network with equipment 3810 Cisco and Cisco 1750 in topology in stars.
-The router central is a Cisco 3810 wthin a E1 connected to PBX
- other router in the network, have fxs wthin two port
- the network this working with vofr
- the problem is: from an equipment 1750 I can call to a Cisco 3810 but from an equipment 3810 I can not to a cisco 1750.
- but if I place debug in Cisco 1750 ( debug voice ccaip inout) I watch that the call this arriving
- the configurations de routers is OK
- please it can help me---------------Debug voice ccaip inout-----------------------------------
ARBORAL-R#
ARBORAL-R#
ARBORAL-R#ter moni
ARBORAL-R#
*Mar 4 00:01:59.358: cc_api_call_setup_ind (vdbPtr=0x810920C0, callInfo={called=6250,called_oct3=0x0,calling=,calling_oct3=0x0,subscriber_type_str=Unknown,
fdest=1 peer_tag=0},callID=0x80FF6BB4)
*Mar 4 00:01:59.358: cc_api_call_setup_ind type 0 , prot 11
*Mar 4 00:01:59.362: cc_process_call_setup_ind (event=0x81093FA8) handed call to app "DEFAULT"
*Mar 4 00:01:59.362: sess_appl: ev(23=CC_EV_CALL_SETUP_IND), cid(1), disp(0)
*Mar 4 00:01:59.362: sess_appl: ev(SSA_EV_CALL_SETUP_IND), cid(1), disp(0)
*Mar 4 00:01:59.362: ccCallSetContext (callID=0x1, context=0x81074A5C)
*Mar 4 00:01:59.366: ssaCallSetupInd finalDest cllng(), clled(6250)
*Mar 4 00:01:59.366: ssaSetupPeer cid(1) peer list: tag(6250) called number (6250) tag(1) called number (6250)
*Mar 4 00:01:59.366: ssaSetupPeer rotary_dialpeer_status(1)
*Mar 4 00:01:59.366: ssaSetupPeer cid(1), destPat(6250), matched(4), prefix(), peer(81213410), peer->encapType (1)
*Mar 4 00:01:59.366: ccCallProceeding (callID=0x1, prog_ind=0x0)
*Mar 4 00:01:59.366: ccCallSetupRequest (Inbound call = 0x1, outbound peer =6250, dest=, params=0x81074A70 mode=0, *callID=0x8109F780)
*Mar 4 00:01:59.366: ccCallSetupRequest numbering_type 0x0
*Mar 4 00:01:59.366: dest pattern 6250, called 6250, digit_strip 1
*Mar 4 00:01:59.370: callingNumber=, calledNumber=6250, redirectNumber=
*Mar 4 00:01:59.370: accountNumber=, pinNumber=
*Mar 4 00:01:59.370: finalDestFlag=1, guid=06e4.bc49.8945.19b9.0000.0000.fdc3.ac59
*Mar 4 00:01:59.370: peer_tag=6250
*Mar 4 00:01:59.370: ccIFCallSetupRequestPrivate: (vdbPtr=0x81069AF4, dest=, callParams={called=6250,called_oct3=0x0, calling=,calling_oct3=0x0, subscriber_type_str=Unknown, fdest=1, voice_peer_tag=6250},mode=0x0) vdbPtr type = 6
*Mar 4 00:01:59.370: ccIFCallSetupRequestPrivate: (vdbPtr=0x81069AF4, dest=, callParams={called=6250, called_oct3 0x0,
calling=,calling_oct3 0x0,fdest=1, voice_peer_tag=6250}, mode=0x0)
*Mar 4 00:01:59.370: ccSaveDialpeerTag (callID=0x1, dialpeer_tag=
*Mar 4 00:01:59.370: ccCallSetContext (callID=0x2, context=0x810C043C)
*Mar 4 00:01:59.378: cc_api_call_proceeding(vdbPtr=0x81069AF4, callID=0x2,
prog_ind=0x0)
*Mar 4 00:01:59.378: cc_api_call_alert(vdbPtr=0x81069AF4, callID=0x2, prog_ind=0x8, sig_ind=0x1)
*Mar 4 00:01:59.378: sess_appl: ev(20=CC_EV_CALL_PROCEEDING), cid(2), disp(0)
*Mar 4 00:01:59.378: cid(2)st(SSA_CS_CALL_SETTING)ev(SSA_EV_CALL_PROCEEDING)
oldst(SSA_CS_MAPPING)cfid(-1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.382: -cid2(1)st2(SSA_CS_CALL_SETTING)oldst2(SSA_CS_MAPPING)
*Mar 4 00:01:59.382: ssaIgnore cid(2), st(SSA_CS_CALL_SETTING),oldst(1), ev(20)
*Mar 4 00:01:59.382: sess_appl: ev(7=CC_EV_CALL_ALERT), cid(2), disp(0)
*Mar 4 00:01:59.382: cid(2)st(SSA_CS_CALL_SETTING)ev(SSA_EV_CALL_ALERT)
oldst(SSA_CS_CALL_SETTING)cfid(-1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.382: -cid2(1)st2(SSA_CS_CALL_SETTING)oldst2(SSA_CS_MAPPING)
*Mar 4 00:01:59.382: ccCallAlert (callID=0x1, prog_ind=0x8, sig_ind=0x1)
*Mar 4 00:01:59.382: ccConferenceCreate (confID=0x8109F7F8, callID1=0x1, callID2=0x2, tag=0x0)
*Mar 4 00:01:59.382: cc_api_bridge_done (confID=0x1, srcIF=0x810920C0, srcCallID=0x1, dstCallID=0x2, disposition=0, tag=0x0)
*Mar 4 00:01:59.386: cc_api_bridge_done (confID=0x1, srcIF=0x81069AF4, srcCallID=0x2, dstCallID=0x1, disposition=0, tag=0x0)
*Mar 4 00:01:59.386: cc_api_caps_ind (dstVdbPtr=0x810920C0, dstCallId=0x1, srcCallId=0x2,
caps={codec=0xEBFB, fax_rate=0x7F, vad=0x3, modem=0x2
codec_bytes=0, signal_type=3})
*Mar 4 00:01:59.386: cc_api_caps_ind (Playout: mode 0, initial 56068,min 33034, max 5688)
*Mar 4 00:01:59.386: cc_api_caps_ind (dstVdbPtr=0x81069AF4, dstCallId=0x2, srcCallId=0x1,
caps={codec=0x8, fax_rate=0x2, vad=0x2, modem=0x1
codec_bytes=30, signal_type=2})
*Mar 4 00:01:59.386: cc_api_caps_ind (Playout: mode 0, initial 0,min 0, max 0)
*Mar 4 00:01:59.386: cc_api_caps_ack (dstVdbPtr=0x81069AF4, dstCallId=0x2, srcCallId=0x1,
caps={codec=0x8, fax_rate=0x2, vad=0x2, modem=0x1
codec_bytes=30, signal_type=2})
*Mar 4 00:01:59.386: cc_api_caps_ack (dstVdbPtr=0x810920C0, dstCallId=0x1, srcCallId=0x2,
caps={codec=0x8, fax_rate=0x2, vad=0x2, modem=0x1
codec_bytes=30, signal_type=2})
*Mar 4 00:01:59.390: cc_api_call_disconnected(vdbPtr=0x81069AF4, callID=0x2, cause=0xAC)
*Mar 4 00:01:59.390: sess_appl: ev(28=CC_EV_CONF_CREATE_DONE), cid(1), disp(0)
*Mar 4 00:01:59.390: cid(1)st(SSA_CS_CONFERENCING_ALERT)ev(SSA_EV_CONF_CREATE_DONE)
oldst(SSA_CS_MAPPING)cfid(1)csize(0)in(1)fDest(1)
*Mar 4 00:01:59.390: -cid2(2)st2(SSA_CS_CONFERENCING_ALERT)oldst2(SSA_CS_CALL_SETTING)
*Mar 4 00:01:59.390: sess_appl: ev(12=CC_EV_CALL_DISCONNECTED), cid(2), disp(0)
*Mar 4 00:01:59.394: cid(2)st(SSA_CS_CONFERENCED_ALERT)ev(SSA_EV_CALL_DISCONNECTED)
oldst(SSA_CS_CALL_SETTING)cfid(1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.394: -cid2(1)st2(SSA_CS_CONFERENCED_ALERT)oldst2(SSA_CS_CONFERENCING_ALERT)
*Mar 4 00:01:59.394: ssaDisconnectedAlert: redirect_numbers(0)
*Mar 4 00:01:59.394: ccConferenceDestroy (confID=0x1, tag=0x0)
*Mar 4 00:01:59.394: cc_api_bridge_drop_done (confID=0x1, srcIF=0x810920C0, srcCallID=0x1, dstCallID=0x2, disposition=0 tag=0x0)
*Mar 4 00:01:59.394: cc_api_bridge_drop_done (confID=0x1, srcIF=0x81069AF4, srcCallID=0x2, dstCallID=0x1, disposition=0 tag=0x0)
*Mar 4 00:01:59.394: sess_appl: ev(29=CC_EV_CONF_DESTROY_DONE), cid(1), disp(0)
*Mar 4 00:01:59.394: cid(1)st(SSA_CS_ALERT_DISC_CONF_DESTROYING)ev(SSA_EV_CONF_DESTROY_DONE)
oldst(SSA_CS_CONFERENCING_ALERT)cfid(1)csize(0)in(1)fDest(1)
*Mar 4 00:01:59.398: -cid2(2)st2(SSA_CS_ALERT_DISC_CONF_DESTROYING)oldst2(SSA_CS_CONFERENCED_ALERT)
*Mar 4 00:01:59.398: ssa: Disconnected cid(2) state(11) cause(0xAC)
*Mar 4 00:01:59.398: ssaCallDisconnectAlert: cid(2), peer-cid(1)
*Mar 4 00:01:59.398: ccCallDisconnect (callID=0x2, cause=0xAC tag=0x0)
*Mar 4 00:01:59.402: cc_api_call_disconnect_done(vdbPtr=0x81069AF4, callID=0x2, disp=0, tag=0x0)
*Mar 4 00:01:59.402: sess_appl: ev(13=CC_EV_CALL_DISCONNECT_DONE), cid(2), disp(0)
*Mar 4 00:01:59.402: cid(2)st(SSA_CS_ALERT_DISC_DISCONNECTING)ev(SSA_EV_CALL_DISCONNECT_DONE)
oldst(SSA_CS_CONFERENCED_ALERT)cfid(-1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.402: -cid2(1)st2(SSA_CS_ALERT_DISC_DISCONNECTING)oldst2(SSA_CS_ALERT_DISC_CONF_DESTROYING)
*Mar 4 00:01:59.406: ssaDisconnectDone: Rotary Retry cid(1) peer list: tag(1) called number (6250)
*Mar 4 00:01:59.406: ssaSetupPeer cid(1) peer list: tag(1) called number (6250)
*Mar 4 00:01:59.406: ssaSetupPeer rotary_dialpeer_status(2)
*Mar 4 00:01:59.406: ssaSetupPeer cid(1), destPat(6250), matched(0), prefix(), peer(81211DC4), peer->encapType (5)
*Mar 4 00:01:59.406: ccCallProceeding (callID=0x1, prog_ind=0x0)
*Mar 4 00:01:59.406: ccCallSetupRequest (Inbound call = 0x1, outbound peer =1, dest=, params=0x81074A70 mode=0, *callID=0x8109F7C0)
*Mar 4 00:01:59.406: ccCallSetupRequest numbering_type 0x0
*Mar 4 00:01:59.406: dest pattern ...., called 6250, digit_strip 0
*Mar 4 00:01:59.406: callingNumber=, calledNumber=6250, redirectNumber=
*Mar 4 00:01:59.406: accountNumber=, pinNumber=
*Mar 4 00:01:59.410: finalDestFlag=1, guid=06e4.bc49.8945.19b9.0000.0000.fdc3.ac59
*Mar 4 00:01:59.410: peer_tag=1
*Mar 4 00:01:59.410: ccIFCallSetupRequestPrivate: (vdbPtr=0x810920C0, dest=, callParams={called=6250,called_oct3=0x0, calling=,calling_oct3=0x0, subscriber_type_str=Unknown, fdest=1, voice_peer_tag=1},mode=0x0) vdbPtr type = 11
*Mar 4 00:01:59.410: ccSaveDialpeerTag (callID=0x1, dialpeer_tag=
*Mar 4 00:01:59.410: ccCallSetContext (callID=0x3, context=0x810C0D90)
*Mar 4 00:01:59.458: cc_api_call_proceeding(vdbPtr=0x810920C0, callID=0x3,
prog_ind=0x8)
*Mar 4 00:01:59.462: sess_appl: ev(20=CC_EV_CALL_PROCEEDING), cid(3), disp(0)
*Mar 4 00:01:59.462: cid(3)st(SSA_CS_CALL_SETTING)ev(SSA_EV_CALL_PROCEEDING)
oldst(SSA_CS_MAPPING)cfid(-1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.462: -cid2(1)st2(SSA_CS_CALL_SETTING)oldst2(SSA_CS_ALERT_DISC_CONF_DESTROYING)
*Mar 4 00:01:59.462: ssaIgnore cid(3), st(SSA_CS_CALL_SETTING),oldst(1), ev(20)
*Mar 4 00:01:59.466: cc_api_call_disconnected(vdbPtr=0x810920C0, callID=0x3, cause=0x3)
*Mar 4 00:01:59.466: sess_appl: ev(12=CC_EV_CALL_DISCONNECTED), cid(3), disp(0)
*Mar 4 00:01:59.466: cid(3)st(SSA_CS_CALL_SETTING)ev(SSA_EV_CALL_DISCONNECTED)
oldst(SSA_CS_CALL_SETTING)cfid(-1)csize(0)in(0)fDest(0)
*Mar 4 00:01:59.466: -cid2(1)st2(SSA_CS_CALL_SETTING)oldst2(SSA_CS_ALERT_DISC_CONF_DESTROYING)
*Mar 4 00:01:59.466: ssa: Disconnected cid(3) state(1) cause(0x3)
*Mar 4 00:01:59.470: ccCallDisconnect (callID=0x3, cause=0x3 tag=0x0)
*Mar 4 00:01:59.470: ccCallDisconnect (callID=0x1, cause=0x3 tag=0x0)
*Mar 4 00:01:59.470: cc_api_call_disconnect_done(vdbPtr=0x810920C0, callID=0x3, disp=0, tag=0x0)
*Mar 4 00:01:59.470: sess_appl: ev(13=CC_EV_CALL_DISCONNECT_DONE), cid(3), disp(0)
*Mar 4 00:01:59.474: cid(3)st(SSA_CS_DISCONNECTING)ev(SSA_EV_CALL_DISCONNECT_DONE)
oldst(SSA_CS_CALL_SETTING)cfid(-1
ARBORAL-R#
ARBORAL-R#
ARBORAL-R# -
RSA SecurID and Cisco ACS integration for user(s) with enable mode
I thought I had this problem figured out but I guess not.
I have a Cisco 2621 router with IOS 12.2(15)T17. Behind the
router is a Gentoo linux, RSA SecurID 6.1 and Cisco ACS 3.2.
I use tacacs+ authentication for logging into the Cisco router
such as telnet and ssh. In the ACS I use "external user databases"
for authentication which proxy the request from the ACS over
to the RSA SecurID Server. I installed RSA Agents with
sdconf.rec file on the Cisco ACS server. I renamed "user group 1"
to be "RSA_SecurID" group. In the "External user databases" and
"database configurations" I assign SecurID to this "RSA_SecurID"
group.
Everything is working fine. In the "User Setup" I can see dynamic
user test1, test2,...testn listed in there as "dynamic users". In
other words, I can telnet into the router with my two-factor
SecurID.
The problem is that if test1 wants to go into "enable" mode with
SecurID login, I have to go into "test1" user setting and select
"TACACS+Enable Password" and choose "Use external database password".
After that, test1 can go into enable mode with his/her SecurID
credential.
Well, this works fine if I have a few users. The problem is that
I have about 100 users that I need to do this. The solution is
clearly not scalable. Is there a setting from group level that
I can do this?
Any ACS "experts" want to help me out here? Thanks.That is not what I want. I want user "test1" to be able to do this:
C
Username: test1
Enter PASSCODE:
C2960>en
Enter PASSCODE:
C2960#
In other words, test1 user has to type in his/her RSA token password to get
into exec mode. After that, he/she has to use the RSA token password to
get into enable mode. Each user can get into "enable" mode with his/her
RSA token mode.
The way you descripbed, it seemed like anyone in this group can go directly
into enable mode without password. This is not what I have in mind.
Any other ideas? Thanks.
Maybe you are looking for
-
Error while importing configuration from NWDI into NWDS
Hi All, I am working on customizing ESS applications. I am unable to import the configuration from NWDI to NWDS. When I select 'Remote' option and enter the user id and password for SLD, I get the following error: <b><b>HTTP response "Unauthorized" f
-
Where's the default location of multicam clip creation
This is silly but where does the multi cam clip goes whenever I create them? I have a fairly large project (8 years compilation) with about 1500 folders on a 96 Tb RAID array and whenever I create multicam, it's no where to be found. Is there a way t
-
How to block displaying message "Save changes to file 'Test1' " in BEx?
Hello, dear colleagues! Do You know how to block displaying message "Save changes to file 'Test1' " in BEx? I need some BEx setting which can block it and make it the same way as You close common Excel workbook without any changes made to it after op
-
Hello all, Please see http://www.thewharfhouse.co.uk/press-and-media.html - I'm stuck trying to get the <h3 class="pressmedia"> headings to work as desired. I have set a clear:left in the style sheet, and applied a margin-top:30px in order to add som
-
How many Hash Partitions do I need?
Is there a general rule, guideline or best practice that I can follow to derive the optimum number of hash partitions I should create for a table to be hash partitioned? I see that oracle recommends to consider partitioning if the table exceeds 2GB,