Send cisco-voip mailing list submissions to
        [email protected]

To subscribe or unsubscribe via the World Wide Web, visit
        https://puck.nether.net/mailman/listinfo/cisco-voip
or, via email, send a message with subject or body 'help' to
        [email protected]

You can reach the person managing the list at
        [email protected]

When replying, please edit your Subject line so it is more specific
than "Re: Contents of cisco-voip digest..."


Today's Topics:

   1. Re: CUCM 9.x ELM and Owner ID (Dana Tong)
   2. Re: CUCM 9.x ELM and Owner ID (Ryan Ratliff (rratliff))
   3. Re: CUCM 9.x ELM and Owner ID (Erick Wellnitz)
   4. Re: RTP permission and related attacks/threats (Wes Sisk (wsisk))


----------------------------------------------------------------------

Message: 1
Date: Mon, 14 Oct 2013 09:52:40 +0000
From: Dana Tong <[email protected]>
To: "Ryan Ratliff (rratliff)" <[email protected]>, Tim Smith
        <[email protected]>
Cc: "[email protected]" <[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Message-ID:
        <[email protected]>
Content-Type: text/plain; charset="us-ascii"

So I have a customer who has an early CUCM version (9.1.1.10000-11) and they 
have EM.

They have CUWL standard licensing and the ELM is doubling up on UCL Enhanced 
licenses for devices and User Device Profiles.


The "Owner User ID" field is greyed out and cannot be selected. The procedure 
to update was to:
https://supportforums.cisco.com/thread/289688



1.       Logout the user

2.       Turn off EM on the device

3.       Set the Owner ID

4.       Turn on EM

5.       Log the user back into the phone.

Surely there's a better way?!?! They have some 1300 logged in users at present.


As another test, I exported all phones of type x. Updated the "Owner User ID" 
in the CSV and re-inserted the phone.
The field is updated but the license count is not reflected when I click the 
"Update Usage Details" on the license page within CUCM.

Does anyone else have a solution for fixing up this license calculation error 
in bulk?

Cheers
Dana


From: cisco-voip [mailto:[email protected]] On Behalf Of Ryan 
Ratliff (rratliff)
Sent: Friday, 11 October 2013 12:06 AM
To: Tim Smith
Cc: [email protected]
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Importance: High

The intelligence to consolidate users and licenses is still in CUCM.  ELM just 
handles the distribution of licenses to clusters.  This is why ELM can't tell 
you which users/devices are consuming which license, just how many.  CUCM is 
still where you have to look to see what license an individual user or device 
is consuming.

-Ryan

On Oct 10, 2013, at 1:00 AM, Tim Smith 
<[email protected]<mailto:[email protected]>>
 wrote:

Yeah I've actually done this and poor ELM is confused now, but happily 
"compliant"
But I still don't think it's great, it kind of kills the usefulness of ELM

I think ELM needs to be a bit smarter in how it calculates and reconciles 
licensing
I think it should be primarily looking at users with device profiles and 
devices associated and working out lic that way (they would be active UC users)

Cheers,

Tim


On 10 Oct 2013, at 3:06 pm, "Nate VanMaren" 
<[email protected]<mailto:[email protected]>> wrote:
Remember a CUWL Standard user gets 10 devices per license.  So you could just 
assign all of your phones to one user that would end up with N/10 CUWL standard 
licenses.  That would easy to maintain, and probably less expensive than public 
space + user profile...

I haven't migrated any CUWL PRO to 9.x yet, so I am not sure what their device 
entitlement really is.

From: cisco-voip [mailto:[email protected]] On Behalf Of Tim 
Smith
Sent: Wednesday, October 09, 2013 5:30 PM
To: Ryan Ratliff (rratliff)
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

Thanks mate,

I'm ok with the structure (well I think it still needs work - so hopefully 
product team will continue to improve it)

In these scenario's it's usually 99% of the phones actually get logged into by 
1 user (so they really do have a user and are not really public space) - it's 
just as the admins use EM, they don't keep track and update the physical 
devices to reflect this (as you'd expect - most people use EM as a deployment / 
roll out tool (instead of TAPS) these days so they don't need to worry about 
linking physical phones to people)

There were also some good threads on the partner communities about this.

I'm more interested now in working around what is there. I have a few ideas.


-          I have a bulk login script, which logs people in, at the same time I 
could put in an AXL update to update owner ID as I go. (There is still on-going 
maintenance issue though)

-          A proxy type login service (new front end for EM, could also take 
care of this)

-          Or one of the PC based login systems (it could also do the AXL 
update)

-          Also, just trying out assigning phones to single user.

I'll do some more investigation!

Thanks for your comments so far!

Cheers,

Tim

From: Ryan Ratliff (rratliff) [mailto:[email protected]]
Sent: Thursday, 10 October 2013 4:25 AM
To: Tim Smith
Cc: Joe Martini (joemar2); 
[email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Importance: High

I agree, and unfortunately our current licensing model is structured such that 
the public space phones consume a license just as they would if they were the 
only phone associated to a user with no additional features.

-Ryan

On Oct 9, 2013, at 2:53 AM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Thanks Ryan,

Sorry to keep banging on about this, but I'm still a bit confused.

I definitely don't want to get more licensing than we are entitled to.

I think from CUCM point of view, and based on below.
Phones without owners are essentially considered public space.

Phones with owners associated, would get attributed in the right place, i.e. 
CUWL standard, pro etc.

In extension mobility environments, usually none of our phones have owners 
associated.
So when we go to add CSF's for Jabber for instance, we come unstuck.

Cheers,

Tim

________________________________
From: Ryan Ratliff (rratliff) <[email protected]<mailto:[email protected]>>
Sent: Wednesday, 9 October 2013 1:41 AM
To: Tim Smith
Cc: Joe Martini (joemar2); 
[email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

I recommend when looking at the User Count Tool or whatever tool you are using 
to do your license migration (before the upgrade) you should count your public 
space phones as a separate user that will require a license.

I understand Licensing is being very generous for current migrations however I 
would pay careful attention to what you ask for and what you get as compared to 
what you currently pay for so there are no big surprises at your next renewal.

-Ryan

On Oct 8, 2013, at 10:25 AM, Tim Smith 
<[email protected]<mailto:[email protected]>>
 wrote:

Thanks Ryan

Does that mean we should ask licensing for a public space lic per em phone?

We don't actually need to buy more licenses right?

Cheers,

Tim


On 9 Oct 2013, at 1:09 am, "Ryan Ratliff (rratliff)" 
<[email protected]<mailto:[email protected]>> wrote:
As soon as you add SNR or a soft client to those users you have to double up on 
licenses to account for the public space phones.

Today that is the solution and when doing your DLU to ELM conversion you need 
to plan accordingly.

-Ryan

On Oct 7, 2013, at 7:33 PM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Thanks Joe,

I have seen that one before, I'm not sure that is the same issue.

This is in regard to the physical phones not been allocated to a user. (i.e. 
assigning phones owner ID's)

This seems to cause a double up for me when I create CSF profiles.

Cheers,

Tim

From: Joe Martini [mailto:[email protected]<http://cisco.com/>]
Sent: Tuesday, 8 October 2013 10:08 AM
To: Tim Smith
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

Versions of CUCM that contain the fix for CSCue14471 no longer have this issue.
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCue14471

Joe

On Oct 7, 2013, at 6:00 PM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Hi guys,

I've seen some discussion on this already
http://www.gossamer-threads.com/lists/cisco/voip/172472?search_string=owner%20cuwl;#172472

Most clients do not assign owner ID as they use extension mobility.
(I will admit it is true that a lot of mobility users actually stay logged into 
the same phone and we could technically assign them as the owner)

Either way, I keep ending up with my licensing in ELM being out of balance due 
to having phones and CSF's.

The TAC answer to me was that I should assign an owner ID.

Am I missing something here? Is there another solution?

Cheers,

Tim.
_______________________________________________
cisco-voip mailing list
[email protected]<mailto:[email protected]>
https://puck.nether.net/mailman/listinfo/cisco-voip

_______________________________________________
cisco-voip mailing list
[email protected]<mailto:[email protected]>
https://puck.nether.net/mailman/listinfo/cisco-voip



NOTICE: This email message is for the sole use of the intended recipient(s) and 
may contain confidential and privileged information. Any unauthorized review, 
use, disclosure or distribution is prohibited. If you are not the intended 
recipient, please contact the sender by reply email and destroy all copies of 
the original message.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131014/ffbe47e6/attachment-0001.html>

------------------------------

Message: 2
Date: Mon, 14 Oct 2013 13:36:52 +0000
From: "Ryan Ratliff (rratliff)" <[email protected]>
To: Dana Tong <[email protected]>
Cc: "[email protected]" <[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Message-ID:
        <[email protected]>
Content-Type: text/plain; charset="windows-1252"

An upgrade to 9.1(2) will help in both the users with only EM enabled not 
getting assigned Essential licenses and the fact that owner user id cannot be 
set on an EM-enabled phone (CSCue14471), in addition to a bunch of bug fixes.

-Ryan

On Oct 14, 2013, at 5:52 AM, Dana Tong 
<[email protected]<mailto:[email protected]>> wrote:

So I have a customer who has an early CUCM version (9.1.1.10000-11) and they 
have EM.

They have CUWL standard licensing and the ELM is doubling up on UCL Enhanced 
licenses for devices and User Device Profiles.


The ?Owner User ID? field is greyed out and cannot be selected. The procedure 
to update was to:
https://supportforums.cisco.com/thread/289688


1.       Logout the user
2.       Turn off EM on the device
3.       Set the Owner ID
4.       Turn on EM
5.       Log the user back into the phone.

Surely there?s a better way?!?! They have some 1300 logged in users at present.


As another test, I exported all phones of type x. Updated the ?Owner User ID? 
in the CSV and re-inserted the phone.
The field is updated but the license count is not reflected when I click the 
?Update Usage Details? on the license page within CUCM.

Does anyone else have a solution for fixing up this license calculation error 
in bulk?

Cheers
Dana


From: cisco-voip 
[mailto:[email protected]<mailto:[email protected]>]
 On Behalf Of Ryan Ratliff (rratliff)
Sent: Friday, 11 October 2013 12:06 AM
To: Tim Smith
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Importance: High

The intelligence to consolidate users and licenses is still in CUCM.  ELM just 
handles the distribution of licenses to clusters.  This is why ELM can't tell 
you which users/devices are consuming which license, just how many.  CUCM is 
still where you have to look to see what license an individual user or device 
is consuming.

-Ryan

On Oct 10, 2013, at 1:00 AM, Tim Smith 
<[email protected]<mailto:[email protected]>>
 wrote:

Yeah I've actually done this and poor ELM is confused now, but happily 
"compliant"
But I still don't think it's great, it kind of kills the usefulness of ELM

I think ELM needs to be a bit smarter in how it calculates and reconciles 
licensing
I think it should be primarily looking at users with device profiles and 
devices associated and working out lic that way (they would be active UC users)

Cheers,

Tim


On 10 Oct 2013, at 3:06 pm, "Nate VanMaren" 
<[email protected]<mailto:[email protected]>> wrote:
Remember a CUWL Standard user gets 10 devices per license.  So you could just 
assign all of your phones to one user that would end up with N/10 CUWL standard 
licenses.  That would easy to maintain, and probably less expensive than public 
space + user profile?

I haven?t migrated any CUWL PRO to 9.x yet, so I am not sure what their device 
entitlement really is.

From: cisco-voip [mailto:[email protected]] On Behalf Of Tim 
Smith
Sent: Wednesday, October 09, 2013 5:30 PM
To: Ryan Ratliff (rratliff)
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

Thanks mate,

I?m ok with the structure (well I think it still needs work ? so hopefully 
product team will continue to improve it)

In these scenario?s it?s usually 99% of the phones actually get logged into by 
1 user (so they really do have a user and are not really public space) ? it?s 
just as the admins use EM, they don?t keep track and update the physical 
devices to reflect this (as you?d expect ? most people use EM as a deployment / 
roll out tool (instead of TAPS) these days so they don?t need to worry about 
linking physical phones to people)

There were also some good threads on the partner communities about this.

I?m more interested now in working around what is there. I have a few ideas.

-          I have a bulk login script, which logs people in, at the same time I 
could put in an AXL update to update owner ID as I go. (There is still on-going 
maintenance issue though)
-          A proxy type login service (new front end for EM, could also take 
care of this)
-          Or one of the PC based login systems (it could also do the AXL 
update)
-          Also, just trying out assigning phones to single user.

I?ll do some more investigation!

Thanks for your comments so far!

Cheers,

Tim

From: Ryan Ratliff (rratliff) [mailto:[email protected]]
Sent: Thursday, 10 October 2013 4:25 AM
To: Tim Smith
Cc: Joe Martini (joemar2); 
[email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Importance: High

I agree, and unfortunately our current licensing model is structured such that 
the public space phones consume a license just as they would if they were the 
only phone associated to a user with no additional features.

-Ryan

On Oct 9, 2013, at 2:53 AM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Thanks Ryan,

Sorry to keep banging on about this, but I'm still a bit confused.

I definitely don't want to get more licensing than we are entitled to.

I think from CUCM point of view, and based on below.
Phones without owners are essentially considered public space.

Phones with owners associated, would get attributed in the right place, i.e. 
CUWL standard, pro etc.

In extension mobility environments, usually none of our phones have owners 
associated.
So when we go to add CSF's for Jabber for instance, we come unstuck.

Cheers,

Tim

________________________________
From: Ryan Ratliff (rratliff) <[email protected]<mailto:[email protected]>>
Sent: Wednesday, 9 October 2013 1:41 AM
To: Tim Smith
Cc: Joe Martini (joemar2); 
[email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

I recommend when looking at the User Count Tool or whatever tool you are using 
to do your license migration (before the upgrade) you should count your public 
space phones as a separate user that will require a license.

I understand Licensing is being very generous for current migrations however I 
would pay careful attention to what you ask for and what you get as compared to 
what you currently pay for so there are no big surprises at your next renewal.

-Ryan

On Oct 8, 2013, at 10:25 AM, Tim Smith 
<[email protected]<mailto:[email protected]>>
 wrote:

Thanks Ryan

Does that mean we should ask licensing for a public space lic per em phone?

We don't actually need to buy more licenses right?

Cheers,

Tim


On 9 Oct 2013, at 1:09 am, "Ryan Ratliff (rratliff)" 
<[email protected]<mailto:[email protected]>> wrote:
As soon as you add SNR or a soft client to those users you have to double up on 
licenses to account for the public space phones.

Today that is the solution and when doing your DLU to ELM conversion you need 
to plan accordingly.

-Ryan

On Oct 7, 2013, at 7:33 PM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Thanks Joe,

I have seen that one before, I?m not sure that is the same issue.

This is in regard to the physical phones not been allocated to a user. (i.e. 
assigning phones owner ID?s)

This seems to cause a double up for me when I create CSF profiles.

Cheers,

Tim

From: Joe Martini [mailto:[email protected]<http://cisco.com/>]
Sent: Tuesday, 8 October 2013 10:08 AM
To: Tim Smith
Cc: [email protected]<mailto:[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID

Versions of CUCM that contain the fix for CSCue14471 no longer have this issue.
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCue14471

Joe

On Oct 7, 2013, at 6:00 PM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Hi guys,

I?ve seen some discussion on this already
http://www.gossamer-threads.com/lists/cisco/voip/172472?search_string=owner%20cuwl;#172472

Most clients do not assign owner ID as they use extension mobility.
(I will admit it is true that a lot of mobility users actually stay logged into 
the same phone and we could technically assign them as the owner)

Either way, I keep ending up with my licensing in ELM being out of balance due 
to having phones and CSF?s.

The TAC answer to me was that I should assign an owner ID.

Am I missing something here? Is there another solution?

Cheers,

Tim.
_______________________________________________
cisco-voip mailing list
[email protected]<mailto:[email protected]>
https://puck.nether.net/mailman/listinfo/cisco-voip

_______________________________________________
cisco-voip mailing list
[email protected]<mailto:[email protected]>
https://puck.nether.net/mailman/listinfo/cisco-voip



NOTICE: This email message is for the sole use of the intended recipient(s) and 
may contain confidential and privileged information. Any unauthorized review, 
use, disclosure or distribution is prohibited. If you are not the intended 
recipient, please contact the sender by reply email and destroy all copies of 
the original message.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131014/01228d64/attachment-0001.html>

------------------------------

Message: 3
Date: Mon, 14 Oct 2013 10:01:03 -0500
From: Erick Wellnitz <[email protected]>
To: "Ryan Ratliff (rratliff)" <[email protected]>
Cc: "[email protected]" <[email protected]>
Subject: Re: [cisco-voip] CUCM 9.x ELM and Owner ID
Message-ID:
        <cak0wosc+6hglr8knyydyppv5jgruzvltzctjhy6bcw1f-zc...@mail.gmail.com>
Content-Type: text/plain; charset="windows-1252"

I don't wan tto hijack this but we have a similar thing going on.

Our issue is that we use Extension Mobility exclusively in order to
eliminate as much MAC work as possible.  We don't wnat to assign a user to
the device but we also don't want to double up on licenses.  Even after an
upgrade to 9.1.2 and being able to set teh devices as 'public space' we
still run into the issue of doubling up because we also use mobility/SNR.

It would be interesting to know if anyone has found a way, besides
assigning an owner user id, to relieve the doubling up issue in an
organization using EM exclusively along with other licensed features.


On Mon, Oct 14, 2013 at 8:36 AM, Ryan Ratliff (rratliff) <[email protected]
> wrote:

>  An upgrade to 9.1(2) will help in both the users with only EM enabled not
> getting assigned Essential licenses and the fact that owner user id cannot
> be set on an EM-enabled phone (CSCue14471), in addition to a bunch of bug
> fixes.
>
> -Ryan
>
>  On Oct 14, 2013, at 5:52 AM, Dana Tong <[email protected]>
> wrote:
>
>   So I have a customer who has an early CUCM version (9.1.1.10000-11) and
> they have EM.****
>
>  They have CUWL standard licensing and the ELM is doubling up on UCL
> Enhanced licenses for devices and User Device Profiles.****
>
>
>  The ?Owner User ID? field is greyed out and cannot be selected. The
> procedure to update was to:****
>  https://supportforums.cisco.com/thread/289688****
>
>
>  1.       Logout the user****
>  2.       Turn off EM on the device****
>  3.       Set the Owner ID****
>  4.       Turn on EM****
>  5.       Log the user back into the phone.****
>
>  Surely there?s a better way?!?! They have some 1300 logged in users at
> present.****
>
>
>  As another test, I exported all phones of type x. Updated the ?Owner
> User ID? in the CSV and re-inserted the phone.****
>  The field is updated but the license count is not reflected when I click
> the ?Update Usage Details? on the license page within CUCM.****
>
>  Does anyone else have a solution for fixing up this license calculation
> error in bulk?****
>
>  Cheers****
>  Dana****
>
>
>   *From:* cisco-voip [mailto:[email protected]] *On
> Behalf Of *Ryan Ratliff (rratliff)
> *Sent:* Friday, 11 October 2013 12:06 AM
> *To:* Tim Smith
> *Cc:* [email protected]
> *Subject:* Re: [cisco-voip] CUCM 9.x ELM and Owner ID
> *Importance:* High****
>   ** **
>  The intelligence to consolidate users and licenses is still in CUCM.  ELM
> just handles the distribution of licenses to clusters.  This is why ELM
> can't tell you which users/devices are consuming which license, just how
> many.  CUCM is still where you have to look to see what license an
> individual user or device is consuming.****
>  ** **
>   -Ryan****
>  ** **
>   On Oct 10, 2013, at 1:00 AM, Tim Smith <[email protected]>****
>    wrote:****
>  ** **
>   Yeah I've actually done this and poor ELM is confused now, but happily
> "compliant"****
>   But I still don't think it's great, it kind of kills the usefulness of
> ELM****
>   ** **
>   I think ELM needs to be a bit smarter in how it calculates and
> reconciles licensing****
>   I think it should be primarily looking at users with device profiles
> and devices associated and working out lic that way (they would be active
> UC users)****
>   ** **
>   Cheers,****
>   ** **
>
> Tim
>
> ****
>
>
> On 10 Oct 2013, at 3:06 pm, "Nate VanMaren" <[email protected]>
> wrote:****
>
>  Remember a CUWL Standard user gets 10 devices per license.  So you could
> just assign all of your phones to one user that would end up with N/10 CUWL
> standard licenses.  That would easy to maintain, and probably less
> expensive than public space + user profile?****
>   ****
>  I haven?t migrated any CUWL PRO to 9.x yet, so I am not sure what their
> device entitlement really is.****
>   ****
>   *From:* cisco-voip 
> [mailto:[email protected]<[email protected]>
> ] *On Behalf Of *Tim Smith
> *Sent:* Wednesday, October 09, 2013 5:30 PM
> *To:* Ryan Ratliff (rratliff)
> *Cc:* [email protected]
> *Subject:* Re: [cisco-voip] CUCM 9.x ELM and Owner ID****
>    ****
>  Thanks mate,****
>   ****
>  I?m ok with the structure (well I think it still needs work ? so
> hopefully product team will continue to improve it)****
>   ****
>  In these scenario?s it?s usually 99% of the phones actually get logged
> into by 1 user (so they really do have a user and are not really public
> space) ? it?s just as the admins use EM, they don?t keep track and update
> the physical devices to reflect this (as you?d expect ? most people use EM
> as a deployment / roll out tool (instead of TAPS) these days so they don?t
> need to worry about linking physical phones to people)****
>   ****
>  There were also some good threads on the partner communities about this.*
> ***
>   ****
>  I?m more interested now in working around what is there. I have a few
> ideas.****
>   ****
>  -          I have a bulk login script, which logs people in, at the same
> time I could put in an AXL update to update owner ID as I go. (There is
> still on-going maintenance issue though)****
>  -          A proxy type login service (new front end for EM, could also
> take care of this)****
>  -          Or one of the PC based login systems (it could also do the
> AXL update)****
>  -          Also, just trying out assigning phones to single user.****
>   ****
>  I?ll do some more investigation!****
>   ****
>  Thanks for your comments so far!****
>   ****
>  Cheers,****
>
> Tim****
>   ****
>   *From:* Ryan Ratliff (rratliff) 
> [mailto:[email protected]<[email protected]>
> ]
> *Sent:* Thursday, 10 October 2013 4:25 AM
> *To:* Tim Smith
> *Cc:* Joe Martini (joemar2); [email protected]
> *Subject:* Re: [cisco-voip] CUCM 9.x ELM and Owner ID
> *Importance:* High****
>    ****
>  I agree, and unfortunately our current licensing model is structured such
> that the public space phones consume a license just as they would if they
> were the only phone associated to a user with no additional features.  ***
> *
>   ****
>  -Ryan****
>   ****
>   On Oct 9, 2013, at 2:53 AM, Tim Smith <[email protected]> wrote:**
> **
>   ****
>   Thanks Ryan,****
>   ****
>   Sorry to keep banging on about this, but I'm still a bit confused.****
>    ****
>   I definitely don't want to get more licensing than we are entitled to.**
> **
>    ****
>   I think from CUCM point of view, and based on below.****
>   Phones without owners are essentially considered public space.****
>    ****
>   Phones with owners associated, would get attributed in the right place,
> i.e. CUWL standard, pro etc.****
>    ****
>   In extension mobility environments, usually none of our phones have
> owners associated.****
>   So when we go to add CSF's for Jabber for instance, we come unstuck.****
>    ****
>   Cheers,****
>    ****
>   Tim****
>    ****
>   ------------------------------
>   *From:* Ryan Ratliff (rratliff) <[email protected]>
> *Sent:* Wednesday, 9 October 2013 1:41 AM
> *To:* Tim Smith
> *Cc:* Joe Martini (joemar2); [email protected]
> *Subject:* Re: [cisco-voip] CUCM 9.x ELM and Owner ID****
>   ****
>   I recommend when looking at the User Count Tool or whatever tool you
> are using to do your license migration (before the upgrade) you should
> count your public space phones as a separate user that will require a
> license.  ****
>   ****
>   I understand Licensing is being very generous for current migrations
> however I would pay careful attention to what you ask for and what you get
> as compared to what you currently pay for so there are no big surprises at
> your next renewal.****
>   ****
>  -Ryan****
>   ****
>   On Oct 8, 2013, at 10:25 AM, Tim Smith <[email protected]>****
>    wrote:****
>   ****
>   Thanks Ryan****
>    ****
>   Does that mean we should ask licensing for a public space lic per em
> phone?****
>    ****
>   We don't actually need to buy more licenses right?****
>    ****
>   Cheers,****
>    ****
>   Tim****
>    ****
>
>
> On 9 Oct 2013, at 1:09 am, "Ryan Ratliff (rratliff)" <[email protected]>
> wrote:****
>
>  As soon as you add SNR or a soft client to those users you have to
> double up on licenses to account for the public space phones.  ****
>   ****
>   Today that is the solution and when doing your DLU to ELM conversion
> you need to plan accordingly.****
>    ****
>  -Ryan****
>   ****
>   On Oct 7, 2013, at 7:33 PM, Tim Smith <[email protected]> wrote:**
> **
>   ****
>   Thanks Joe,****
>    ****
>   I have seen that one before, I?m not sure that is the same issue.****
>    ****
>   This is in regard to the physical phones not been allocated to a user.
> (i.e. assigning phones owner ID?s)****
>    ****
>   This seems to cause a double up for me when I create CSF profiles.****
>    ****
>   Cheers,****
>    ****
>   Tim****
>    ****
>   *From:* Joe Martini [mailto:[email protected]]
> *Sent:* Tuesday, 8 October 2013 10:08 AM
> *To:* Tim Smith
> *Cc:* [email protected]
> *Subject:* Re: [cisco-voip] CUCM 9.x ELM and Owner ID****
>    ****
>   Versions of CUCM that contain the fix for CSCue14471 no longer have
> this issue.****
>
> http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCue14471
> ****
>    ****
>   Joe****
>    ****
>   On Oct 7, 2013, at 6:00 PM, Tim Smith <[email protected]> wrote:**
> **
>    ****
>   Hi guys,****
>    ****
>   I?ve seen some discussion on this already****
>
> http://www.gossamer-threads.com/lists/cisco/voip/172472?search_string=owner%20cuwl;#172472
> ****
>    ****
>   Most clients do not assign owner ID as they use extension mobility.****
>   (I will admit it is true that a lot of mobility users actually stay
> logged into the same phone and we could technically assign them as the
> owner)****
>    ****
>   Either way, I keep ending up with my licensing in ELM being out of
> balance due to having phones and CSF?s.****
>    ****
>   The TAC answer to me was that I should assign an owner ID.****
>    ****
>   Am I missing something here? Is there another solution?****
>    ****
>   Cheers,****
>    ****
>   Tim.****
>   _______________________________________________
> cisco-voip mailing list
> [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-voip****
>     ****
>   _______________________________________________
> cisco-voip mailing list
> [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-voip****
>
>        ****
>
>
> NOTICE: This email message is for the sole use of the intended
> recipient(s) and may contain confidential and privileged information. Any
> unauthorized review, use, disclosure or distribution is prohibited. If you
> are not the intended recipient, please contact the sender by reply email
> and destroy all copies of the original message.****
>  ** **
>
>
>
> _______________________________________________
> cisco-voip mailing list
> [email protected]
> https://puck.nether.net/mailman/listinfo/cisco-voip
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131014/3a80c3e9/attachment-0001.html>

------------------------------

Message: 4
Date: Mon, 14 Oct 2013 15:56:50 +0000
From: "Wes Sisk (wsisk)" <[email protected]>
To: Tim Smith <[email protected]>
Cc: "[email protected]" <[email protected]>
Subject: Re: [cisco-voip] RTP permission and related attacks/threats
Message-ID:
        <[email protected]>
Content-Type: text/plain; charset="windows-1252"

Border device highly recommended.

All NAT inspection engines are not keeping up with protocol updates. This 
article is dated but still relevant:
https://supportforums.cisco.com/docs/DOC-8131

Even with that NAT does not proxy TCP data so any TCP retransmission. See:
CSCso34072    NAT TCP re-assemby of skinny packets causes fragmentation
for some background. IOS first attempted to implement a proxy to store bytes 
for TCP retransmit on either side but that was unscalable and backed out.

NAT/PAT will not work with IOS if TCP retransmits are involved AFAIK.

Regards,
Wes

On Oct 12, 2013, at 6:41 AM, Tim Smith 
<[email protected]<mailto:[email protected]>> wrote:

Hi Ahmed,

When you say different organizations, do you mean other CUCM systems? SIP / 
H323 systems etc?
If so it?s perfect use for CUBE and / or trusted relay points.

I would definitely not let other organizations right into my network on such a 
broad range of ports.
You should try and force them through a demarcation point that you can control.
You want the media to flow through this device. This way you only have to let 
them talk to your CUBE, and your CUBE can reach everyone inside your network on 
their behalf.

The other complication this gets around is NAT, and routing issues. I.e. 
without this type of setup, you would both have to have fairly full knowledge 
of each others networks, and also avoid overlaps.

It?s been a while since I?ve looked at security on routers.
However, NBAR and ACL?s are typically used in class maps in QoS to identify 
traffic and apply QoS policies

You do have inspection as an option on Cisco routers as well. Used to be called 
CBAC, I think it?s just IOS Firewall now. It can inspect SIP, SCCP, H323 from 
memory, and open up pinholes where required.

My recommendation is look at some smart border device. I would be mandating SIP 
if possible and use CUBEs.

There are lots of improvements and fun stuff planned for the edge and this sort 
of connectivity coming soon too.

Hope that helps a bit.

Cheers,

Tim

From: cisco-voip 
[mailto:[email protected]<mailto:[email protected]>]
 On Behalf Of Ahmed -Y
Sent: Saturday, 12 October 2013 7:53 AM
To: [email protected]<mailto:[email protected]>
Subject: [cisco-voip] Fwd: RTP permission and related attacks/threats


HI Guys,

I have to permit RTP traffic from internal network to other organizations 
(under different management) on gateway devices (routers, switches). I am 
curious to know if there are known attacks/threats when upd range 16384-32767 
is permited. RTP source/destination can be desk phone or PC with softphone. If 
yes then can we configure gateway routers/switches to protect from these 
attacks.



We have cisco 7200, 6500, 3550, 3560, 3750 switches as gateway devices.



One more quick question are there only two ways (NBAR and ACL with udp range) 
on routers/switches to identify/match RTP traffic? I know Firewalls provide 
feature like inspect, AGL etc to dynamically identify RTP ports by inspecting 
control traffic.



Your input will be highly appreciated



Regards

_______________________________________________
cisco-voip mailing list
[email protected]<mailto:[email protected]>
https://puck.nether.net/mailman/listinfo/cisco-voip

-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131014/675097b1/attachment-0001.html>

------------------------------

Subject: Digest Footer

_______________________________________________
cisco-voip mailing list
[email protected]
https://puck.nether.net/mailman/listinfo/cisco-voip


------------------------------

End of cisco-voip Digest, Vol 120, Issue 14
*******************************************

Reply via email to