<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Jabber Windows VDI via Expressway Auth Question in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627078#M47795</link>
    <description>&lt;P&gt;Customer uses Jabber VDI on Citrix from in office and at home....they currently just use CUCM local passwords for authentication but need to move to LDAP and are concerned about brute force password attacks via Expressway. I know Expressway has its own inbuilt IPS which will blacklist IPs entering wrong password a few times but customer is looking for a bit more without enabling SSO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically what the customer is looking for is to only allow Citrix MRA logins (eg only allow logins from their Citrix server IPs) and not logins from anywhere else as all users have dedicated Thin Clients for Jabber. I don't see how this is possible so thought I'd just throw the question out here in case someone has had a similar request as&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 12:28:37 GMT</pubDate>
    <dc:creator>rchaseling</dc:creator>
    <dc:date>2022-06-07T12:28:37Z</dc:date>
    <item>
      <title>Jabber Windows VDI via Expressway Auth Question</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627078#M47795</link>
      <description>&lt;P&gt;Customer uses Jabber VDI on Citrix from in office and at home....they currently just use CUCM local passwords for authentication but need to move to LDAP and are concerned about brute force password attacks via Expressway. I know Expressway has its own inbuilt IPS which will blacklist IPs entering wrong password a few times but customer is looking for a bit more without enabling SSO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically what the customer is looking for is to only allow Citrix MRA logins (eg only allow logins from their Citrix server IPs) and not logins from anywhere else as all users have dedicated Thin Clients for Jabber. I don't see how this is possible so thought I'd just throw the question out here in case someone has had a similar request as&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 12:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627078#M47795</guid>
      <dc:creator>rchaseling</dc:creator>
      <dc:date>2022-06-07T12:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Jabber Windows VDI via Expressway Auth Question</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627918#M47798</link>
      <description>&lt;P&gt;You can modify the firewall rules on the Expressway E , to only permit your management and client addresses. That's fairly straight forward, though ideally if this is internal to your network it's not in a place to be exposed from elsewhere. There's control in the UCM to allow MRA authentication, but it is not granular to location in any way.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 14:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627918#M47798</guid>
      <dc:creator>Adam Pawlowski</dc:creator>
      <dc:date>2022-06-08T14:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Jabber Windows VDI via Expressway Auth Question</title>
      <link>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627959#M47800</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for response. Yeah I was looking at firewall rules but I'm let down by my knowledge of how Jabber registers via Citrix/Expressway. My understanding was that the VDI client just offloads the audio to the local machine but to do this it must login and authenicate fully via Expressway as you can see Jabber's registered IP in CUCM is Expressway C - thus adding firewall rules - we'd need to add in all the users home public IPs which defeats the purpose&amp;nbsp; -- unless my original hope was we could block the login/signalling ports on E and only allow media ports but doesn't seem to work that way&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 14:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/jabber-windows-vdi-via-expressway-auth-question/m-p/4627959#M47800</guid>
      <dc:creator>rchaseling</dc:creator>
      <dc:date>2022-06-08T14:59:59Z</dc:date>
    </item>
  </channel>
</rss>

