<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes, I have it running all in in Unified Communications Infrastructure</title>
    <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005469#M11288</link>
    <description>&lt;P&gt;Yes, I have it running all in the same subnet, with just one NIC while I get a second subnet for my lab.&lt;/P&gt;
&lt;P&gt;Basic steps are all the same, you just don't need to worry to poke holes for network traffic as you would in a real network.&lt;/P&gt;
&lt;P&gt;My MRA devices are in a secondary DNS domain which only resolves the _collab-edge SRV and that way are re-directed to my EXP-E IP for registration.&lt;/P&gt;
&lt;P&gt;If you do have two networks, what you won't need to do, is to configure NAT in the "external" network but point directly to that IP, and I'd place the DNS and test machines in that network as well (that's what I'm planning to do in my lab). Or just point devices to that special DNS which would only resolve _collab-edge, or use split-horizon DNS.&lt;/P&gt;</description>
    <pubDate>Sat, 13 May 2017 18:47:37 GMT</pubDate>
    <dc:creator>Jaime Valencia</dc:creator>
    <dc:date>2017-05-13T18:47:37Z</dc:date>
    <item>
      <title>Jabber MRA without Firewall</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005468#M11287</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;for lab purpose, can we run Jabber MRA without firewall ?&amp;nbsp; I have 1 BE6K&amp;nbsp; that I plan to use for lab (UCM , IMP, Exp-C and Exp-E).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if possible, can share some steps and notes here?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 19:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005468#M11287</guid>
      <dc:creator>karen.johnson5801</dc:creator>
      <dc:date>2019-03-19T19:25:40Z</dc:date>
    </item>
    <item>
      <title>Yes, I have it running all in</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005469#M11288</link>
      <description>&lt;P&gt;Yes, I have it running all in the same subnet, with just one NIC while I get a second subnet for my lab.&lt;/P&gt;
&lt;P&gt;Basic steps are all the same, you just don't need to worry to poke holes for network traffic as you would in a real network.&lt;/P&gt;
&lt;P&gt;My MRA devices are in a secondary DNS domain which only resolves the _collab-edge SRV and that way are re-directed to my EXP-E IP for registration.&lt;/P&gt;
&lt;P&gt;If you do have two networks, what you won't need to do, is to configure NAT in the "external" network but point directly to that IP, and I'd place the DNS and test machines in that network as well (that's what I'm planning to do in my lab). Or just point devices to that special DNS which would only resolve _collab-edge, or use split-horizon DNS.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 18:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005469#M11288</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2017-05-13T18:47:37Z</dc:date>
    </item>
    <item>
      <title>Thanks Jamie,</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005470#M11289</link>
      <description>&lt;P&gt;Thanks Jamie,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;am trying &amp;nbsp;to understand here.&amp;nbsp; So if I choose all in one subnet for Exp-C and Exp-E and UCM.&lt;/P&gt;
&lt;P&gt;Do you mind writing down detailed steps here ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry&amp;nbsp; I am bit confuse on this statement&amp;nbsp; "My MRA devices are in a secondary DNS domain which only resolves the _collab-edge SRV and that way are re-directed to my EXP-E IP for registration "&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 22:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005470#M11289</guid>
      <dc:creator>karen.johnson5801</dc:creator>
      <dc:date>2017-05-16T22:04:26Z</dc:date>
    </item>
    <item>
      <title>Hi Karen,</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005471#M11290</link>
      <description>&lt;P&gt;Hi Karen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes, that's correct, you can choose everything in same subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But if you plan to use Exp-E with a dual NIC then make sure that both the NIC's get IP from a different subnet. So for e.g.&lt;/P&gt;
&lt;P&gt;Nic 1- 172.17.17.210&lt;/P&gt;
&lt;P&gt;Nic 2- 172.17.18 210&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please note that to enable dual nic you need advanced network key. So if you don't have that, for the lab purpose you can just go ahead with the single NIC on Expressway-E.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to build two DNS servers for simulating internal &amp;amp; external login scenarios.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you login internally, on the Jabber for PC configure the DNS as (internal server) and login, it should be able to resolve the _cisco-uds srv record query pointing to the CUCM.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When you login externally configure the DNS as (external server) and login, it should fail to resolve _cisco-uds and then falls back to _collab-edge srv record.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Alok&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 09:00:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005471#M11290</guid>
      <dc:creator>Alok Jaiswal</dc:creator>
      <dc:date>2017-05-17T09:00:40Z</dc:date>
    </item>
    <item>
      <title>hi Alok,</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005472#M11291</link>
      <description>&lt;P&gt;hi Alok,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Assuming if I just use all internal for Exp-E , I have internal DNS.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For external DNS I have few questions :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- Do I need to install new AD with different domain for external DNS ?&lt;/P&gt;
&lt;P&gt;- what is different in setting and install for this external DNS?&lt;/P&gt;
&lt;P&gt;- This external DNS just in same subnet with internal DNS ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;tks,&lt;/P&gt;
&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 20:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005472#M11291</guid>
      <dc:creator>karen.johnson5801</dc:creator>
      <dc:date>2017-05-18T20:51:24Z</dc:date>
    </item>
    <item>
      <title>Hi Karen,</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005473#M11292</link>
      <description>&lt;P&gt;Hi Karen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For external DNS you can have it on same subnet no issues, the only thing you need to do is when you simulate the MRA Environment (login via expressway), you manually change the DNS on the PC to point to external DNS or you can have two separate PC instances running one pointing to internal DNS and the other to external DNS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For external DNS no need to enable AD, just enable the DNS services and create your forward lookup zone and SRV records for your external domain simulation.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use the certificates on Exp-C &amp;amp; E generated via internal CA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Alok&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 23:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005473#M11292</guid>
      <dc:creator>Alok Jaiswal</dc:creator>
      <dc:date>2017-05-18T23:41:22Z</dc:date>
    </item>
    <item>
      <title>Thanks Alok,</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005474#M11293</link>
      <description>&lt;P&gt;Thanks Alok,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;One more question :&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible to combine internal AD and external AD on same server?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 23:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005474#M11293</guid>
      <dc:creator>karen.johnson5801</dc:creator>
      <dc:date>2017-05-18T23:44:33Z</dc:date>
    </item>
    <item>
      <title>No, i don't think so, its</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005475#M11294</link>
      <description>&lt;P&gt;No, i don't think so, its possible in this scenario.&lt;/P&gt;
&lt;P&gt;Jabber always runs the _cisco-uds query first to find the servers, if it doesn't finds it then only it goes to _collab-edge.&lt;/P&gt;
&lt;P&gt;If you use same DNS server, then jabber always be able to find the _cisco-uds record and will never fall to _collab-edge. It can be done if you have for e.g. an ASA in your environment. In that case you can use the capability of ASA to do SRV filtering and then ASA will drop _cisco-uds record query which will allow Jabber to fall back to _collab-edge.&lt;/P&gt;
&lt;P&gt;Look at the document below.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/BYOD_CollabEdge.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure if anyone else has any other ideas for this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Alok&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 00:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005475#M11294</guid>
      <dc:creator>Alok Jaiswal</dc:creator>
      <dc:date>2017-05-19T00:05:11Z</dc:date>
    </item>
    <item>
      <title>Thanks Alok and also great</title>
      <link>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005476#M11295</link>
      <description>&lt;P&gt;Thanks Alok and also great doc.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 16:40:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/unified-communications-infrastructure/jabber-mra-without-firewall/m-p/3005476#M11295</guid>
      <dc:creator>karen.johnson5801</dc:creator>
      <dc:date>2017-05-19T16:40:00Z</dc:date>
    </item>
  </channel>
</rss>

