cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1489
Views
0
Helpful
6
Replies

Proximity enpoint acl/filter

SVciscomio
Level 1
Level 1

Hi,

is it possible to authorize only a subset of clients to connect to a video endpoint using Cisco Proximity?

Is there a filter or a MAC access list or other way to do it?

Thanks

SV

1 Accepted Solution

Accepted Solutions

There currently is no way to do this on the endpoint, you will need to do it at the network level.

Wayne
--
Please remember to rate responses and to mark your question as answered if appropriate.

Wayne

Please remember to mark helpful responses and to set your question as answered if appropriate.

View solution in original post

6 Replies 6

mneergaa
Cisco Employee
Cisco Employee

I don't believe the endpoints have any such filtering ability, nor is it a feature we intend to support. You may be able to do it by filtering https traffic at infrastructure level.

Hi,

I do not mean about the chance to use an ACL to filter access to the web GUI of the endpoint (for example SX20).

I mean about the chance to restrict the connection by Cisco Proximity function to the endpoint (for example SX20), so that only some specific clients can do it.

There currently is no way to do this on the endpoint, you will need to do it at the network level.

Wayne
--
Please remember to rate responses and to mark your question as answered if appropriate.

Wayne

Please remember to mark helpful responses and to set your question as answered if appropriate.

Hi,

I found this document about this argument and I think that it could be very precious: https://supportforums.cisco.com/sites/default/files/attachments/discussion/admin-guide-intelligent-proximity_1.pdf

Does somebody know if there is a new version of this document to describe protocol and data flows used by Intelligent Proximity for Content Sharing?

Very high-level, the Proximity client listens to a token (ultrasound) that contains the IP address of the video system. Once decoded, the Proximity client will connect to the given IP address over HTTPS (port 443). 

If you want to control which mobile clients are allowed to connect, you could do so by blocking 443 from clients to the IP of the endpoints. (Or - block everything but white list a set of mobile clients per MAC/IP to a set of video systems).

Do you happen to have an example on the network level that you could share? I'm trying to get guest endpoints coming through an ASA to connect and I don't think I'm doing the ACLs correctly at all.

Would you mind sharing yours?