01-09-2014 07:50 AM - edited 03-16-2019 09:10 PM
Hi All,
I have two questions regarding Cisco Unified Presence.
I have installed CUPS 9.1 in our CUCM 9.1 environment.
All call control, calendering and IM works fine with both CUPC and Jabber Clients
We would like to open our presence server up to be allowed to service our external support clients from outside of our firewall. Is this possible and which ports will need to be allowed through the firewall?
I.e. a Jabber/XMPP Openfire clients external to the organisation to go through the firewall and hit our cisco presence server. Only IM functionality is required.
Federation is out of the equation, as our organisation are security/compliance conscious that gtalk / AOL / iChat have the ability to log messages outside the organisation.
Also, as the external clients are not part of the organisation, is there any way to create a user that is not imported from CUCM.
I would like to utilise CUPS, instead of an open source XMPP server, as we are then able to utilise call control for internal users.
Thanks for your assistance.
ed
Solved! Go to Solution.
01-09-2014 08:05 AM
Sounds to me that you're really looking for Jabber Guest
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
01-09-2014 08:05 AM
Sounds to me that you're really looking for Jabber Guest
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
01-10-2014 12:46 AM
Hi Jamie,
Thanks for your quick response.
I have requested additional information from our TAM.
01-11-2014 12:44 PM
This is a rare occurance but I feel the need to disagree with Jaime here. Jabber Guest is a browser-based (currently a plug-in is required) audio/video client, not chat. It's sole purpose is to allow any unauthenticated party outside the firewall to call a CUCM/VCS endpoint inside the firewall. It can only initiate calls, not receive them.
I.e. a Jabber/XMPP Openfire clients external to the organisation to go through the firewall and hit our cisco presence server. Only IM functionality is required.
The thread originator specifically called out that only XMPP (i.e. chat) is required, not voice/video calls and Jabber Guest does not help you address this objective. In fact, there is no native Cisco product that does. Here are the options that I can imagine:
Federation is out of the equation, as our organisation are security/compliance conscious that gtalk / AOL / iChat have the ability to log messages outside the organisation.
Two comments: 1) unless you have absolute control over the client environment similar to Snap Chat, far-end logging is always possible. Nearly every XMPP client I'm aware of has this feature. 2) You can whitelist specific DNS domains that you want to allow federation with. It's not an all-or-nothing policy. In fact, you could even setup an OSS XMPP server in another domain namespace and federate with it for these "external clients."
Also, as the external clients are not part of the organisation, is there any way to create a user that is not imported from CUCM.
CUCM 9.0(1) and above allow you to have a mixture of local and LDAP-synced user accounts. You would need to use UDS in this design to ensure that Jabber could resolve all accounts, not only those in LDAP.
Please remember to rate helpful responses and identify helpful or correct answers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide