07-08-2016 01:44 PM - edited 03-17-2019 07:28 AM
Is there a way to prevent certain Jabber users from accessing Expressway from off-net (MRA)?
I have a certain group of users that are allowed to use Jabber IM/Chat while on-net, but should not be able to log in from off-net.
There is another group of users that are allowed to use Jabber Chat and Softphone (CSF/TCT/BOT devices) while off-net via MRA.
I tried to set the REMOTEACCESS switch in the jabber-config.xml file to OFF. This stopped the Jabber Phone services, but users could still send IM/Chat messages.
I am running Expressway/MRA X8.7 with CUCM 11.0, and IM&P is on premises.
Thanks, Randy
07-08-2016 04:33 PM
No
07-08-2016 05:10 PM
Currently this functionality/feature does not exist for the Collaboration Edge solution. Enhancement requests CSCus94318 and CSCux35528 are already filed for this feature.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCus94318
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCux35528
You can try one of the following workarounds:
07-11-2016 04:03 PM
Thank you. Do you know if this feature is currently on a road map?
I tried changing the RemoteAccess parameter, but it didn't prevent Jabber IM access. I will ask if the customer is interested in changing Domains, but I don't think that is possible.
07-12-2016 08:40 PM
Shashank already provided the relevant bugs, and using the RemoteAccess parameter is no longer supported
11-29-2017 12:30 PM
I assume if it cant be done use .xml on Jabber, then a way to prevent it on hardphones is not an option at this moment.
Much like a Phone VPN profile was allowed for Annyconnect, there is not control once Expressway is provisioned to prevent phones from leaving the company and attempting to use MRA
11-29-2017 01:37 PM
Correct, with Jabber there are a few options, and 12.0 now is introducing a way to control Jabber MRA access, not available yet, but it's going to be available in the future.
For phones, there is no way to prevent phones from using MRA, aside from using a public CA that is not listed as supported for MRA, but if you need just some phones to use MRA, and some others not, no way to do that.
03-13-2018 12:40 AM
Hi!
May be it is possible to limit access by using SSO for external authentication?
03-13-2018 07:17 AM
CUCM and Jabber 12.0 will provide the ability to configure if a user can use full UC, IM only or no Jabber over MRA.
But yes, the previous solution would be to use external SSO to deny the access over MRA and only allow it internally.
07-10-2019 09:32 AM
So now the Jabber 12.0 is released. Can we restricted Specific users using Jabber over MRA?
07-10-2019 09:39 AM
Yes, you need both, CUCM and Jabber 12.x, I suggest using the latest releases of each.
03-30-2020 08:10 AM - edited 03-30-2020 08:39 AM
Edited:
For those looking for the documentation
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide