02-16-2013 07:46 AM - edited 03-18-2019 12:36 AM
Dear Experts,
We have Cisco VCSC and TMS with TMSPE. We have integrated the the Cisco VCSC with AD. All the client of that AD are able to login but any other client outside the domain is not able to login on Jabber movi client for Ipad and Window.
In TMS I can import all the users for other domain, I can see all users in Phone book and user provisioning section. But I am not able to login, even I have created local users on VCSC and authetication method is set to both, but still users are not able to login. Kindly advise how we can solve this issue.
Basically a company has offices across the word and they are using different domain and connectd through internal network. For UAE they are using x.corp and for Germany they are using y.corp etc
BR
02-18-2013 05:39 AM
Do you think I can create subzone and rule to match the y.corp pattern.
02-18-2013 11:18 PM
If you use AD Auth with NTLM all Jabber Clients (iPad, Mac, Win) need to be authenticated with NTLM.
The VCSC checks if the client, trying to authenticate, is a Jabber Client and only provides the authenticate Negotiate. If this fails, it will send an 401 with Authentication Digest, but Jabber client won't try again.
If you want to authenticate users with and without AD you need a second VCS.
02-18-2013 11:19 PM
or did you mean different AD domains?
02-19-2013 04:20 AM
HI Muhammad. Is the VCS added to the domain? Have your users in y.corp tried from Windows Jabber DOMAIN\username to login via the VCS? If VCS added to domain, it should query that domain to look for credential for login. This, i think is still having problems in Jabber for IPAD for VCS log in under CSCub38436.
Not sure if this will resolve the problem or not. A log of someone trying to SUBSCRIBE and REGISTER would be helpful.
VR
Patrick
02-19-2013 04:27 AM
Hi Patrick,
I also ran into CSCub38436, but I can't see more details under this bug.
Could you provide us more infos, like when this will be fixed?
02-19-2013 04:33 AM
HI Paul. The hopeful target date is end of March early April for release with this fix.
VR
Patrick
02-23-2013 11:42 PM
Dear Paul,
Actually we have common forest but different domain, like x.om , y.com and z.com. I have joined the cisco vcs in x.domain, and under authentication, devices I am using AD authentication for x.com. I know that Cisco VCS for authentication will look its local database then forward to AD and for Jabber NTLM authentication is required. Its mean for Jabber it will look into NTLM.
I have provisioind the users in TMS for all domain, and I can see users in TMS from all doamin, but I am not able to see the users from y, z.com into VCS.
It should import the users from TMS. I think this is the issue once Cisco VCS will import the users form y and z.com from TMS then I think it will resolve the issue.
But I am not sure why it is not importing these users. Any advise? I have opned a TAC case and will update you all.
Secondly Patric if this bug CSCub38436 get resolved then we will be able to login to IPad from any doamin ?
BR
BR
02-24-2013 05:23 AM
Hi!
Which TMS / VCS / TMSPE version do you use?
As you said you do not see some users on the VCS, where exactly would you expect them to see
and what would you expect to happen?
Is the "SIP Server Address" different for these users/groups?
Please remember to rate helpful responses and identify
02-28-2013 04:03 AM
Hi This issue is solved,
Actually in TMS on VCSC provisioning option wrong base group was mentioned.
Thanks for every one for feed back.
BR
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide