05-29-2018 05:54 PM - edited 03-19-2019 01:22 PM
I've migrated Unity Connection mailboxes from AXL to LDAP but not the other way around. Is it possible? What does the process look like? Any drawbacks?
Just looking to leverage AXL to CUCM (with LDAP sync) to leverage the new pin sync.
Solved! Go to Solution.
05-30-2018 11:36 AM
From the Design Guide for Cisco Unity Connection 11.x
"When you integrate Unity Connection with an LDAP directory, you can configure Unity Connection to authenticate passwords for web applications against the LDAP database. When you import data from Cisco Unified CM, you must maintain passwords for Unity Connection web applications in Unity Connection and maintain passwords for Cisco Unified CM web applications in Cisco Unified CM. "
05-29-2018 09:39 PM
05-30-2018 03:21 AM
Thanks Jaime. It’s more than just the pin, but the pin sync is what got me thinking about this. Why should I sync users via ldap and pins via axl, especially considering that cucm is ldap-integrated also? It seems to make more sense to just import users from cucm (via ldap) to begin with.
...but what to do with the users already imported from ldap? How to seamlessly ‘convert’ those ldap users to cucm users in bulk? Or should I leave the existing users as is? Or am I over-thinking it altogether and just keep importing from ldap?
05-30-2018 05:56 AM
What Jaime is saying is that AXL is required only for the PIN sync itself. CUCM and CUC can both be LDAP integrated. As long as the CUCM userID and the CUC alias are the same, the PIN should sync:
From the CUC Administration Guide:
PIN Synchronization between Unity Connection and Cisco Unified CM
Before using PIN Synchronization feature, make sure that:
Maren
05-30-2018 06:20 AM
You're overthinking this. did you read in any doc that PIN sync would only work if your users were brought from CUCM via AXL?
I show how to do it here, both servers using LDAP
05-30-2018 06:22 AM
I was trying to be succinct, but I guess I wasn't very clear. Sorry about that.
I understand completely how the pin sync works. Today, I have ldap integration configured on both cucm and cxn with no axl servers defined within cxn. In my mind, it seems unnecessary to integrate both systems with ldap, and also if I'm going to configure the cucm integration...I might as well just use that for user imports as well. I see zero gain for using axl for pin sync and direct ldap integration for user imports -- why not simplify things and use axl for all of it (entirely and completely understanding that I don't 'have to'). That's what I intended this post to be about...not the pin sync requirements.
So guys, I appreciate the thoughts, but if anyone can speak to converting/migrating ldap-imported users to cucm/axl users, I'd appreciate it.
05-30-2018 08:49 AM
Ah, roger that.
One benefit of LDAP integration for CUCM and CUC separately is LDAP Authentication. Since CUCM v9, only LDAP synchronized are LDAP authenticated in CUCM. The same is true for CUC.
You can convert an LDAP users to a local user with a checkbox on the User Basics page. I don't know if doing that, and then doing an AXL sync (with UserID/Alias match, Primary Extension/Extension match) would 'pick up' the user via AXL. I'd say try it once and see if it works. If not, the next LDAP sync should re-pick-up the user.
That said, I haven't tried the un-associate-re-associate an LDAP user in Unity Connection for a couple of versions, so test first with a dummy user.
Maren
05-30-2018 11:32 AM
Wait... So in CUCM/CXN 11.5, if LDAP sync is configured on both, how would LDAP authentication be different than if it was LDAP <-> CUCM <AXL> CXN?
05-30-2018 11:36 AM
From the Design Guide for Cisco Unity Connection 11.x
"When you integrate Unity Connection with an LDAP directory, you can configure Unity Connection to authenticate passwords for web applications against the LDAP database. When you import data from Cisco Unified CM, you must maintain passwords for Unity Connection web applications in Unity Connection and maintain passwords for Cisco Unified CM web applications in Cisco Unified CM. "
05-30-2018 12:03 PM - edited 05-30-2018 12:04 PM
No idea how I missed that. That's pretty significant. Guess I'll be just adding the axl pin sync. Darn it.
+5 to both of you. Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide