BRKCOL 2060b
BRKCOL 2060b
BRKCOL 2060b
Luis Garcia
BRKCOL-2060b
#CiscoLive
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
• Introduction
• SIP-Base DoS Attack Protection
• SIP Registration Failover for Soft Clients
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Introduction
Introduction
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Expressway Deployments
B2B Calling
CMS WebRTC
Internet Interworking
Call Control
Webex Edge
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Mobile and Remote Access
Internet
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
X14 Upgrade Benefits
The #1 priority for each Registration failover Webex App Improved operational
release Enhancements efficiencies
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
SIP-Base DoS
Attack
Protection
SIP-Base DoS Attack Protection - Pre-X14
SIP INVITE
SYN
SYN,
ACK
ACK
CPL Expressway-E Firewall Internet
SIP 403 Forbidden
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
SIP-Base DoS Attack Protection - X14
• The “SIP Authentication Failure” category under System > Protection >
Automated Detection, will now match against 403 Forbidden reason
codes.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
SIP-Base DoS Attack Protection - X14
• Web GUI shows an example of the log message that will trigger the
protection.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
SIP-Base DoS Attack Protection - X14
SIP INVITE
SYN
SYN,
ACK
ACK
IntrusionCPL
Protection Expressway-E Firewall Internet
SIP 403 Forbidden
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
SIP Registration Failure Detection
Pre-X14
X14
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Rate Limits for SIP
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Rate Limits for SIP
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
SIP Registration
Failover
MRA SIP Registration Failover
These features are not supported for IP Phones or Webex devices using MRA.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Adaptive Routing
Expressways can dynamically alter the routing path for SIP Registers
when an Exp-C node is detected to be down.
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Adaptive Routing
Expressway C Down Scenario
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Adaptive Routing FQDN IP Address
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Adaptive Routing FQDN IP Address
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Adaptive Routing– APNS
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
STUN Keepalives
This is enabled from the Exp-C only, under Unified Communications >
Configuration. Exp-E will automatically match the configuration of the Exp-C.
Exp-C
Exp-E
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
STUN Keepalives
• Webex app and Jabber clients will send STUN Binding request
messages to check the connection path.
• When running UCM 14 we can identify when a UCM node goes
down.
STUN Keepalives are sent every 30 seconds.
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
STUN Keepalives
UCM Down Scenario
Message Header:
(type=BindRequest(0x0001)
Flow Token: a77317ec-ac7f-4e38-
9d03-4bceaae7ff8e:1
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
STUN Keepalives
UCM Down Scenario
(type=BindErrorResponse(0x0111)
ErrorCode: (class=4, number=21,
reason=PATH IS DOWN)
Flow Token: a77317ec-ac7f-4e38-
9d03-4bceaae7ff8e:1
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
STUN Keepalives
UCM Down Scenario
• WxA or Jabber client will select a new SIP registration route and
use it to failover to an active UCM server.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
MRA SIP Registration Failover
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Webex App
Enhancements
MRA – UCM Calling
SIP TLS
HTTPS
UCM
Internet
Expressway-C Expressway-E
Unity Connection
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Redirect URI for SSO/OAuth
• This feature enhances the security of Cisco Jabber/Webex Client
embedded browser support with following benefits:
• Provides protection against "Authorization Code Interception
Attack" using RFC7636
• Allows clients running on an Operating Systems other than iOS, to
use the Embedded Browser (For example: Android)
• Allows Jabber and Webex client to use the Embedded browser for
Unified Communications Manager (and MRA) OAuth flow.
• Improves the user experience when using Webex client and Unified
Communications Manager Calling.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Redirect URI for SSO/OAuth
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
IPv6 Support
IPv6 Support – X14.2 Preview
X14.2 will support MRA Jabber clients using an IPv6 address. Exp-E
is required to be setup in dual mode (IPv4/IPv6), Exp-C is setup as
IPv4 only.
UCM servers need to be running in dual mode.
IPv6
IPv4
Internet
UCM3 Exp-C3 Exp-E3
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Serviceability
Enhancements
System Key Recovery
• Clustering can fail and generate a “Failed to update system key”
alert, to recover the system required a factory reset of the node
showing the alert.
• New CLI command “xcommand forcesystemkeyupdate” allow us to
recover from the error without a factory reset.
xstatus alarm
*s Alarm: /
1: Description: "Failed to update system key file due to inconsistent state"
ID: "40055"
Solution: "Restart the system. If that doesn't clear the problem, contact your Cisco
representative"
Title: "Failed to update key file”
xcommand forcesystemkeyupdate
OK
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
IP/Port Filter for tcpdump on Diagnostic Logging
• Filtering the packet capture will allow to prevent the pcaps from
overwriting in a short period of time. We also increased the amount
of data we collect from 40 MB per interface to 400 MB.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Conclusion
Highlights
• SIP DoS protections stops spam calls and toll fraud attempts.
• SIP Registration failover for Jabber and WxA takes only 30 seconds
to discover failures in the SIP path when using UCM 14.
• WxA enhancements make it easier to use UCM Calling.
• Limited support for IPv6 when the infrastructure is IPv4.
• Serviceability enhancements help simplify the troubleshooting
process.
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Technical Session Surveys
• Attendees who fill out a minimum of four
session surveys and the overall event
survey will get Cisco Live branded socks!
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Pay for Learning with
Cisco Learning Credits
Cisco Learning and Certifications (CLCs) are prepaid training
vouchers redeemed directly
From technology training and team development to Cisco certifications and learning with Cisco.
plans, let us help you empower your business and career. www.cisco.com/go/certs
Here at the event? Visit us at The Learning and Certifications lounge at the World of Solutions
#CiscoLive BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
• Visit the Cisco Showcase
for related demos
BRKCOL-2060b © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Thank you
#CiscoLive
#CiscoLive