cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7412
Views
0
Helpful
6
Replies

Does Jabber for Windows need VPN to connect across Internet?

perrymcgrew
Level 1
Level 1

I have installed and config'd CUPS 8.6(4) and am running CUCM 8.6(2).  Basically everything seems to be working "on premise" just fine.  I take my laptop home and try to use Jabber for Windows and it does not work -- unless I start a VPN tunnel (I have Check Point FW/VPN).  My Jabber for IM iPhone client (1.0.0 bld 23241) works fine w/o a VPN.  My CUPS server is statically NAT'd to public IP and I have several TCP ports open to CUPS from the internet side based on the Admin guide.  I use FQDN to resolve the CUPS server -- it is the same internally and externally.  .  

I do not have WebEx server.  I do not understand why iPhone Jabber IM works across public internet w/o pre-establishing a VPN (unless there is a AnyConnect Lite client under the covers.)  and the Windowes client does not work! 

My boss wants to roll this out and I need Windows client to work w/o VPN.

TIA...Perry          

6 Replies 6

coflaher
Cisco Employee
Cisco Employee

Hi Perry,

Unfortunately, Jabber for Windows needs VPN access to the connect to a on-prem CUPS server.

- Colin

On page 11 of Jabber for Windows Admin Guide lists inbound / outbound ports.  I have not found anywhere that states it needs a pre-established VPN tunnel.  We are looking to replace Google Talk / Skype with Jabber for Windows.  Still don't understand how iPhone's jabber IM client does not require a VPN access -- I point it to the same public CUPS server name as the Windows client.

They do talk about WebEx integration for "cloud based deployments".  Can't see where you would need all that just to get Jabber for Windows to work across public Internet w/o pre-establishing a VPN tunnel.

-- Perry

I'm not sure how the iphone client connects, but Jabber connects in two stages.

1. Connects to CUPS over SOAP. Uses the address you enter in Jabber

2. CUPS then returns the node name of the CUPS server to connect over XMPP. This node name needs to be also be solvable.

So if the ports are allowed from a firewall perspective, and the client can resolve the CUPS hostname via both external and internal DNS, that should work?  We're looking to do the same, where we allow IM and Presence without VPN, and the rest of the UC functionality will be allowed if they are on the VPN.

mrmhar1408
Level 4
Level 4

Guys,

did we get resolution for this issue ? i have the same case, android and iphone are working without vpn but windows jabber doesn't

Sort of.

You need to deploy either VCS Expressway or Expressway Series.  The latter is free with CUWL, but you need to "order" a bunch of $0 sku's to get the licensing.  Once you have that in place, you will still need to wait for Cisco to release teh apps for those.  iOS and Android apps compabilitle with Edge haven't been released FCS yet.  Windows 9.6 is the only client FCS, and that is considered "technical preview".

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: