We want media streams with external call parties to be encrypted. We do have TLS end-to-end but I don't believe we can support SRTP to the MX300s registered to UCM w/o provisioning mixed mode (based on Cisco docs). So, we are attempting to use Media encryption policy on the VCS. Specifically, we set one of the traversal client zone to use "Best effort". This works for most calls but we have seen a couple of calls fail.
From end user perspective, failures manifest as a call that gets connected and is immediately torn down.
On the VCS, we will see the following when looking at the call history:
The B2BUA Encryption component is disconnected after ~3 seconds. The disconnect reason is: B2BUA disconnected call on the ingress saying "mismatched transport type in answer".
Based on context clues, this points to TLS negotiation. The thing is, if I set the media policy back to "auto" then the call connects fine and the transport is TLS. At least, it reports TLS on my VCS-C and VCS-E.
Any pointers that someone is willing to toss my way?
Won't help but I have a very similar but slightly different scenario with:
Jabber 10 or CUCM registered TC endpoint
As for settings:
CUCM-VCS SIP trunk is TCP not encrypted (never got it to work following the doc step by step....)
VCS-C to VCS-E is TLS as setup on the doc.
On the VCS-C, the DNSZone Media Encrytion mode is set to "Auto"
Some SIP calls work perfectly (i.e. the Cisco test endpoints) but some users have issues. Dialing partners' cloud service video-conference, the call connects and gets dropped immediately. I created myself a trial account on that service to test and can reproduce it all the time. I can see the call coming in my cloud service client and when I accept it it just drops.
On the VCS-C,
I see a SIP 200 OK
an then a call component status=disconnected type=B2BUA
Disconnect reason summary
Disconnect reason details
B2BUA disconnected call on the Egress saying "Received 'Request Timeout' to mid-dialog request"
But on the VCS-E in the call history, I only see and "408 request timeout".
When I call my Jabber account from that service it works well. But in that case the second call component with type B2BUA shows:
You have reached the Cisco Logistics Support Center.. To Check Status of
your RMA, visit Product Returns & Replacements (RMA). Need help? Contact
us by Phone or Email. North Americas Phone: 1800 553 2447 Option 4
Email: email@example.com Europe Phone: +3...
The short answer is that you don't.... That isn't entirely true while at
the same time it kind of is, but for the most part you don't configure
the softkeys. You enable or disable them via TCL. Here is the long
answer. Be sure to read the whole thing or e...
Topology: IP Phone > Switches > Microsoft NPS setup to forward 802.1x
proxy to > ISE 2.1 patch 3 Authentication: EAP-TLS using Cisco MIC SANs
Phone Models 802.1X support? 802.1x flavor Addtl Comment EAP-MD5 EAP-TLS
Cisco 3905 Y Y N Cisco 6911 Y Y N Cisco ...