Sunday, October 18, 2015

Cisco 8845 Intelligent Proximity Bluetooth Mobile Voice

An introduction to the intelligent proximity feature on the Cisco 8845 phone:

For reference, during this video I’m using a Cisco 8845 phone running firmware version 10-3-2-16, the latest available at this time.  The device is registered to a Cisco Unified Communications Manager running 10.5.2.10000-5.  There is a Cisco Expressway Edge and Core server between the phone and Communications Manager, a deployment model commonly referred to as Mobile Remote Access.  I’ll also be using an Apple iPhone 5S with no special apps or configuration.

From a Communications Manager administrative perspective, the setup is simple and the two required variables are normally already set by default. On the the 8845 device, first find the “Bluetooth” setting and confirm it’s enabled.  Then just a bit below that, verify “Allow Bluetooth Mobile Handsfree Mode” is enabled as well.

CUCM version 10.5.2.10000-5

CP-8845 firmware 10-3-2-16

CP-8845 Bluetooth settings

From a user perspective, you’ll be required to pair the iPhone with the Cisco 8845 phone. 

On the iPhone, select your settings app, then Bluetooth and if it’s not already on, turn it on now.

On the Cisco 8845 phone, select the application button, and scroll over or press the digit 3 to the select the Bluetooth menu.  First highlight “Bluetooth” and turn it on, then select “Hands-free 2-way Audio” and turn that on.  The pairing communication should begin at this time.  Finally, on the Cisco 8845, select “Add Bluetooth device”.  You should see a splash screen that says “Make sure your device is discoverable”.  Wait a few moments while the devices communicate.

Once communication is established between the Cisco 8845 and the cell phone, you will see the name of your mobile phone in the 8845 display. Select the “Pair” option. 

If successful, you’ll receive a toast message on the 8845 with a Bluetooth verification code.  You’ll also receive a “Bluetooth Pairing Request” message on the iPhone.  Press “Yes” on the 8845 and “Pair” on the iPhone.

CP-8845 with Bluetooth On and paired iPhone

Next, on the 8845 you will be given the option to save your mobile phone contacts on your deskphone.  Choosing “Yes” here imports the contacts from your iPhone for use on your 8845 desk phone.

When complete, press “Exit” on the 8845 until you are returned to the idle display.

On the Cisco phone, you should now see a new line label with the name of your iPhone. Selecting the new line changes your “External Phone Number Mask” to that of your iPhone number and provides the iPhone battery status and cell coverage as well. Note that this pairing and line appearance does not display on the Device in the Communications Manager administrative interface.

Making calls from your iPhone:

While your phones are paired, when calling from your cell phone, you will now be presented with the option to use the “CP-8845”, the “iPhone” or the “Speaker”.  The “iPhone” and “Speaker” options represent standard iPhone functions where you are selecting whether to send and receive audio through the standard iPhone ear and mouthpiece or via the iPhone speakerphone.  Choosing the “CP-8845” option though now allows you to place the call over the iPhone cellular network but use your CP-8845 phone as the audio device.  You can use the 8845 handset, a headset if equipped, or the built in speakerphone.

iPhone making call with audio over CP-8845 speakerphone


Making calls from your 8845 phone:

While your phones are paired, when calling from your desk phone, you now have the option to dial from the 8845 phone and use the handset, headset or speakerphone there, but to place the call over your iPhone and it’s cellular network.  Simply first select the new iPhone line on the 8845 and then dial your number as if you are dialing on your iPhone.

If the call was placed via the 8845 over the cellular network, once the call is in progress, pressing the “Move Audio” button changes the audio sending and receiving from the 8845 phone back to the iPhone handset.  Conversely, while the call is in progress on the iPhone, pressing “Move Audio” on the 8845 phone makes the 8845 handset, headset or speakerphone the active audio device.

CP-8845 call over iPhone with Move Audio button

Using the iPhone directory:

You can now scroll through and dial iPhone contacts form you 8845 phone. If during the pairing process you chose to save your mobile phone contacts on your deskphone, you will have a new directory option there.  On the 8845 phone, press the Directories button, scroll to and select the new directory with the name of your iPhone.  You will be presented with a list of your iPhone contacts, can scroll through and call any of them using the “Call” softkey.

CP-8845 with iPhone contacts directory

Receiving calls from your iPhone:

While your phones are paired, when receiving calls on your iPhone, your iPhone still rings and presents information like normal.  Now though, the incoming call information on your iPhone will be presented on your 8845 phone display as well, associated with the new iPhone line created during the pairing.  You can answer the incoming call to the iPhone on the 8845 using the normal Cisco “Answer” softkey, the 8845 speaker button or of course by lifting the handset.

Once the call is answered and in progress on the 8845 phone, pressing the “Move Audio” button changes the audio sending and receiving from the 8845 phone back to the iPhone handset.  Conversely, while the call is in progress on the iPhone, pressing “Move Audio” on the 8845 phone makes the 8845 handset, headset or speakerphone the active audio device.

Takeaways:
  • System Administration requires two settings per device, likely already set by default.
  • User administration requires pairing your iPhone or other device with the 8845.
  • Incoming calls to your cell phone can now be answered on your 8845 phone.
  • Outgoing calls on your 8845 phone can be sent over the iPhone cellular network if desired.
  • Once calls are in progress over the cellular network, you can toggle which device to use for audio by pressing the “Move Audio” softkey.
  • Your iPhone contacts can be accessed and dialed from your 8845 deskphone.

Additional references:

Cisco Intelligent Proximity
http://www.cisco.com/c/en/us/products/collaboration-endpoints/intelligent-proximity.html

Cisco IP Phone 8800 Series User Guide
http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/userguide/P881_BK_CC6C5F2C_00_cisco-ip-phone-8800_series.html

Cisco IP Phone 8800 Series Administration Guide
http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series.html

Friday, October 02, 2015

VG224 VG310 VG320 SCCP configuration

I've been asked a couple time lately about SCCP on analog gateways.

On the CUCM side:

First, add the gateway in CUCM and pick the SCCP protocol.  Then, much like the host name is critical in MGCP setups, you'll need to identify it with the last 10 digits of the gateways interface MAC address.  Then, still in CUCM, add however many sub-units are in your gateways so you have ports to configure.

On the gateway side:

After you get basic network connectivity and access, the basic critical SCCP related commands are:
!
!
stcapp ccm-group 1
stcapp
!
! loopbacks are generally preferred here, but the physical interfaces will work
sccp local GigabitEthernet0/0
! 7.0+ is basically standard now but check your version here against your CUCM
sccp ccm <ip address of a CUCM,  subscriber if you have one> identifier 10 priority 1 version 7.0+
!
sccp ccm <ip address of another CUCM subscriber, if you have another in a CUCM group> identifier 20 priority 2 version 7.0+
!
sccp
!
sccp ccm group 1
 ! again, loopbacks are generally preferred here
 ! keep it consistent
 bind interface GigabitEthernet0/0
 associate ccm 10 priority 1
 associate ccm 20 priority 2
!
dial-peer group 1 pots
 service stcapp
 port all
!
! check if it's working
!
show sccp
show stcapp device summary

Monday, September 28, 2015

CUCM using SIP phones as PLAR or ring down lines

Customer using Cisco 8841 and 8851 phones wanted to use a particular button on several phones as ring down or PLAR lines.  The basic idea is after accessing a DN, rather than being returned dial tone you automatically call another number.  This is common in elevators, emergency phones, common areas, etc.

The steps below are found in various CUCM documents, but step 5 needs a bit of clarification.  Since the phones I was testing with are SIP based running sip88xx.10-3-1-20, you do indeed need to apply SIP dial rules to the phone devices, but configuring the rule takes one more bit of information. See my italics and pictures.  This technique that includes defining the button used as the PLAR seems to be required for multiple button Cisco 7800 and 8800 series phones.

Note: if you are using Cisco 3905 phones as ring down / PLAR devices, you do not and should not define the button in the SIP dial pattern. 

I've modified some of the other steps to hopefully help avoid confusion as well.


How to Configure Cisco multiple line SIP phones as PLAR / ring down phones

Step 1:
Create  a partition, for example, P1, and a calling search space, for example  CSS1, so CSS1 contains P1. (In Cisco Unified Communications Manager  Administration, choose Call Routing > Class of Control > Partition or Calling Search Space.)

Step 2:
Create  a null (blank) translation pattern, for example, TP1, in partition P1. In this null (blank)  pattern, make sure that you enter the directory number for the PLAR destination in the Called Party Transformation Mask field and that the translation pattern uses a CSS that has access to that destination. (In Cisco  Unified Communications Manager Administration, choose Call Routing > Translation Pattern.)

Step 3:
Assign the calling search space, CSS1, to either a device or line on a phone that will be dialing automatically. (In Cisco Unified Communications Manager Administration, choose Device > Phone.) 

Step 4:
For phones that are running SIP, create a SIP dial rule. (In Cisco Unified Communications Manager Administration, choose Call Routing > Dial Rules > SIP Dial Rules. Choose 7940_7960_OTHER. Enter a name for the pattern; for example, PLAR1. Click Save; then, click Add Plar. Click Save.) 

Here's the missing piece:  after you click Add Plar you must define what button number on the phone has the DN that is acting as the PLAR.  Leaving the PLAR default will show you a line with a blank pattern.  While this seems correct as it is similar to the blank translation pattern you created earlier, it will not work.

Here's a working SIP Dial rule:

The device where this will be applied will automatically dial when the fourth DN / button is accessed.
In addition, if you mistakenly choose Add Pattern rather than Add PLAR and make it look just like the above rule, your PLAR will still not work.

Here's a great looking SIP Dial rule that doesn't work:

Looks good, works badly.

Step 5:
For  phones that are running SIP, assign the SIP dial rule configuration  that you created for PLAR to the phones (In Cisco Unified Communications Manager Administration, choose  Device > Phone. Choose the SIP dial rule configuration from the SIP Dial Rules drop-down list box.)

FYI... here's another post of mine from years a ago reiterating the first several steps suitable for SCCP devices http://webmaxtor.blogspot.com/2011/05/cucm-ring-down-phone.html

Sunday, September 20, 2015

Cisco CUCM weak ephemeral Diffie-Hellman public key

At the time of this writing, due to one or more SSL vulnerabilities that were discovered in CUCM’s web server you may suddenly be prevented from accessing the administrative interface. This is the result of various Internet browser upgrades attempting to protect you from these vulnerabilities but in the process, preventing access to the CUCM web pages.  The good news is because your CUCM servers are typically not exposed to remote users, the only threat would be from malicious users inside your network, and then only malicious users extremely knowledgeable in these vulnerabilities and possible exploits, and then only those literate in Cisco CUCM or other UC applications.   While compromises to your CUCM server's security may be unlikely, keeping up to date with software patches / upgrades is prudent.


Your new browser looking out for your best interests.
For your reference, Cisco publishes information re: security advisories here: http://tools.cisco.com/security/center/publicationListing.x

Google has decided to be rather unforgiving (maybe call it condescending?) and not even provide an interactive way for a Chrome user to opt out of their security measures.

The real fix is to upgrade / patch your systems to versions that rectify the vulnerabilities.

In the interim, there are workarounds for most browsers if you care to suggest your users go that route.

For Firefox (the one I use):
Navigate to about:config in the address bar.
Choose “I’ll be careful”
Search for security.ssl3.dhe_rsa_aes
Double click security.ssl3.dhe_rsa_aes_128_sha  and security.ssl3.dhe_rsa_aes_256_sha to change them to false.
Restart Firefox.

For Chrome (I haven’t tried this personally but is the commonly referenced workaround):
In MS Windows, right click on desktop and choose New | Shortcut
In the location field, including the double quotation marks enter "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --cipher-suite-blacklist=0x0039,0x0033
Choose Next and enter a name like “CUCM Chrome” and Finish.
You should be able to use that shortcut to start a version of Chrome access the CUCM interface.

Sunday, August 23, 2015

Cisco Quality Manager 10.5 upgrade issues

I'm sharing several important lessons learned during a Cisco Quality Manager upgrade from 9.0.1.57 to 10.5 SR6, given they are not well documented.  I hope it saves you some time.

Quality Manager administrator access

In environments where you are using MS Active Directory to associate users with recorded devices you may find your self unable to login to the QM administrator's application after the upgrade.  The normal Quality Manager local admin user and password doesn't seem to work, and neither do the AD accounts you've used for logging in as administrators previously. If you are really motivated and change the model to use QM Authentication, the local QM administrator works but now your administrative AD access is gone. 

What to do?

Note there is a new field buried in the Enterprise | Site Configuration | Enterprise Settings form.  You need to actually select and choose to edit one of your Active Directory entries to see it.  Of course you can't do any of this unless you run postinstall.exe because of course, your locked out.

When you choose to edit an Active Directory entry, you will find a field called Admin Group. Mine contained the value QMAdministrator.  I don't know where that value came from because the Admin Group is now actually enforced and represents a MS Active Directory group that contains users that may or may not be Quality Manager system administrators.

First, find or create a AD group that contains your potential QM admins.  Enter the display name of the group in the QM Admin Group field.

Then, when choosing OK you will be presented with a grid of users from that AD group.  Choose one or more to become system admins.  See below.



You're in.

CUCM Recording Server SIP Trunk

If you are using Cisco Built In Bridge recording / Calabrio network recording you will already have a SIP trunk configured in CUCM, pointing to your recording server.  This trunk carries information from CUCM to Quality Manager regarding the DNs that need to be recorded, and from Quality Manager regarding what recording server to use.  There's the rub.  Previously the CUCM pointed the trunk to the Quality Manager recording server and no one thought about it. Of course, you would point it to the recording server because of course that's where the recording are going to go. Right?

Calabrio has changed the basic architecture in 10.5.  You now point the SIP trunk in CUCM to the Quality Manager Base server, not the recording server.  Before you correct this, you might dig around in the QM logs and find references to your QM not receiving SIP invites on the base server and be confused. Why would you need them there? 

Reset your CUCM trunk, start WireSharking stuff, reread all the install and upgrade guides you can find from Cisco's site. Freak out a little.

Then just point the trunk to the Quality Manager base server, rather than the record server where it's been pointing forever. 

See below.


Quality Manager VoIP Devices and Recording Cluster and Signaling Group

New programmatic entities in Quality Manager probably make in more scalable and manageable. New information under Enterprise | Site Configuration | Telephony Groups allow you to parse up and group different recording resources and signalling types.  This is great, but after the upgrade you will need to verify those values have been associated with your VoIP devices correctly.  My experience was that none of my devices had been associated with a Recording Cluster or Signaling Group at all.  That won't work.

Luckily, given all my devices need to be associated with the same Recording Cluster and Signaling Group, it's an easy edit of the entire list.  If your environment has multiple recorders, this might be a more painful process.

Go to Enterprise | Record Server Configuration | VoIP Devices and clean up your mess.

See below.


Enjoy your recordings again.