Cisco Cisco IP Contact Center Release 4.6.1 Design Guide

Page of 388
 
8-12
Cisco Unified Contact Center Enterprise 7.0, 7.1, and 7.2 SRND
OL-8669-16
Chapter 8      Securing Unified CCE
IPSec Deployment
The following notes apply to 
:
  •
Cisco_ICM and ipcc organizational unit object hierarchies are created by the application installer.
  •
Unified ICM Servers and Unified CCE Servers organizational unit objects must be created by the 
AD administrators to separately apply custom Cisco Unified ICM Security Policies through a GPO 
if required.
  •
Flexible Single Master Operation servers must be distributed across Domain Controllers in the 
appropriate sites according to Microsoft recommendations.
IPSec Deployment
The Unified CCE solution relies on Microsoft Windows IPSec and/or Cisco IOS IPSec to secure critical 
links between application servers and sites. 
 shows a number of connection paths where IPSec 
is supported. For a more detailed list of supported communication paths, refer to the Security Best 
Practices Guide for ICM and IPCC Enterprise & Hosted Editions
, available at 
The Security Best Practices Guide lists not only the supported paths but also information to help users 
deploy Windows IPSec, including recommended settings and much more.
 illustrates the guidelines provided in this chapter and shows the various server 
interconnections that should be secured with either Windows IPSec or Cisco IOS IPSec. The diagram 
also shows a number of paths that support SSL and TLS. More information on TLS support can be found 
in the section on