Cisco Cisco TelePresence Video Communication Server Expressway 관리 매뉴얼
SIP Authentication Trust
requests. If the VCS then forwards the request on to a neighbor zone such as another VCS, that receiving system will
also authenticate the request. In this scenario the message has to be authenticated at every hop.
also authenticate the request. In this scenario the message has to be authenticated at every hop.
To simplify this so that a device’s credentials only have to be authenticated once (at the first hop), and to reduce the
number of SIP messages in your network, you can configure neighbor zones to use the Authentication trust mode
setting.
number of SIP messages in your network, you can configure neighbor zones to use the Authentication trust mode
setting.
This is then used in conjunction with the zone's authentication policy to control whether pre-authenticated SIP
messages received from that zone are trusted and are subsequently treated as authenticated or unauthenticated
within the VCS. Pre-authenticated SIP requests are identified by the presence of a P-Asserted-Identity field in the
SIP message header as defined by
messages received from that zone are trusted and are subsequently treated as authenticated or unauthenticated
within the VCS. Pre-authenticated SIP requests are identified by the presence of a P-Asserted-Identity field in the
SIP message header as defined by
The Authentication trust mode settings are:
■
On: pre-authenticated messages are trusted without further challenge and subsequently treated as
authenticated within the VCS. Unauthenticated messages are challenged if the Authentication policy is set to
Check credentials.
authenticated within the VCS. Unauthenticated messages are challenged if the Authentication policy is set to
Check credentials.
■
Off: any existing authenticated indicators (the P-Asserted-Identity header) are removed from the message.
Messages from a local domain are challenged if the Authentication policy is set to Check credentials.
Messages from a local domain are challenged if the Authentication policy is set to Check credentials.
Note:
■
We recommend that you enable authentication trust only if the neighbor zone is part of a network of trusted
SIP servers.
SIP servers.
■
Authentication trust is automatically implied between traversal server and traversal client zones.
124
Cisco TelePresence Video Communication Server Administrator Guide