Cisco connect montreal 2018 collaboration les services webex hybrides

Cisco Canada
Cisco CanadaCisco Canada
Cisco Connect Montreal
Canada • November 20th 2018
Global vision.
Local knowledge.
Yves Daigneault - TSA
Jeff Corcoran - TSA
20 novembre 2018
Meeting you wherever you are along your journey to the cloud
Webex Hybrid Services
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Agenda
• Cloud Collaboration
• Hybrid Cloud Collaboration
• Hybrid Directory Service
• Hybrid Calendar Service
• Hybrid Call Service
• Hybrid Message Service
• Cisco Webex Edge Service
• Webex Teams Cloud Security
and Hybrid Data Security
Cloud Collaboration
Common Management
Messaging Meeting Calling
Application Integration
APIs
Device registrations
Cisco Webex Hybrid
Services
Cloud + On-Premises
Cisco Webex – The Platform
BRKCOL-2607 5
Anywhere, Any Device, Any Time
Cisco Webex
Cisco Webex
Room DeviceCisco Webex
Desk Phone
Cisco Video
Endpoints
3rd
Party endpoints
& service
integrations
Webex Teams
Mobile App
Webex Teams
Desktop App
WebEx
App
Cisco Webex – Meetings
BRKCOL-2607 6
NEW
Spark Board 70
Room 70D G2Room 70S G2Room 55DRoom 55
NEW NEW NEW
Room Kit PlusRoom KitRoom Kit Mini
NEW NEW
Room Kit Pro
NEW NEW NEW
NEW
Soon
Board 55 Board 70 Board 85
2019
DX80
Share
Soon
Hybrid Cloud
Collaboration
Creating unique value by
connecting on-premises and
cloud services
Hybrid Calendar Service
Cisco Webex platform
Messaging | Meetings | Calling
Existing Services
Hybrid Call Service
• Call Service Aware
• Call Service Connect
Hybrid Directory Service
Hybrid Media Service
Hybrid Data Security
Cisco Webex Hybrid Services: AND, not OR
9BRKCOL-2607
Hybrid Message Service
Expressway
Windows
*Includes Business Edition or HCS
Webex
Messenger
Integrating On-Premises and Cloud
10
Directory Calendar Media KMS
Microsoft AD Exchange Media Node
Data
Security
Call Message
IM&PCisco UCM*
?
Platform
BRKCOL-2607
SIPTrunk
XMPP
Expressway
C
DMZ
Collaboration Cloud Infrastructure
Collaboration Cloud Services
Media/TranscodingNotification/Alerts
Messaging Interop Content Sharing
Call Control RoomsIdentity/SSO
File
Storage
Metadata
Storage
Metrics &
Reporting
Billing &
Provisioning
Management Calendar Future
DC
Serviceability
Connector
Management
Connector
Common Connector Framework
Message
Connector
Calendar
Connector
Management Connector
Directory
Connector
Call
Connector
FutureService
Connector
BRKCOL-2607 11
Webex Admin Control Hub
12Presentation ID
Hybrid Service Expressway-C Registration Complete
BRKCOL-2607 13
Hybrid Directory Service
and SSO
Hybrid Directory Service
and SSO
Admin Portal DirSync User Configuration
BRKCOL-2607 15
Provisioning via Directory Connector
• Infrastructure for premises directory synchronization to the Identity cloud services
• Directory connector integrates with AD to retrieve user information to sync with the
identity service, and specifies the Active Directory synchronization agreement and
attribute mappings
• Customer installs Directory Connector in its network on a Windows Domain server
(Windows Server 2003, 2008 R2, 2012, 2012 R2, 2016) with administrative user privilege
• Directory Connector supports Single Forest, Multi-Domain and Multi-Forest, Multi-Domain
Directory
Connector
Active
Directory
Cisco Webex Cloud
Identity/SSO
HTTPS
BRKCOL-2607 16
Windows
WebEx
Messenger
17
On-Premises Directory Synchronization
Directory
Microsoft AD
BRKCOL-2607
Hybrid Calendar Service
Calendaring Scheduling Integration with @webex or @meet
@webex will backfill the users personal room
information into the calendar invite (seen here)
@meet will utilize the Cisco Webex Teams
space information when populating a calendar
invite, or create a new space (next page).
BRKCOL-2607 19
Calendaring Scheduling Integration with @webex
20Presentation ID
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Calendaring Scheduling Integration with @meet
21Presentation ID
Calendaring Scheduling Integration with @meet
22Presentation ID
23
OBTP User Meeting Scheduling Experience
Cloud Registered
Room Device
Bookable Resource
BRKCOL-2607
24
OBTP User Meeting Join Experience
Before Meeting
During Meeting
Cloud Registered Room Device
BRKCOL-2607
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Set Out-of-Office from Outlook
25Presentation ID
Edge
Exchange /
Office 365
Calendar
WebEx
Messenger
26
Calendar Service Hybrid Exchange Calendaring
BRKCOL-2607
Edge
Calendar
WebEx
Messenger
27
Calendar Service Hybrid Exchange Calendaring
BRKCOL-2607
Cloud Calendar Connector uses the same
system architecture; however, the connector
resides in the Cisco Collaboration Cloud (i.e.
requires no premises infrastructure)
Hybrid Call Services
Webex Hybrid Call Service at a Glance
Call Service Aware
Provides the Webex Teams application an awareness of calls placed between the on
premise devices of two Aware enabled users. This means a one-to-one space will be
created for the users and they will be offered the ability to share their screen with one click.
Call Service Connect
Provides Webex Teams users the ability to make and receive calls on their Webex Room
Devices or Webex Teams application by leveraging the on premise infrastructure’s dialing
capabilities
29
Call Connect for Webex Teams
30Presentation ID
Calling my mobile from Teams
Calling my Cisco phone number
from my mobile
Hybrid Call Service for Cisco Webex Devices Architecture
31Presentation ID
Edge
WebEx
Messenger
32
Call Service Integration for CUCM
BRKCOL-2607
*Includes Business Edition or HCS
Call
Cisco UCM *
Call Service Aware/Connect Architecture
Expressway-E Expressway-C
Expressway-C
(Connectors)
Communications
Manager
SIP
AXL/SOAP/RIS
CTIQBE
REST/HTTPS
*.ciscospark.com example.com
Hybrid Message Service
Expressway
Hybrid Message Service Integration
35
Message
IM&P
?
BRKCOL-2607
SIPTrunk
XMPP
Expressway
C
DMZ
Collaboration Cloud Infrastructure
Collaboration Cloud Services
Media/TranscodingNotification/Alerts
Content Sharing
Call Control RoomsIdentity/SSO
File
Storage
Metadata
Storage
Metrics &
Reporting
Billing &
Provisioning
Management Calendar Future
Messaging Interop
Serviceability
Connector
FutureService
Connector
Management
Connector
Common Connector Framework
Message
Connector
Calendar
Connector
Message Service
Directory
Connector
DC
Call
Connector
RESTful https
BRKCOL-2607 36
AXL / XMPP
Cisco Webex Teams / Jabber Interoperability - Presence
37
• When user is running Jabber, the user’s Presence on
Jabber shall be based on existing Jabber logic
• Available / Busy / Presenting / In meeting, etc.
• When user is not running Jabber, the user’s Presence
on Jabber shall be based on WebEx Teams activity
• “Available On WebEx Teams” when the user has
been active on WebEx Teams within the last 24
hours
• “Offline” when the user has not been active on
WebEx Teams for over 24 hours
Note: Webex Teams Presence is not impacted due to user’s Jabber activity
BRKCOL-2607
Cisco Webex Teams / Jabber Interoperability - Message
38
• Cisco Webex Teams Interop will allow 1:1 message only between
Jabber and Webex Teams users.
• Users must be configured and enabled on both IM&P and Webex
Teams
• Message Connector will map Jabber and the Webex Teams ID using
a common email address
• Notifications include is Typing, Message Read, Deletes, or Missed
• File transfer is not supported.
o When a Webex Teams user posts a file, Cisco Jabber will receive a notification to
get access to the file in the Webex Teams web client
BRKCOL-2607
Cisco Webex Edge
Service
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Cisco Webex Edge service
Webex Edge service
Enhanced
Quality
Consistent
Experience
No Change in
User Behavior
Cost
Savings
Purpose-built for collaboration and
real-time media
Customer Premises
Leverage existing investments
Reshaping the edge to maximize the power of the Webex cloud
Version 1.1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Capabilities of Webex Edge
Intelligent Audio + Direct Connection + Industry-Leading Media Experiences
Audio Connect Video Mesh
Webex Edge
New New
Version 1.1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Multiple deployment options
1
3
2
Webex Edge Connect provides peering connection to Webex datacenters for media.
• Can be used with Webex Edge Audio.
• Can be used with Video Mesh.
• Not required for either service to operate but recommended for Edge Audio.
Webex Edge Audio provides dial in and call back for Webex meeting audio to customer premises.
• Does not require Edge Connect, but is strongly recommended to be used with Edge Audio.
• Does not require Video Mesh, functions independently from this service.
Webex Edge Video Mesh provides on premises meeting resources for devices and Teams app.
• Does not require Edge Connect, but can utilize the direct peering link.
• Does not require Edge Audio, functions independently from this service.
Version 1.1
Audio Connect Video Mesh
Webex Edge
New New
Webex Edge Audio
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Webex Edge Audio
Intelligent audio routing
•Intelligent audio routing: integrating Webex with
Unified CM
• Creates end-to-end VoIP path for Unified CM
registered devices (callback and dial-in)
• Uses company’s own PSTN for any other device
(callback savings)
• No SIP trunks or peering arrangements required
•Geo-country code configurable
•Included in Collaboration Flex Plan – no extra
charge. No port charges on Expressway
•Supports Webex Meetings, Events, Training
•Enhanced audio quality when G.722 is enabled
No user training, no change in user behavior, easy for IT
IP
Phone
Cisco
Unified CM
Customer
Premises
Media Path
Z
Expressway
C/E
Webex Edge
Audio
Signaling
Meeting
Version 1.1
Unified CM support only
• 10.5 or later
Cisco UCM registered IP phones
• Supporting G.711 or G.722
Expressway support only
• X8.10 or later
• Can use existing Expressway C/E deployment
• Audio scale dependent on Expressway deployment
and services enabled.
Webex site
• WBS 33.x or higher
• Included in Flex, A-WBX and A-SPK SKU need the
Webex Edge Audio package
• Not available on CCA-SP, CCA-ENT or TSP sites.
• Requires migration to Webex Audio Site
Requires a signed certification from a Cisco trusted
Certificate Authority (CA)
Cisco Webex Edge Audio
Architecture requirements
IP
Phone
Cisco
Unified
CM
Customer
Premises
Media Path
Z
Expressway C/E
Webex Edge
Audio
Signaling
Meetin
g
Version 1.1
Webex Edge Audio Configuration Steps:
1. Obtain dial-in numbers and Lua script
from Site Administration
2. Configure DNS SRV records (5062)
3. Configure Unified CM
4. Set Up Expressway-C
5. Set Up Expressway-E
5. Open Firewall ports
6. Apply Signed Certificate From Trusted
Certificate Authority
7. Apply Edge Audio Callback Settings
Cisco Webex Edge Audio
Architecture configuration
IP
Phone
Cisco
Unified
CM
Customer
Premises
Media Path
Z
Expressway C/E
Webex Edge
Audio
Signaling
Meetin
g
Version 1.1
1. Endpoint dials Webex Audio access number.
2. Cisco UCM matches the number and routes
as +E.164 through SIP trunk to Expressway-
C.
3. LUA script on SIP trunk to Expressway-C
applies transformations required for correct
routing to Webex
4. Expressway-C sends request to
Expressway-E.
5. Expressway-E routes call to the Webex
cloud.
6. Meeting resources are setup.
Cisco Webex Edge Audio
Dial in Signaling Call Flow
IP
Phone
Cisco
Unified
CM
Customer
Premises
Media Path
Z
Expressway C/E
Webex Edge
Audio
Signaling
Meetin
g
Dials Webex Access Number
SIP Trunk
1
2 3 4
5
Version 1.1
1. The IP phone sends media to Expressway-C
2. The Expressway-C sends media to
Expressway-E via the traversal zone
3. The Expressway-E sends media to the
Webex cloud.
4. IP phone’s audio is mixed into the meeting
and it hears the other participants.
Cisco Webex Edge Audio
Dial in Media Call Flow
IP
Phone
Cisco
Unified
CM
Customer
Premises
Media Path
Z
Expressway C/E
Webex Edge
Audio
Signaling
1
2 3
4
Meetin
g
Version 1.1
Webex Edge Audio Callback Set Up Steps:
1. Apply Webex Edge Audio Callback Settings
• Define country callback parameters in Site Admin
• Ensure proper SRV record configuration for
Expressway
• Ensure connectivity checks are successful.
• Cisco UCM routes the +E.164 audio call to the IP
phones or local PSTN
Cisco Webex Edge Audio
Architecture configuration
IP
Phone
Cisco
Unified
CM
Customer
Premises
Media Path
Z
Expressway C/E
Webex Edge
Audio
Signaling
Meetin
g
PSTN
Version 1.1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Single Country Call Back – Multiple Expressways
Customer
Premises
Z
Webex Edge
Audio
Meetin
g
USA
Intern
et
• Expressway-E is configured in Webex for callback
• +1 is defined in Webex callback settings
• SRV records along with DNS configuration will determine
cluster routing or load balancing
Site 1Cisco
Unified CM
DNS SRV:
_sips._tcp.edge-amer.example.com
DNS SRV Records
_sips._tcp.edge-amer.example.com. 60 IN SRV 0 5 5062 exp-amer1.example.com.
_sips._tcp.edge-amer.example.com. 60 IN SRV 0 5 5062 exp-amer2.example.com.Z
Webex Edge
Audio
Site 2
Cisco
Unified CM
Call back made to
On net IP phone
Laptop
Client
exp-amer1.example.com
exp-amer2.example.com
WAN
Signaling
Media Path
Version 1.1
Caveats
• CCA- SP, CCA-ENT, TSP customers can not use their present
configuration with Edge Audio.
• If a call fails, user needs to dial into the call or callback.
• Dial-in through customer owned E.164 or VOIP numbers is not
supported.
• Reroute call back to Webex PSTN resources if rejected by UCM is
not available
• Unable to define Class of Service for call back
• OPUS codec not supported
Webex Audio Caveats
Initial release
Version 1.1
Webex Edge Connect
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Webex Edge Connect
Brings the power of the Webex backbone directly to your data center
Webex Edge Connect
• A direct peering at Equinix data centers
• Bypasses the Internet by providing a direct connection1
to the Webex data center
• All Webex media traffic traverses the dedicated link providing
end-to-end QoS. (VoIP, video, content sharing)
• When used with Video Mesh provides a more secure
end-to-end experience
1 via a peering agreement with Equinix
Webex Edge
Version 1.1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Customer Requirements
1. A cage and router in place at Equinix
2. A paid connection to the Equinix Cloud Exchange
3. Knowledge of BGP Routing
4. Public BGP Autonomous System Number
5. Public provider independent IP block
• No RFC1918 addressing (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
• Customer may rent a /29 IP block from Equinix
6. Paid service to Cisco Webex
Customer
Premises
Equinix Cloud
Exchange
(ECX)
Cisco Webex
Version 1.1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Connectivity - Components
Layer 2
(802.1q)
Equinix
Cloud Exchange
Layer 3
(BGP)
Layer 1
(1G/10G)
AS13445
Customer
Network
1. Layer 1 – Physical Connectivity
2. Layer 2 – Ethernet Connectivity
3. Layer 3 – IP connectivity
Network Details
1. Customer orders physical circuit
to ECX fabric
2. Customer provisions virtual
circuit to Cisco WebEx using
Equinix self-service portal
3. Customer completes WebEx
BGP network questionnaire
4. Cisco enables BGP connection
to the Customer to establish
connectivity
Equinix responsibility:
ü Physical link provisioning (cross connects)
ü Virtual circuit monitoring reports & support
Roles and Responsibilities
Cisco responsibility:
ü Peering provisioning and support
Version 1.1
• A customer sets up dual connections to
Equinix for redundancy
• Cisco Webex has redundant connection to
Equinix at all colocations across the globe
• BGP routing is used to route traffic across
the peering connection.
• Customers that have a global presence
can choose which regions to peer.
• Customer’s Internet connection is used as
fallback
Architecture
Equinix
PRI SEC
Customer Premises
PRI SEC
ORD10-WXBB-CRT01
Cisco Webex
ORD10-WXBB-CRT02
ORD10-WXBB-PE02ORD10-WXBB-PE01
Intern
et
Version 1.1
Z
• Media flows via Equinix peering
connection.
• Webex Meetings app signaling
and media use the peering
connection
• Signaling for cloud registered
devices and Webex Teams uses
the public Internet
• Third party services accessed via
the Internet
Signaling and Media Flow
Customer
Signaling only
Internet
Media Path
Signaling
Webex AS13445
Webex IP blocks:
https://collaborationhel
p.cisco.com/article/en-
us/WBX000028782
Version 1.1
Webex Edge Video
Mesh
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Webex Edge Video Mesh
On-premises video quality and bandwidth savings
Webex Edge Video Mesh
• Automatic overflow if local capacity is full / unavailable
• Software extends cloud to the premises
- media stays local for on-premises attendees
• Cloud simple: managed by & registered to Webex cloud local media
kept local
Video Mesh
Node
local media
kept local
Video Mesh
Node
local media
kept local
Video Mesh
Node
Version 1.1
• Video Mesh is part of the Webex Edge solution
• Video Mesh functionality is the same, handling
the Main Video, Speaker’s Audio and Content
being shared by the video devices in the
meeting that can utilize Video Mesh
• Video Mesh communicates directly to Webex
cloud and terminates the media for cloud
registered device and SIP video endpoints for
dialing into Webex meetings.
• Webex Teams, Webex registered devices and
Cisco UCM registered SIP video endpoints use
Video Mesh. Webex Meeting app or Webex
Teams browser does not use Video Mesh.
Cisco Webex Edge Video Mesh
Architecture
SIP
Video
Endpoint
Cisco
Unified
CM
Customer
Premises
Media Path
ZExpressway C/E
Webex Edge
Audio
Signaling
Video
Mesh
Cloud
Registered
Video
Endpoint
Meeting
Version 1.1
SIP
Trunk
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
• Video Mesh is part of the Webex Edge solution
• Video Mesh functionality is the same, handling
the Main Video, Speaker’s Audio and Content
being shared by the video devices in the
meeting that can utilize Video Mesh
• Video Mesh communicates directly to Webex
cloud and terminates the media for cloud
registered device and SIP video endpoints for
dialing into Webex meetings.
• Webex Teams, Webex registered devices and
Cisco UCM registered SIP video endpoints use
Video Mesh. Webex Meeting app or Webex
Teams browser does not use Video Mesh.
Cisco Webex Edge Video Mesh
Architecture
SIP
Video
Endpoint
Cisco
Unified
CM
Customer
Premises
Media Path
ZExpressway C/E
Webex Edge
Audio
Signaling
Video
Mesh
Cloud
Registered
Video
Endpoint
Meeting
Version 1.1
SIP Trunk
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
CASCADE CASCADE
Architecture
MEDIA
NODE
MEDIA
NODE
00:50
MEDIA
NODE
• Cloud and Premises nodes
• Hub and Spoke design
• Cascades initiated from premise to cloud
• Inside à Cloud only
Uses the Node
1. Any Webex registered device
Ø SX, MX, RK series, Webex Board
2. Webex Teams app
3. CUCM registered devices
Ø Calling a Webex scheduled, Webex
PMR, or space meeting including the IX.
4. VCS/Exp registered devices
Ø Calling a Webex scheduled Webex
PMR, or space meeting
Ø SIP or H.323 (requires Interworking)
5. Webex dial back to Webex
registered endpoints
Can NOT Use the Node
1. Webex Teams browser client
Ø web.ciscospark.com
2. Webex Call registered phones
Ø 88xx and 78xx (Spark Call) IP
Phones
3. Webex dialing back to SIP registered
endpoints
4. Webex Meetings app
What devices and scenario can the media node
be used?
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Capacity on Multiparty Media 410v and Cisco
Meeting Server 1000
Server (version) Max simultaneous calls per server
Cisco Spark only
(720p | 1080p)
Standard based SIP endpoints and
Cisco Spark app/devices
(720p | 1080p)
MM410v (Full version) 100 | 75 65 | 48
CMS 1000 (Full version) 100 | 75 80 | 60
Demo version 10 | 5 10 | 5
Note: If all the meetings hosted on a given Hybrid Media Node have only Cisco Spark apps and devices,
then the server can scale up to 100 participants at 720p. If all meetings have a mix of Cisco Spark and SIP
participants, then the scale goes up to 80 participants for the CMS 1000 server and 65 participants for the
MM410v server.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Webex Video Mesh Requirements
Component purpose Minimum supported version
On-Premises call control Cisco Unified Communications Manager, Release 10.5(2) SU5 or
later
Cisco Expressway-C or E, Release X8.9.2 or later
Meeting infrastructure Cisco Webex Meetings WBS31.11.1, WBS31.12.1, WBS31.20, or
WBS32.0.2 and above, enabled with video platform version 2.0
Webex Edge
Audio, Video Mesh and
Connect
• Video Mesh and Edge Audio work
independently but are part of an overall
solution when connecting to a Webex meeting.
• IP phones dialing in or call back to the Webex
meeting use +E.164 numbers and utilize the
Expressway to connect to the Webex meeting.
(Webex Edge Audio)
• Cisco UCM registered SIP video endpoints,
Webex registered devices and Webex Teams
app dial SIP URIs to the Webex meeting and
use Video Mesh for local media processing.
• Webex Meeting app goes directly to the
Webex Cloud.
Cisco Webex Edge Audio + Video Mesh
Signaling and Media
Version 1.1
SIP
Video
Endpoint
Cisco
Unified
CM
Customer
Premises
Media Path
ZExpressway C/E
Webex Edge
Audio
Signaling
Video
Mesh
Cloud
Registered
Video
Endpoint
IP
Phone
SIP Trunk
Meetin
g
SIP
Trunk
• Webex Connect is a peering connection
to Cisco Webex.
• Both Video Mesh and Webex Edge Audio
can use the Webex Edge Connect peering
service to connect media to the Webex
Meeting, but it is not a requirement.
• Webex Teams signaling goes via the
Internet link and all media goes via Webex
Connect.
• Webex Meetings app sends signaling and
media via Webex Connect.
• If the peering connection is not available
all signaling and media traffic will flow via
the Internet.
Cisco Webex Edge Audio + Video Mesh +
Connect
Architecture
SIP Video
Endpoint
IP
Phone
Laptop
Client
Cisco
Unified
CM
Customer
Premises Media Path
ZExpresswa
y
Webex Edge
Video Mesh
Signaling
Connect
InternetLaptop
Client
Meeting
Version 1.1
Webex Teams Cloud
Security and Hybrid
Data Security
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Security mechanisms
• Realms of separation
• Identity Obfuscation
• SSO authentication using SAML based IdP
• OAuth access and refresh token based authorization
• Key Management Service for managing encryption keys
• End to end encryption of content (one key per space)
• Data encrypted in transit
• Data encrypted at rest
• Application layer database content encryption
• Hash key based secure index and search (one key per space)
• Secure compliance reporting service based on hashed index
Security Option for On-Premise Control
Webex Teams Security
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Secure Data Center
Content Server
Key Mgmt Service eDiscovery ServiceIndexing Service
Hybrid Data Security
Hybrid Data Security
=
On-Premises
Key Management Service
Indexing Service
eDiscovery Service
Requires
Pro Pack
Add-onHybrid Data Security (HDS)
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Secure Data Center
Content Server Key Mgmt Server
The Hybrid Key Management
Service performs the same
functions as the cloud based
Key Management Service
Customer now owns and
manages all of the keys for
messages and content
BUT
Key Management Service
Key Mgmt Service
Requires
Pro Pack
Add-onHDS – Key Management
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS
Secure Data Center
Content Server
Hybrid Data Security
Hybrid Data Security
Multiple servers can be provisioned
for Scalability & Load Sharing
Hybrid Data Security instances are
managed and upgraded from the
cloud
Customers can access usage
information for the HDS services via
the Cisco Webex Control Hub
Requires
Pro Pack
Add-on
Hybrid Data Security
Key Mgmt Server
HDS - Scalability
HDS Install Prerequisites
HDS Deployment Guide https://www.cisco.com/go/hybrid-data-security
X.509 Certificate, Intermediates and Private Key
PKI is used for KMS to KMS federation (Public Key Infrastructure)
Common Name signed by member of Mozzila Trusted Root Store
No SHA1 signatures, PKCS12 format
2 ESXi Virtualized Hosts: Min 2 to support upgrades, 3 recommended, 5 max
Minimum 4 vCPUs, 8-GB main memory, 50-GB local hard disk space per server
1 Microsoft SQL or Postgres 9.6.1 Database Instance (Key datastore)
8 vCPU, 16 GB RAM, 2 TB Disk. User created with createuser. Assigned GRANT ALL PRIVILEGES ON database.
1 Syslog Host
Hostname and port required to centralize syslog output from HDS instances and management containers
A secure backup
The HDS system requires organization administrators to securely backup :
1) A configuration ISO file generated during the install process
2) The MS SQL/ Postgres database.
Failure to maintain backups will result in loss of customer data.
See Standby Data Center for Disaster Recovery section of the HDS Deployment Guide
Network
Outbound HTTPS on TCP port 443 from HDS host
Bi-directional WSS on TCP port 443 from HDS host
TCP connectivity from HDS host to Postgres database host, syslog host and statsd host
HTTPS proxies not supported today
75© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
• Hybrid services connect premises resources to cloud
• Each hybrid service can be deployed independently
• Benefits
• Leverage premises investments
• Enhance user experience
• Increase security
• Ease management
• Transition to cloud at desired pace
Key Points
#CLUS
1 von 76

Recomendados

ملخص عرض فكرة المشروع von
ملخص عرض فكرة المشروعملخص عرض فكرة المشروع
ملخص عرض فكرة المشروعEyad Barhoum
362 views9 Folien
Business model canvas نموذج العمل التجاري von
Business model canvas  نموذج العمل التجاري Business model canvas  نموذج العمل التجاري
Business model canvas نموذج العمل التجاري Mohamed Reda
1.5K views28 Folien
IMD3.pdf von
IMD3.pdfIMD3.pdf
IMD3.pdfYves Pigneur
77 views140 Folien
Value proposition of analytics in P&C insurance von
Value proposition of analytics in P&C insuranceValue proposition of analytics in P&C insurance
Value proposition of analytics in P&C insuranceGregg Barrett
12.7K views39 Folien
The Common Challenges of Common Practices: Tips for Effectively Moving to a S... von
The Common Challenges of Common Practices: Tips for Effectively Moving to a S...The Common Challenges of Common Practices: Tips for Effectively Moving to a S...
The Common Challenges of Common Practices: Tips for Effectively Moving to a S...eprentise
1.5K views50 Folien
ملخص كتاب سيكولوجية الإقناع - روبرت شالديني von
ملخص كتاب سيكولوجية الإقناع - روبرت شالدينيملخص كتاب سيكولوجية الإقناع - روبرت شالديني
ملخص كتاب سيكولوجية الإقناع - روبرت شالدينيAhmed Al-Shamy
5.3K views7 Folien

Más contenido relacionado

Was ist angesagt?

اهم استراتيجيات التسويق von
اهم استراتيجيات التسويقاهم استراتيجيات التسويق
اهم استراتيجيات التسويقosmanabdelrhman
793 views19 Folien
About Workday von
About WorkdayAbout Workday
About WorkdayWorkday
3K views4 Folien
コンサルタントの選び方活用方法 von
コンサルタントの選び方活用方法コンサルタントの選び方活用方法
コンサルタントの選び方活用方法Osami Nakamura
2.1K views8 Folien
Cross selling credit card to existing debit card customers von
Cross selling credit card to existing debit card customersCross selling credit card to existing debit card customers
Cross selling credit card to existing debit card customersSaurabh Singh
149 views10 Folien
A.M.REVOLT QNET: صناعة البيع المباشر العالمية von
A.M.REVOLT QNET: صناعة البيع المباشر العالميةA.M.REVOLT QNET: صناعة البيع المباشر العالمية
A.M.REVOLT QNET: صناعة البيع المباشر العالميةABIDI MARWA
3.9K views21 Folien
It budget von
It budgetIt budget
It budgetsucesu68
8K views31 Folien

Was ist angesagt?(10)

اهم استراتيجيات التسويق von osmanabdelrhman
اهم استراتيجيات التسويقاهم استراتيجيات التسويق
اهم استراتيجيات التسويق
osmanabdelrhman793 views
About Workday von Workday
About WorkdayAbout Workday
About Workday
Workday3K views
コンサルタントの選び方活用方法 von Osami Nakamura
コンサルタントの選び方活用方法コンサルタントの選び方活用方法
コンサルタントの選び方活用方法
Osami Nakamura2.1K views
Cross selling credit card to existing debit card customers von Saurabh Singh
Cross selling credit card to existing debit card customersCross selling credit card to existing debit card customers
Cross selling credit card to existing debit card customers
Saurabh Singh149 views
A.M.REVOLT QNET: صناعة البيع المباشر العالمية von ABIDI MARWA
A.M.REVOLT QNET: صناعة البيع المباشر العالميةA.M.REVOLT QNET: صناعة البيع المباشر العالمية
A.M.REVOLT QNET: صناعة البيع المباشر العالمية
ABIDI MARWA3.9K views
It budget von sucesu68
It budgetIt budget
It budget
sucesu688K views
The BPO Transformation Journey von Capgemini
The BPO Transformation JourneyThe BPO Transformation Journey
The BPO Transformation Journey
Capgemini3.3K views
التوثيق العلمي von majoodahsaad
التوثيق العلمي التوثيق العلمي
التوثيق العلمي
majoodahsaad45.8K views
المال في الاسلام von Abdul Ghani
المال في الاسلامالمال في الاسلام
المال في الاسلام
Abdul Ghani1.5K views

Similar a Cisco connect montreal 2018 collaboration les services webex hybrides

Cisco Connect Halifax 2018 Cisco Spark hybrid services architectural design von
Cisco Connect Halifax 2018   Cisco Spark hybrid services architectural designCisco Connect Halifax 2018   Cisco Spark hybrid services architectural design
Cisco Connect Halifax 2018 Cisco Spark hybrid services architectural designCisco Canada
606 views42 Folien
How to Transform Your Workplace with Hybrid Collaboration von
How to Transform Your Workplace with Hybrid CollaborationHow to Transform Your Workplace with Hybrid Collaboration
How to Transform Your Workplace with Hybrid CollaborationCisco Webex
272 views35 Folien
Cisco Spark Hybrid Service Design Guide by PlanetComm von
Cisco Spark Hybrid Service Design Guide by PlanetCommCisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetCommNarin Fungsatit
160 views23 Folien
Deploying WebEx Between Cloud and On-Prem for Canadian Customers von
Deploying WebEx Between Cloud and On-Prem for Canadian CustomersDeploying WebEx Between Cloud and On-Prem for Canadian Customers
Deploying WebEx Between Cloud and On-Prem for Canadian CustomersCisco Canada
5.6K views50 Folien
TechWiseTV Workshop: Intercloud Fabric von
TechWiseTV Workshop: Intercloud FabricTechWiseTV Workshop: Intercloud Fabric
TechWiseTV Workshop: Intercloud FabricRobb Boyd
770 views73 Folien
emea_cisco_live_webinar_150623.pptx von
emea_cisco_live_webinar_150623.pptxemea_cisco_live_webinar_150623.pptx
emea_cisco_live_webinar_150623.pptxThousandEyes
217 views44 Folien

Similar a Cisco connect montreal 2018 collaboration les services webex hybrides(20)

Cisco Connect Halifax 2018 Cisco Spark hybrid services architectural design von Cisco Canada
Cisco Connect Halifax 2018   Cisco Spark hybrid services architectural designCisco Connect Halifax 2018   Cisco Spark hybrid services architectural design
Cisco Connect Halifax 2018 Cisco Spark hybrid services architectural design
Cisco Canada606 views
How to Transform Your Workplace with Hybrid Collaboration von Cisco Webex
How to Transform Your Workplace with Hybrid CollaborationHow to Transform Your Workplace with Hybrid Collaboration
How to Transform Your Workplace with Hybrid Collaboration
Cisco Webex272 views
Cisco Spark Hybrid Service Design Guide by PlanetComm von Narin Fungsatit
Cisco Spark Hybrid Service Design Guide by PlanetCommCisco Spark Hybrid Service Design Guide by PlanetComm
Cisco Spark Hybrid Service Design Guide by PlanetComm
Narin Fungsatit160 views
Deploying WebEx Between Cloud and On-Prem for Canadian Customers von Cisco Canada
Deploying WebEx Between Cloud and On-Prem for Canadian CustomersDeploying WebEx Between Cloud and On-Prem for Canadian Customers
Deploying WebEx Between Cloud and On-Prem for Canadian Customers
Cisco Canada5.6K views
TechWiseTV Workshop: Intercloud Fabric von Robb Boyd
TechWiseTV Workshop: Intercloud FabricTechWiseTV Workshop: Intercloud Fabric
TechWiseTV Workshop: Intercloud Fabric
Robb Boyd770 views
emea_cisco_live_webinar_150623.pptx von ThousandEyes
emea_cisco_live_webinar_150623.pptxemea_cisco_live_webinar_150623.pptx
emea_cisco_live_webinar_150623.pptx
ThousandEyes217 views
TLC303_Walkthrough Setting up a Highly Available Communications Platform on AWS von Amazon Web Services
TLC303_Walkthrough Setting up a Highly Available Communications Platform on AWSTLC303_Walkthrough Setting up a Highly Available Communications Platform on AWS
TLC303_Walkthrough Setting up a Highly Available Communications Platform on AWS
Amazon Web Services1.5K views
Webex APIs for Administrators - CL20B - DEVNET-2610 von Cisco DevNet
Webex APIs for Administrators - CL20B - DEVNET-2610Webex APIs for Administrators - CL20B - DEVNET-2610
Webex APIs for Administrators - CL20B - DEVNET-2610
Cisco DevNet197 views
DEVNET-1122 Integrating Cisco Collaboration into Web Apps von Cisco DevNet
DEVNET-1122	Integrating Cisco Collaboration into Web AppsDEVNET-1122	Integrating Cisco Collaboration into Web Apps
DEVNET-1122 Integrating Cisco Collaboration into Web Apps
Cisco DevNet2.9K views
New ThousandEyes Product Features and Release Highlights: July 2023 von ThousandEyes
New ThousandEyes Product Features and Release Highlights: July 2023New ThousandEyes Product Features and Release Highlights: July 2023
New ThousandEyes Product Features and Release Highlights: July 2023
ThousandEyes51 views
Citrix Cloud Master Class June 2014 von Citrix
Citrix Cloud Master Class June 2014Citrix Cloud Master Class June 2014
Citrix Cloud Master Class June 2014
Citrix1.3K views
Cisco’s Cloud Strategy, including our acquisition of CliQr von Cisco Canada
Cisco’s Cloud Strategy, including our acquisition of CliQr Cisco’s Cloud Strategy, including our acquisition of CliQr
Cisco’s Cloud Strategy, including our acquisition of CliQr
Cisco Canada1.9K views
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf von HarryH11
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdfBRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
BRKDCN-2670 Day2 operations for Datacenter VxLAN EVPN fabrics.pdf
HarryH1110 views
Cisco Webex Board - Maticmind von Maticmind
Cisco Webex Board - MaticmindCisco Webex Board - Maticmind
Cisco Webex Board - Maticmind
Maticmind100 views
Docker Enterprise Networking and Cisco Contiv - Cisco Live 2017 BRKSDN-2256 von Mark Church
Docker Enterprise Networking and Cisco Contiv - Cisco Live 2017 BRKSDN-2256Docker Enterprise Networking and Cisco Contiv - Cisco Live 2017 BRKSDN-2256
Docker Enterprise Networking and Cisco Contiv - Cisco Live 2017 BRKSDN-2256
Mark Church1K views
Seven Criteria for Building an AWS Global Transit Network von Khash Nakhostin
Seven Criteria for Building an AWS Global Transit NetworkSeven Criteria for Building an AWS Global Transit Network
Seven Criteria for Building an AWS Global Transit Network
Khash Nakhostin172 views
Equinix cloud exchange fabric.pdf von Timucin Dikmen
Equinix cloud exchange fabric.pdfEquinix cloud exchange fabric.pdf
Equinix cloud exchange fabric.pdf
Timucin Dikmen29 views
Hybrid Solution Integration von BizTalk360
Hybrid Solution IntegrationHybrid Solution Integration
Hybrid Solution Integration
BizTalk3601.1K views
Foundry Management System Desktop Application von Dharmendra Sid
Foundry Management System Desktop Application Foundry Management System Desktop Application
Foundry Management System Desktop Application
Dharmendra Sid576 views
2020-02-10 Java on Azure Solution Briefing von Ed Burns
2020-02-10 Java on Azure Solution Briefing2020-02-10 Java on Azure Solution Briefing
2020-02-10 Java on Azure Solution Briefing
Ed Burns95 views

Más de Cisco Canada

Cisco connect montreal 2018 net devops von
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devopsCisco Canada
6.5K views56 Folien
Cisco connect montreal 2018 iot demo kinetic fr von
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic frCisco Canada
1.3K views24 Folien
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization von
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco Canada
1.4K views59 Folien
Cisco connect montreal 2018 secure dc von
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dcCisco Canada
973 views47 Folien
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns von
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla nsCisco Canada
1.5K views57 Folien
Cisco connect montreal 2018 vision mondiale analyse locale von
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse localeCisco Canada
682 views68 Folien

Más de Cisco Canada(20)

Cisco connect montreal 2018 net devops von Cisco Canada
Cisco connect montreal 2018 net devopsCisco connect montreal 2018 net devops
Cisco connect montreal 2018 net devops
Cisco Canada6.5K views
Cisco connect montreal 2018 iot demo kinetic fr von Cisco Canada
Cisco connect montreal 2018   iot demo kinetic frCisco connect montreal 2018   iot demo kinetic fr
Cisco connect montreal 2018 iot demo kinetic fr
Cisco Canada1.3K views
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization von Cisco Canada
Cisco connect montreal 2018 - Network Slicing: Horizontal VirtualizationCisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco Canada1.4K views
Cisco connect montreal 2018 secure dc von Cisco Canada
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
Cisco Canada973 views
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns von Cisco Canada
Cisco connect montreal 2018   enterprise networks - say goodbye to vla nsCisco connect montreal 2018   enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco Canada1.5K views
Cisco connect montreal 2018 vision mondiale analyse locale von Cisco Canada
Cisco connect montreal 2018 vision mondiale analyse localeCisco connect montreal 2018 vision mondiale analyse locale
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco Canada682 views
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco von Cisco Canada
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec CiscoCisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco Canada673 views
Integration cisco et microsoft connect montreal 2018 von Cisco Canada
Integration cisco et microsoft connect montreal 2018Integration cisco et microsoft connect montreal 2018
Integration cisco et microsoft connect montreal 2018
Cisco Canada1K views
Cisco connect montreal 2018 compute v final von Cisco Canada
Cisco connect montreal 2018   compute v finalCisco connect montreal 2018   compute v final
Cisco connect montreal 2018 compute v final
Cisco Canada1.6K views
Cisco connect montreal 2018 saalvare md-program-xr-v2 von Cisco Canada
Cisco connect montreal 2018 saalvare md-program-xr-v2Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco Canada573 views
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th... von Cisco Canada
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Canada641 views
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net... von Cisco Canada
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Canada1.3K views
Cisco Connect Toronto 2018 an introduction to Cisco kinetic von Cisco Canada
Cisco Connect Toronto 2018   an introduction to Cisco kineticCisco Connect Toronto 2018   an introduction to Cisco kinetic
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Canada1.5K views
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in... von Cisco Canada
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Canada823 views
Cisco Connect Toronto 2018 DevNet Overview von Cisco Canada
Cisco Connect Toronto 2018  DevNet OverviewCisco Connect Toronto 2018  DevNet Overview
Cisco Connect Toronto 2018 DevNet Overview
Cisco Canada726 views
Cisco Connect Toronto 2018 DNA assurance von Cisco Canada
Cisco Connect Toronto 2018  DNA assuranceCisco Connect Toronto 2018  DNA assurance
Cisco Connect Toronto 2018 DNA assurance
Cisco Canada839 views
Cisco Connect Toronto 2018 network-slicing von Cisco Canada
Cisco Connect Toronto 2018   network-slicingCisco Connect Toronto 2018   network-slicing
Cisco Connect Toronto 2018 network-slicing
Cisco Canada2.1K views
Cisco Connect Toronto 2018 the intelligent network with cisco meraki von Cisco Canada
Cisco Connect Toronto 2018   the intelligent network with cisco merakiCisco Connect Toronto 2018   the intelligent network with cisco meraki
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Canada955 views
Cisco Connect Toronto 2018 sixty to zero von Cisco Canada
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
Cisco Canada549 views
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t... von Cisco Canada
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Canada1.9K views

Último

NTGapps NTG LowCode Platform von
NTGapps NTG LowCode Platform NTGapps NTG LowCode Platform
NTGapps NTG LowCode Platform Mustafa Kuğu
365 views30 Folien
Confidence in CloudStack - Aron Wagner, Nathan Gleason - Americ von
Confidence in CloudStack - Aron Wagner, Nathan Gleason - AmericConfidence in CloudStack - Aron Wagner, Nathan Gleason - Americ
Confidence in CloudStack - Aron Wagner, Nathan Gleason - AmericShapeBlue
88 views9 Folien
Why and How CloudStack at weSystems - Stephan Bienek - weSystems von
Why and How CloudStack at weSystems - Stephan Bienek - weSystemsWhy and How CloudStack at weSystems - Stephan Bienek - weSystems
Why and How CloudStack at weSystems - Stephan Bienek - weSystemsShapeBlue
197 views13 Folien
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f... von
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
160 views29 Folien
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue von
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueShapeBlue
179 views7 Folien
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda... von
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...ShapeBlue
120 views13 Folien

Último(20)

NTGapps NTG LowCode Platform von Mustafa Kuğu
NTGapps NTG LowCode Platform NTGapps NTG LowCode Platform
NTGapps NTG LowCode Platform
Mustafa Kuğu365 views
Confidence in CloudStack - Aron Wagner, Nathan Gleason - Americ von ShapeBlue
Confidence in CloudStack - Aron Wagner, Nathan Gleason - AmericConfidence in CloudStack - Aron Wagner, Nathan Gleason - Americ
Confidence in CloudStack - Aron Wagner, Nathan Gleason - Americ
ShapeBlue88 views
Why and How CloudStack at weSystems - Stephan Bienek - weSystems von ShapeBlue
Why and How CloudStack at weSystems - Stephan Bienek - weSystemsWhy and How CloudStack at weSystems - Stephan Bienek - weSystems
Why and How CloudStack at weSystems - Stephan Bienek - weSystems
ShapeBlue197 views
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f... von TrustArc
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc160 views
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue von ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
ShapeBlue179 views
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda... von ShapeBlue
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
Hypervisor Agnostic DRS in CloudStack - Brief overview & demo - Vishesh Jinda...
ShapeBlue120 views
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or... von ShapeBlue
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...
ShapeBlue158 views
CloudStack Managed User Data and Demo - Harikrishna Patnala - ShapeBlue von ShapeBlue
CloudStack Managed User Data and Demo - Harikrishna Patnala - ShapeBlueCloudStack Managed User Data and Demo - Harikrishna Patnala - ShapeBlue
CloudStack Managed User Data and Demo - Harikrishna Patnala - ShapeBlue
ShapeBlue94 views
Igniting Next Level Productivity with AI-Infused Data Integration Workflows von Safe Software
Igniting Next Level Productivity with AI-Infused Data Integration Workflows Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Igniting Next Level Productivity with AI-Infused Data Integration Workflows
Safe Software385 views
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ... von ShapeBlue
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
ShapeBlue85 views
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P... von ShapeBlue
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
ShapeBlue154 views
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue von ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
2FA and OAuth2 in CloudStack - Andrija Panić - ShapeBlue
ShapeBlue103 views
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ... von ShapeBlue
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...
Backroll, News and Demo - Pierre Charton, Matthias Dhellin, Ousmane Diarra - ...
ShapeBlue146 views
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha... von ShapeBlue
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
Mitigating Common CloudStack Instance Deployment Failures - Jithin Raju - Sha...
ShapeBlue138 views
"Surviving highload with Node.js", Andrii Shumada von Fwdays
"Surviving highload with Node.js", Andrii Shumada "Surviving highload with Node.js", Andrii Shumada
"Surviving highload with Node.js", Andrii Shumada
Fwdays53 views
Data Integrity for Banking and Financial Services von Precisely
Data Integrity for Banking and Financial ServicesData Integrity for Banking and Financial Services
Data Integrity for Banking and Financial Services
Precisely78 views
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O... von ShapeBlue
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...
Declarative Kubernetes Cluster Deployment with Cloudstack and Cluster API - O...
ShapeBlue88 views
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T von ShapeBlue
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&TCloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T
CloudStack and GitOps at Enterprise Scale - Alex Dometrius, Rene Glover - AT&T
ShapeBlue112 views
DRBD Deep Dive - Philipp Reisner - LINBIT von ShapeBlue
DRBD Deep Dive - Philipp Reisner - LINBITDRBD Deep Dive - Philipp Reisner - LINBIT
DRBD Deep Dive - Philipp Reisner - LINBIT
ShapeBlue140 views
Business Analyst Series 2023 - Week 4 Session 7 von DianaGray10
Business Analyst Series 2023 -  Week 4 Session 7Business Analyst Series 2023 -  Week 4 Session 7
Business Analyst Series 2023 - Week 4 Session 7
DianaGray10126 views

Cisco connect montreal 2018 collaboration les services webex hybrides

  • 1. Cisco Connect Montreal Canada • November 20th 2018 Global vision. Local knowledge.
  • 2. Yves Daigneault - TSA Jeff Corcoran - TSA 20 novembre 2018 Meeting you wherever you are along your journey to the cloud Webex Hybrid Services
  • 3. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public Agenda • Cloud Collaboration • Hybrid Cloud Collaboration • Hybrid Directory Service • Hybrid Calendar Service • Hybrid Call Service • Hybrid Message Service • Cisco Webex Edge Service • Webex Teams Cloud Security and Hybrid Data Security
  • 5. Common Management Messaging Meeting Calling Application Integration APIs Device registrations Cisco Webex Hybrid Services Cloud + On-Premises Cisco Webex – The Platform BRKCOL-2607 5
  • 6. Anywhere, Any Device, Any Time Cisco Webex Cisco Webex Room DeviceCisco Webex Desk Phone Cisco Video Endpoints 3rd Party endpoints & service integrations Webex Teams Mobile App Webex Teams Desktop App WebEx App Cisco Webex – Meetings BRKCOL-2607 6
  • 7. NEW Spark Board 70 Room 70D G2Room 70S G2Room 55DRoom 55 NEW NEW NEW Room Kit PlusRoom KitRoom Kit Mini NEW NEW Room Kit Pro NEW NEW NEW NEW Soon Board 55 Board 70 Board 85 2019 DX80 Share Soon
  • 9. Creating unique value by connecting on-premises and cloud services Hybrid Calendar Service Cisco Webex platform Messaging | Meetings | Calling Existing Services Hybrid Call Service • Call Service Aware • Call Service Connect Hybrid Directory Service Hybrid Media Service Hybrid Data Security Cisco Webex Hybrid Services: AND, not OR 9BRKCOL-2607 Hybrid Message Service
  • 10. Expressway Windows *Includes Business Edition or HCS Webex Messenger Integrating On-Premises and Cloud 10 Directory Calendar Media KMS Microsoft AD Exchange Media Node Data Security Call Message IM&PCisco UCM* ? Platform BRKCOL-2607
  • 11. SIPTrunk XMPP Expressway C DMZ Collaboration Cloud Infrastructure Collaboration Cloud Services Media/TranscodingNotification/Alerts Messaging Interop Content Sharing Call Control RoomsIdentity/SSO File Storage Metadata Storage Metrics & Reporting Billing & Provisioning Management Calendar Future DC Serviceability Connector Management Connector Common Connector Framework Message Connector Calendar Connector Management Connector Directory Connector Call Connector FutureService Connector BRKCOL-2607 11
  • 12. Webex Admin Control Hub 12Presentation ID
  • 13. Hybrid Service Expressway-C Registration Complete BRKCOL-2607 13
  • 14. Hybrid Directory Service and SSO Hybrid Directory Service and SSO
  • 15. Admin Portal DirSync User Configuration BRKCOL-2607 15
  • 16. Provisioning via Directory Connector • Infrastructure for premises directory synchronization to the Identity cloud services • Directory connector integrates with AD to retrieve user information to sync with the identity service, and specifies the Active Directory synchronization agreement and attribute mappings • Customer installs Directory Connector in its network on a Windows Domain server (Windows Server 2003, 2008 R2, 2012, 2012 R2, 2016) with administrative user privilege • Directory Connector supports Single Forest, Multi-Domain and Multi-Forest, Multi-Domain Directory Connector Active Directory Cisco Webex Cloud Identity/SSO HTTPS BRKCOL-2607 16
  • 19. Calendaring Scheduling Integration with @webex or @meet @webex will backfill the users personal room information into the calendar invite (seen here) @meet will utilize the Cisco Webex Teams space information when populating a calendar invite, or create a new space (next page). BRKCOL-2607 19
  • 20. Calendaring Scheduling Integration with @webex 20Presentation ID
  • 21. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Calendaring Scheduling Integration with @meet 21Presentation ID
  • 22. Calendaring Scheduling Integration with @meet 22Presentation ID
  • 23. 23 OBTP User Meeting Scheduling Experience Cloud Registered Room Device Bookable Resource BRKCOL-2607
  • 24. 24 OBTP User Meeting Join Experience Before Meeting During Meeting Cloud Registered Room Device BRKCOL-2607
  • 25. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Set Out-of-Office from Outlook 25Presentation ID
  • 26. Edge Exchange / Office 365 Calendar WebEx Messenger 26 Calendar Service Hybrid Exchange Calendaring BRKCOL-2607
  • 27. Edge Calendar WebEx Messenger 27 Calendar Service Hybrid Exchange Calendaring BRKCOL-2607 Cloud Calendar Connector uses the same system architecture; however, the connector resides in the Cisco Collaboration Cloud (i.e. requires no premises infrastructure)
  • 29. Webex Hybrid Call Service at a Glance Call Service Aware Provides the Webex Teams application an awareness of calls placed between the on premise devices of two Aware enabled users. This means a one-to-one space will be created for the users and they will be offered the ability to share their screen with one click. Call Service Connect Provides Webex Teams users the ability to make and receive calls on their Webex Room Devices or Webex Teams application by leveraging the on premise infrastructure’s dialing capabilities 29
  • 30. Call Connect for Webex Teams 30Presentation ID Calling my mobile from Teams Calling my Cisco phone number from my mobile
  • 31. Hybrid Call Service for Cisco Webex Devices Architecture 31Presentation ID
  • 32. Edge WebEx Messenger 32 Call Service Integration for CUCM BRKCOL-2607 *Includes Business Edition or HCS Call Cisco UCM *
  • 33. Call Service Aware/Connect Architecture Expressway-E Expressway-C Expressway-C (Connectors) Communications Manager SIP AXL/SOAP/RIS CTIQBE REST/HTTPS *.ciscospark.com example.com
  • 35. Expressway Hybrid Message Service Integration 35 Message IM&P ? BRKCOL-2607
  • 36. SIPTrunk XMPP Expressway C DMZ Collaboration Cloud Infrastructure Collaboration Cloud Services Media/TranscodingNotification/Alerts Content Sharing Call Control RoomsIdentity/SSO File Storage Metadata Storage Metrics & Reporting Billing & Provisioning Management Calendar Future Messaging Interop Serviceability Connector FutureService Connector Management Connector Common Connector Framework Message Connector Calendar Connector Message Service Directory Connector DC Call Connector RESTful https BRKCOL-2607 36 AXL / XMPP
  • 37. Cisco Webex Teams / Jabber Interoperability - Presence 37 • When user is running Jabber, the user’s Presence on Jabber shall be based on existing Jabber logic • Available / Busy / Presenting / In meeting, etc. • When user is not running Jabber, the user’s Presence on Jabber shall be based on WebEx Teams activity • “Available On WebEx Teams” when the user has been active on WebEx Teams within the last 24 hours • “Offline” when the user has not been active on WebEx Teams for over 24 hours Note: Webex Teams Presence is not impacted due to user’s Jabber activity BRKCOL-2607
  • 38. Cisco Webex Teams / Jabber Interoperability - Message 38 • Cisco Webex Teams Interop will allow 1:1 message only between Jabber and Webex Teams users. • Users must be configured and enabled on both IM&P and Webex Teams • Message Connector will map Jabber and the Webex Teams ID using a common email address • Notifications include is Typing, Message Read, Deletes, or Missed • File transfer is not supported. o When a Webex Teams user posts a file, Cisco Jabber will receive a notification to get access to the file in the Webex Teams web client BRKCOL-2607
  • 40. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Cisco Webex Edge service Webex Edge service Enhanced Quality Consistent Experience No Change in User Behavior Cost Savings Purpose-built for collaboration and real-time media Customer Premises Leverage existing investments Reshaping the edge to maximize the power of the Webex cloud Version 1.1
  • 41. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Capabilities of Webex Edge Intelligent Audio + Direct Connection + Industry-Leading Media Experiences Audio Connect Video Mesh Webex Edge New New Version 1.1
  • 42. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Multiple deployment options 1 3 2 Webex Edge Connect provides peering connection to Webex datacenters for media. • Can be used with Webex Edge Audio. • Can be used with Video Mesh. • Not required for either service to operate but recommended for Edge Audio. Webex Edge Audio provides dial in and call back for Webex meeting audio to customer premises. • Does not require Edge Connect, but is strongly recommended to be used with Edge Audio. • Does not require Video Mesh, functions independently from this service. Webex Edge Video Mesh provides on premises meeting resources for devices and Teams app. • Does not require Edge Connect, but can utilize the direct peering link. • Does not require Edge Audio, functions independently from this service. Version 1.1 Audio Connect Video Mesh Webex Edge New New
  • 44. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Webex Edge Audio Intelligent audio routing •Intelligent audio routing: integrating Webex with Unified CM • Creates end-to-end VoIP path for Unified CM registered devices (callback and dial-in) • Uses company’s own PSTN for any other device (callback savings) • No SIP trunks or peering arrangements required •Geo-country code configurable •Included in Collaboration Flex Plan – no extra charge. No port charges on Expressway •Supports Webex Meetings, Events, Training •Enhanced audio quality when G.722 is enabled No user training, no change in user behavior, easy for IT IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling Meeting Version 1.1
  • 45. Unified CM support only • 10.5 or later Cisco UCM registered IP phones • Supporting G.711 or G.722 Expressway support only • X8.10 or later • Can use existing Expressway C/E deployment • Audio scale dependent on Expressway deployment and services enabled. Webex site • WBS 33.x or higher • Included in Flex, A-WBX and A-SPK SKU need the Webex Edge Audio package • Not available on CCA-SP, CCA-ENT or TSP sites. • Requires migration to Webex Audio Site Requires a signed certification from a Cisco trusted Certificate Authority (CA) Cisco Webex Edge Audio Architecture requirements IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling Meetin g Version 1.1
  • 46. Webex Edge Audio Configuration Steps: 1. Obtain dial-in numbers and Lua script from Site Administration 2. Configure DNS SRV records (5062) 3. Configure Unified CM 4. Set Up Expressway-C 5. Set Up Expressway-E 5. Open Firewall ports 6. Apply Signed Certificate From Trusted Certificate Authority 7. Apply Edge Audio Callback Settings Cisco Webex Edge Audio Architecture configuration IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling Meetin g Version 1.1
  • 47. 1. Endpoint dials Webex Audio access number. 2. Cisco UCM matches the number and routes as +E.164 through SIP trunk to Expressway- C. 3. LUA script on SIP trunk to Expressway-C applies transformations required for correct routing to Webex 4. Expressway-C sends request to Expressway-E. 5. Expressway-E routes call to the Webex cloud. 6. Meeting resources are setup. Cisco Webex Edge Audio Dial in Signaling Call Flow IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling Meetin g Dials Webex Access Number SIP Trunk 1 2 3 4 5 Version 1.1
  • 48. 1. The IP phone sends media to Expressway-C 2. The Expressway-C sends media to Expressway-E via the traversal zone 3. The Expressway-E sends media to the Webex cloud. 4. IP phone’s audio is mixed into the meeting and it hears the other participants. Cisco Webex Edge Audio Dial in Media Call Flow IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling 1 2 3 4 Meetin g Version 1.1
  • 49. Webex Edge Audio Callback Set Up Steps: 1. Apply Webex Edge Audio Callback Settings • Define country callback parameters in Site Admin • Ensure proper SRV record configuration for Expressway • Ensure connectivity checks are successful. • Cisco UCM routes the +E.164 audio call to the IP phones or local PSTN Cisco Webex Edge Audio Architecture configuration IP Phone Cisco Unified CM Customer Premises Media Path Z Expressway C/E Webex Edge Audio Signaling Meetin g PSTN Version 1.1
  • 50. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Single Country Call Back – Multiple Expressways Customer Premises Z Webex Edge Audio Meetin g USA Intern et • Expressway-E is configured in Webex for callback • +1 is defined in Webex callback settings • SRV records along with DNS configuration will determine cluster routing or load balancing Site 1Cisco Unified CM DNS SRV: _sips._tcp.edge-amer.example.com DNS SRV Records _sips._tcp.edge-amer.example.com. 60 IN SRV 0 5 5062 exp-amer1.example.com. _sips._tcp.edge-amer.example.com. 60 IN SRV 0 5 5062 exp-amer2.example.com.Z Webex Edge Audio Site 2 Cisco Unified CM Call back made to On net IP phone Laptop Client exp-amer1.example.com exp-amer2.example.com WAN Signaling Media Path Version 1.1
  • 52. • CCA- SP, CCA-ENT, TSP customers can not use their present configuration with Edge Audio. • If a call fails, user needs to dial into the call or callback. • Dial-in through customer owned E.164 or VOIP numbers is not supported. • Reroute call back to Webex PSTN resources if rejected by UCM is not available • Unable to define Class of Service for call back • OPUS codec not supported Webex Audio Caveats Initial release Version 1.1
  • 54. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Webex Edge Connect Brings the power of the Webex backbone directly to your data center Webex Edge Connect • A direct peering at Equinix data centers • Bypasses the Internet by providing a direct connection1 to the Webex data center • All Webex media traffic traverses the dedicated link providing end-to-end QoS. (VoIP, video, content sharing) • When used with Video Mesh provides a more secure end-to-end experience 1 via a peering agreement with Equinix Webex Edge Version 1.1
  • 55. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Customer Requirements 1. A cage and router in place at Equinix 2. A paid connection to the Equinix Cloud Exchange 3. Knowledge of BGP Routing 4. Public BGP Autonomous System Number 5. Public provider independent IP block • No RFC1918 addressing (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) • Customer may rent a /29 IP block from Equinix 6. Paid service to Cisco Webex Customer Premises Equinix Cloud Exchange (ECX) Cisco Webex Version 1.1
  • 56. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Connectivity - Components Layer 2 (802.1q) Equinix Cloud Exchange Layer 3 (BGP) Layer 1 (1G/10G) AS13445 Customer Network 1. Layer 1 – Physical Connectivity 2. Layer 2 – Ethernet Connectivity 3. Layer 3 – IP connectivity Network Details 1. Customer orders physical circuit to ECX fabric 2. Customer provisions virtual circuit to Cisco WebEx using Equinix self-service portal 3. Customer completes WebEx BGP network questionnaire 4. Cisco enables BGP connection to the Customer to establish connectivity Equinix responsibility: ü Physical link provisioning (cross connects) ü Virtual circuit monitoring reports & support Roles and Responsibilities Cisco responsibility: ü Peering provisioning and support Version 1.1
  • 57. • A customer sets up dual connections to Equinix for redundancy • Cisco Webex has redundant connection to Equinix at all colocations across the globe • BGP routing is used to route traffic across the peering connection. • Customers that have a global presence can choose which regions to peer. • Customer’s Internet connection is used as fallback Architecture Equinix PRI SEC Customer Premises PRI SEC ORD10-WXBB-CRT01 Cisco Webex ORD10-WXBB-CRT02 ORD10-WXBB-PE02ORD10-WXBB-PE01 Intern et Version 1.1
  • 58. Z • Media flows via Equinix peering connection. • Webex Meetings app signaling and media use the peering connection • Signaling for cloud registered devices and Webex Teams uses the public Internet • Third party services accessed via the Internet Signaling and Media Flow Customer Signaling only Internet Media Path Signaling Webex AS13445 Webex IP blocks: https://collaborationhel p.cisco.com/article/en- us/WBX000028782 Version 1.1
  • 60. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Webex Edge Video Mesh On-premises video quality and bandwidth savings Webex Edge Video Mesh • Automatic overflow if local capacity is full / unavailable • Software extends cloud to the premises - media stays local for on-premises attendees • Cloud simple: managed by & registered to Webex cloud local media kept local Video Mesh Node local media kept local Video Mesh Node local media kept local Video Mesh Node Version 1.1
  • 61. • Video Mesh is part of the Webex Edge solution • Video Mesh functionality is the same, handling the Main Video, Speaker’s Audio and Content being shared by the video devices in the meeting that can utilize Video Mesh • Video Mesh communicates directly to Webex cloud and terminates the media for cloud registered device and SIP video endpoints for dialing into Webex meetings. • Webex Teams, Webex registered devices and Cisco UCM registered SIP video endpoints use Video Mesh. Webex Meeting app or Webex Teams browser does not use Video Mesh. Cisco Webex Edge Video Mesh Architecture SIP Video Endpoint Cisco Unified CM Customer Premises Media Path ZExpressway C/E Webex Edge Audio Signaling Video Mesh Cloud Registered Video Endpoint Meeting Version 1.1 SIP Trunk © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential • Video Mesh is part of the Webex Edge solution • Video Mesh functionality is the same, handling the Main Video, Speaker’s Audio and Content being shared by the video devices in the meeting that can utilize Video Mesh • Video Mesh communicates directly to Webex cloud and terminates the media for cloud registered device and SIP video endpoints for dialing into Webex meetings. • Webex Teams, Webex registered devices and Cisco UCM registered SIP video endpoints use Video Mesh. Webex Meeting app or Webex Teams browser does not use Video Mesh. Cisco Webex Edge Video Mesh Architecture SIP Video Endpoint Cisco Unified CM Customer Premises Media Path ZExpressway C/E Webex Edge Audio Signaling Video Mesh Cloud Registered Video Endpoint Meeting Version 1.1 SIP Trunk
  • 62. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS CASCADE CASCADE Architecture MEDIA NODE MEDIA NODE 00:50 MEDIA NODE • Cloud and Premises nodes • Hub and Spoke design • Cascades initiated from premise to cloud • Inside à Cloud only
  • 63. Uses the Node 1. Any Webex registered device Ø SX, MX, RK series, Webex Board 2. Webex Teams app 3. CUCM registered devices Ø Calling a Webex scheduled, Webex PMR, or space meeting including the IX. 4. VCS/Exp registered devices Ø Calling a Webex scheduled Webex PMR, or space meeting Ø SIP or H.323 (requires Interworking) 5. Webex dial back to Webex registered endpoints Can NOT Use the Node 1. Webex Teams browser client Ø web.ciscospark.com 2. Webex Call registered phones Ø 88xx and 78xx (Spark Call) IP Phones 3. Webex dialing back to SIP registered endpoints 4. Webex Meetings app What devices and scenario can the media node be used?
  • 64. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Capacity on Multiparty Media 410v and Cisco Meeting Server 1000 Server (version) Max simultaneous calls per server Cisco Spark only (720p | 1080p) Standard based SIP endpoints and Cisco Spark app/devices (720p | 1080p) MM410v (Full version) 100 | 75 65 | 48 CMS 1000 (Full version) 100 | 75 80 | 60 Demo version 10 | 5 10 | 5 Note: If all the meetings hosted on a given Hybrid Media Node have only Cisco Spark apps and devices, then the server can scale up to 100 participants at 720p. If all meetings have a mix of Cisco Spark and SIP participants, then the scale goes up to 80 participants for the CMS 1000 server and 65 participants for the MM410v server.
  • 65. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Webex Video Mesh Requirements Component purpose Minimum supported version On-Premises call control Cisco Unified Communications Manager, Release 10.5(2) SU5 or later Cisco Expressway-C or E, Release X8.9.2 or later Meeting infrastructure Cisco Webex Meetings WBS31.11.1, WBS31.12.1, WBS31.20, or WBS32.0.2 and above, enabled with video platform version 2.0
  • 66. Webex Edge Audio, Video Mesh and Connect
  • 67. • Video Mesh and Edge Audio work independently but are part of an overall solution when connecting to a Webex meeting. • IP phones dialing in or call back to the Webex meeting use +E.164 numbers and utilize the Expressway to connect to the Webex meeting. (Webex Edge Audio) • Cisco UCM registered SIP video endpoints, Webex registered devices and Webex Teams app dial SIP URIs to the Webex meeting and use Video Mesh for local media processing. • Webex Meeting app goes directly to the Webex Cloud. Cisco Webex Edge Audio + Video Mesh Signaling and Media Version 1.1 SIP Video Endpoint Cisco Unified CM Customer Premises Media Path ZExpressway C/E Webex Edge Audio Signaling Video Mesh Cloud Registered Video Endpoint IP Phone SIP Trunk Meetin g SIP Trunk
  • 68. • Webex Connect is a peering connection to Cisco Webex. • Both Video Mesh and Webex Edge Audio can use the Webex Edge Connect peering service to connect media to the Webex Meeting, but it is not a requirement. • Webex Teams signaling goes via the Internet link and all media goes via Webex Connect. • Webex Meetings app sends signaling and media via Webex Connect. • If the peering connection is not available all signaling and media traffic will flow via the Internet. Cisco Webex Edge Audio + Video Mesh + Connect Architecture SIP Video Endpoint IP Phone Laptop Client Cisco Unified CM Customer Premises Media Path ZExpresswa y Webex Edge Video Mesh Signaling Connect InternetLaptop Client Meeting Version 1.1
  • 69. Webex Teams Cloud Security and Hybrid Data Security
  • 70. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Security mechanisms • Realms of separation • Identity Obfuscation • SSO authentication using SAML based IdP • OAuth access and refresh token based authorization • Key Management Service for managing encryption keys • End to end encryption of content (one key per space) • Data encrypted in transit • Data encrypted at rest • Application layer database content encryption • Hash key based secure index and search (one key per space) • Secure compliance reporting service based on hashed index Security Option for On-Premise Control Webex Teams Security
  • 71. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Secure Data Center Content Server Key Mgmt Service eDiscovery ServiceIndexing Service Hybrid Data Security Hybrid Data Security = On-Premises Key Management Service Indexing Service eDiscovery Service Requires Pro Pack Add-onHybrid Data Security (HDS)
  • 72. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Secure Data Center Content Server Key Mgmt Server The Hybrid Key Management Service performs the same functions as the cloud based Key Management Service Customer now owns and manages all of the keys for messages and content BUT Key Management Service Key Mgmt Service Requires Pro Pack Add-onHDS – Key Management
  • 73. © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public#CLUS Secure Data Center Content Server Hybrid Data Security Hybrid Data Security Multiple servers can be provisioned for Scalability & Load Sharing Hybrid Data Security instances are managed and upgraded from the cloud Customers can access usage information for the HDS services via the Cisco Webex Control Hub Requires Pro Pack Add-on Hybrid Data Security Key Mgmt Server HDS - Scalability
  • 74. HDS Install Prerequisites HDS Deployment Guide https://www.cisco.com/go/hybrid-data-security X.509 Certificate, Intermediates and Private Key PKI is used for KMS to KMS federation (Public Key Infrastructure) Common Name signed by member of Mozzila Trusted Root Store No SHA1 signatures, PKCS12 format 2 ESXi Virtualized Hosts: Min 2 to support upgrades, 3 recommended, 5 max Minimum 4 vCPUs, 8-GB main memory, 50-GB local hard disk space per server 1 Microsoft SQL or Postgres 9.6.1 Database Instance (Key datastore) 8 vCPU, 16 GB RAM, 2 TB Disk. User created with createuser. Assigned GRANT ALL PRIVILEGES ON database. 1 Syslog Host Hostname and port required to centralize syslog output from HDS instances and management containers A secure backup The HDS system requires organization administrators to securely backup : 1) A configuration ISO file generated during the install process 2) The MS SQL/ Postgres database. Failure to maintain backups will result in loss of customer data. See Standby Data Center for Disaster Recovery section of the HDS Deployment Guide Network Outbound HTTPS on TCP port 443 from HDS host Bi-directional WSS on TCP port 443 from HDS host TCP connectivity from HDS host to Postgres database host, syslog host and statsd host HTTPS proxies not supported today 75© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
  • 75. • Hybrid services connect premises resources to cloud • Each hybrid service can be deployed independently • Benefits • Leverage premises investments • Enhance user experience • Increase security • Ease management • Transition to cloud at desired pace Key Points
  • 76. #CLUS