Extending video communications securely beyond the enterprise
Figure 1. Cisco TelePresence Video Communication Server Expressway Firewall Traversal (simple deployment)
The Cisco TelePresence® Video Communication Server Expressway (Cisco VCS Expressway) deployed with the Cisco TelePresence Video Communication Server (Cisco VCS) enables smooth video communications easily and securely outside the enterprise.
The Cisco VCS Expressway enables business-to-business video collaboration, improves the productivity of remote and home-based workers, and enables service providers to provide video communications to customers. The application performs securely through standards-based and secure firewall traversal for all Session Initiation Protocol (SIP) and H.323 devices (Figures 1 and 2). As a result, organizations benefit from increased employee productivity and enhanced communication with partners and customers.
The Cisco VCS Expressway uses an intelligent framework that allows endpoints behind firewalls to discover paths through which they can pass media, verify peer-to-peer connectivity through each of these paths, and then select the optimum media connection path, eliminating the need to reconfigure enterprise firewalls.
Administrators have a choice of implementing the Cisco VCS Expressway either as an appliance or as a virtualized application on VMware or similar virtual environments, with additional support for Cisco Unified Computing System™ (Cisco UCS™) platforms.
The Cisco VCS Expressway is built for high reliability and scalability, supporting multivendor firewalls, and it can traverse any number of firewalls regardless of SIP or H.323 protocol.
• Advanced firewall traversal: The Cisco VCS Expressway traverses any number of firewalls, making it easy for enterprises to collaborate more closely with external partners and suppliers.
• Optimal media routing: The Cisco VCS Expressway offers Simple Traversal of User Datagram Protocol Through Network Address Translation (STUN)-compliant firewall traversal, which provides endpoints with an intelligent framework to determine the best path for media connectivity.
• Increased competitiveness: The Cisco VCS Expressway helps enterprises become more competitive through real-time video communications across geographically dispersed teams.
• Improved productivity: The Cisco VCS Expressway empowers remote and home-based workers to collaborate more effectively with colleagues while helping cut travel costs.
• Robust security: The Cisco VCS Expressway uses standards-based device authentication for easier control over the network and safeguards external video communications.
• Flexibility: Administrators can implement the Cisco VCS Expressway either as an appliance or as a virtualized application to meet the needs of their organizations.
Features of the Cisco VCS Expressway follow:
• Firewall traversal services for SIP and H.460.18/19: The Cisco VCS Expressway offers all the functions of Cisco VCS Control. However, its main feature is that it acts as a firewall traversal server for other Cisco networks and any traversal-enabled endpoints that are registered directly to it. The Cisco VCS Expressway uses SIP or H.460.18/19 for firewall traversal of signaling and media across a range of ports.
• Registration of traversal-enabled endpoints: The Cisco VCS Expressway can register traversal-enabled endpoints directly for firewall traversal. You can configure the endpoints with a range of firewall traversal preferences such as protocols, ports, registration attempts, and keepalive intervals.
• Traversal Using Relays for NAT (TURN) relay services:
– The Cisco VCS Expressway provides TURN relay services to Interactive Connectivity Establishment (ICE)-enabled endpoints to allocate relays for the media components of the call. The endpoints perform connectivity checks through ICE to determine how they will communicate.
– For communications between the VCS and external Microsoft Office Communication Server (OCS) and Microsoft Lync clients that are registered through a Microsoft Edge Server, a Back to Back User Agent for Microsoft OCS and Microsoft Lync must be used.
• Call-routing services: The Cisco VCS Expressway supports a wide range of call-routing services, including alphanumeric Uniform Resource Identifier (URI) dialing. Additionally, the Cisco VCS Expressway can take advantage of the Domain Name System (DNS) Service Record (SRV) configuration to advertise availability to parties outside the local network, creating a rich peer-to-peer capability.
• Policy engine for processing calls: The Cisco VCS Expressway allows administrators to set system wide policies that determine how incoming or outgoing calls should be allowed, rejected, or redirected to a different destination based on criteria such as time of day, source or destination address, or more complex algorithms.
Optional features of Cisco VCS Expressway follow:
• Cisco TelePresence FindMe
• Cisco TelePresence Multiway
• Dual network interfaces
• Microsoft OCS 2007 Enhanced Interoperability option
Capacity of one Cisco VCS Expressway follows:
• Up to 2500 registrations
• Up to 500 nontraversal calls
• Up to 100 traversal calls
• Up to 1000 subzones
• Up to 1000 neighbor zones
Capacity of a cluster of six Cisco VCS Expressways follows:
• Up to 10,000 registrations
• Up to 2,000 nontraversal calls
• Up to 400 traversal calls
Table 1 lists the features and benefits of Cisco VCS Expressway.
Table 1. Features and Benefits
• The web interface supports Internet Explorer 7, 8, and 9; Firefox 3 and later; and Chrome.
Supported telepresence endpoints
• Cisco VCS Expressway is compatible with any standards-compliant H.323 or SIP videoconferencing or telepresence device. Provisioning and configuration are supported only for Cisco TelePresence endpoints.
• Support for industry standards such as HTTP and Secure HTTP (HTTPS), XML, Simple Network Management Protocol (SNMP v1, v2, and v3), Secure Copy Protocol (SCP) and Secure Shell (SSH) Protocol
• Embedded setup wizard for initial configuration
• Integration with Cisco TelePresence Management Server (TMS) Version 12.5 or later
• Support for call logging and diagnostics
Architecture (Cisco VCS Expressway Appliance)
• Secure appliance-based architecture
• Flash memory and hard drive
• Cisco TelePresence Expressway technology
• STUN discovery and STUN relay services
• Firewall traversal STUN-compliant
• H.460.18 client-proxy support
• Support for H.460.19 multiplexed media
• SIP support
Resilience and reliability
• Ability to deploy Cisco VCS Expressway in a redundant (six) cluster
• Ability to share licenses across a cluster
• Ability for registrations to survive system restart
• Ability to replicate configuration for clusters
• Ability for the Cisco VCS Expressway process to recycle within seconds
• Support for Cisco VCS Expressway H.225 Alternate Gatekeeper
Session control and registrations
• Support for manual registration of H.323 and SIP endpoints
• Support for H.225/Q.931, H.245 call-control routed mode, and non-call routed mode
• Support for H.323-SIP Interworking Encryption
• Support for H.323-SIP Interworking DuoVideo
• Support for registration of H.323 ID and E.164 aliases and services
• Support for Unicode (UTF-8) registration for global implementation
• Support for URI dialing
• Support for direct call signaling among neighbored Cisco VCSs, border controllers, and gatekeepers
• Support for call policy management (RFC 3880),including call policy and user policy (Cisco TelePresence FindMe)
• Support for conference hunting for multipoint-control-unit (MCU) cluster
• Support for call routed mode
• Support for call loop detection
Zone control and bandwidth management
• Support for remote zone monitoring
• Support for remote zone redundancy
• Support for up to 200 neighbor zones (including Cisco VCSs, border controllers, gatekeepers, and SIP proxies)
• Support for subzone area definition for bandwidth management
• Support for flexible zone configuration with named zones and default zone
• Support for forwarding of requests to neighbor zones
• Support for registration control (open, specifically allow, and specifically deny)
• Support for interzone bandwidth management: Definable call by call
• Maximum bandwidth per call
• Maximum aggregate bandwidth for all neighboring zones
• Support for intrazone bandwidth management: Definable call by call
• Maximum bandwidth per call
• Maximum aggregate bandwidth
• Support for auto-down-speeding if call exceeds per-call maximum
• Support for gateway load balancing
• Support for automatic network failover
• Support for capacity warnings for users and administrators
(H x W x D)
• 1.72 x 16.8 x 18 in. (43.5 x 426 x 457.2 mm)
• 1-rack unit (1RU) rack-mount chassis
• Four 10/100/1000 BASE-TX Ethernet ports (RJ-45) (front)
• One RS-232 console port (RJ-45) (front)
• 17.6 lb (8 kg) (unpacked)
• Auto-sensing 250W (maximum) 580 BTU per hour power supply
• 90-264 VAC full range at 47-63 Hz
• Five 40-millimeter fans for system cooling
System control and indications
• One power LED
• One alarm LED
• One power on/off switch (rear)
• Four act/link/10/100/1000 LEDs on Ethernet ports
Table 3. Ordering Information for Cisco VCS Expressway
Compliance Model Number
Cisco TelePresence Video Communication Server Expressway
(VCS Expressway Appliance)
Comes with: Cisco TelePresence Video Communication Server, Expressway feature, Gateway Feature, 1800 TURN Relay Option, Device Provisioning Feature, Cables
Note: A minimum of 5 traversal licenses must be selected when ordering the VCS Expressway Appliance
Cisco TelePresence Video Communication Server Expressway
Comes with: Cisco TelePresence Video Communication Server, Expressway Feature, Gateway Feature, 1800 TURN Relay Option, Device Provisioning Feature, VCS-Dual Network Interface Feature
Note: A minimum of 5 traversal licenses must be selected when ordering the VCS Expressway Virtualized Application
Ordering Options for the Cisco VCS Expressway
5 Traversal Calls for Cisco VCS Expressway
10 Traversal Calls for Cisco VCS Expressway
20 Traversal Calls for Cisco VCS Expressway
50 Traversal Calls for Cisco VCS Expressway
Additional 10 Non-traversal calls for Cisco VCS Expressway
Additional 20 Non-traversal calls for Cisco VCS Expressway
Additional 50 Non-traversal calls for Cisco VCS Expressway
Additional 200 Non-traversal calls for Cisco VCS Expressway
Additional 300 Non-traversal calls for Cisco VCS Expressway
Enable Device Provisioning for Cisco VCS Control
VCS-Dual Network Interface for Cisco VCS Expressway
(VCS Expressway Appliance Only)
VCS FindMe Application for Cisco VCS Expressway
VCS Enhanced OCS Collaboration
Service and Support
Cisco offers a wide range of services programs to accelerate customer success. These innovative services programs are delivered through a unique combination of people, processes, tools, and partners, resulting in high levels of customer satisfaction. Cisco Services can help you protect your network investment, optimize network operations, and prepare your network for new applications to extend network intelligence and the power of your business. For more information about Cisco Services, visit Cisco Technical Support Services or Cisco TelePresence Services online
For More Information
For more information about the Cisco Video Communication Server Expressway, please visit http://www.cisco.com/go/telepresence or contact your local Cisco account representative or authorized Cisco partner. Product specifications are estimates and subject to change without notice.