- IP Communications Required by Cisco Unity Connection
- Preventing Toll Fraud
- Cisco Unity Connection- Restricted and Unrestricted Version
- Securing the Connection between Cisco Unity Connection, Cisco Unified Communications Manager, and IP Phones
- Securing Administration and Services Accounts
- FIPS Compliance in Cisco Unity Connection
- EnhancedSecurityMode in Cisco Unity Connection
- Passwords, PINs, and Authentication Rule Management
- Cisco Unity Connection Security Password
- Using SSL to Secure Client/Server Connections
- Securing User Messages
- Next Generation Security
IP Communications Required by Cisco Unity Connection
IP Communications Required by Cisco Unity Connection
Service Ports
Table 1 lists the TCP and UDP ports that are used for inbound connections to the Cisco Unity Connection server, and ports that are used internally by Unity Connection.
|
Ports and Protocols1 |
||||||
|---|---|---|---|---|---|---|
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
IP phones must be able to connect to this range of ports on the Unity Connection server for some phone client applications. |
||||||
|
Opened for port-status monitoring read-only connections. Monitoring must be configured in Connection Administration before any data can be seen on this port (Monitoring is off by default). |
||||||
|
TCP and UDP ports allocated by administrator for SIP traffic. |
Unity Connection SIP Control Traffic handled by conversation manager. |
|||||
|
Restricted to localhost only (no remote connections to this service are needed). |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these database ports. |
||||||
|
Client workstations must be able to connect to ports 143 and 993 for IMAP inbox access, and IMAP over SSL inbox access. |
||||||
|
Servers delivering SMTP to Unity Connection port 25, such as other servers in a UC Digital Network. |
||||||
|
Restricted to localhost only (no remote connections to this service are needed). |
||||||
|
Restricted to localhost only (no remote connections to this service are needed). |
||||||
|
VoIP devices (phones and gateways) must be able to send traffic to these UDP ports to deliver inbound audio streams. |
||||||
|
Restricted to localhost only (no remote connections to this service are needed). |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Heartbeat event traffic is not encrypted but is MAC secured. Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
If this service is enabled it allows administrative read/write database connections for off-box clients. For example, some of the ciscounitytools.com tools use this port. |
||||||
|
Firewall must be open for TCP 22 connections for remote CLI access and serving SFTP in a Unity Connection cluster. Administrative workstations must be able to connect to a Unity Connection server on this port. Servers in a Unity Connection cluster must be able to connect to each other on this port. |
||||||
|
Using ipsec is optional, and off by default. If the service is enabled, servers in a Unity Connection cluster must be able to connect to each other on this port. |
||||||
|
The cluster manager service is part of the Voice Operating System. Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Network time service is enabled to keep time synchronized between servers in a Unity Connection cluster. The publisher server can use either the operating system time on the publisher server or the time on a separate NTP server for time synchronization. Subscriber servers always use the publisher server for time synchronization. Servers in a Unity Connection cluster must be able to connect to each other on this port. |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
These database instances contain information for LDAP integrated users, and serviceability data. Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Performs back-end serviceability data exchanges 1090: AMC RMI Object Port 1099: AMC RMI Registry Port Servers in a Unity Connection cluster must be able to connect to each other on these ports. |
||||||
|
Both client and administrative workstations need to connect to these ports. Servers in a Unity Connection cluster must be able to connect to each other on these ports for communications that use HTTP-based interactions like REST.
|
||||||
|
Servers in HTTPS Networking must be able to connect to each other on these ports for communications. Unity Connection HTTPS Directory Feeder service uses these ports for directory synchronization.
|
||||||
|
Ephemeral port ranges, used by anything with a dynamically allocated client port. |
||||||
|
TCP: 7443 |
Open |
jetty/Unity Connection Jetty |
jetty |
Exchange 2010 and above, single inbox: Jabber and Web Inbox notifications
|
||
|
Exchange 2010 only, single inbox only: EWS notifications of changes to Unity Connection voice messages. |
||||||
|
Single inbox only: WebDAV notifications of changes to Unity Connection voice messages. |
||||||
|
Video server must be able to connect to Unity Connection on this port for communications. |
Outbound Connections Made by Unity Connection
Table 1-2 lists the TCP and UDP ports that Cisco Unity Connection uses to connect with other servers in the network.
Securing Transport Layer
Unity Connection uses Transport Layer Security(TLS) protocol and Secure Sockets Layer(SSL) protocol for signaling and client server communication. Unity Connection supports TLS 1.0, TLS 1.1 and TLS 1.2 for secure communication across various interfaces of Cisco Unity Connection. TLS 1.2 is the most secure and authenticated protocol for communication.
Depending upon the organization security policies and deployment capabilities, Unity Connection 12.0(1) and later allows you to configure the minimum TLS version. After configuring the minimum version of TLS, Unity Connection supports the minimum configured version and higher versions of TLS. For example, if you configure TLS 1.1 as a minimum version of TLS, Unity Connection uses TLS 1.1 and higher versions for communication and rejects the request for a TLS version that is lower than the configured value. By default, TLS 1.0 is configured.
Before configuring minimum TLS version, ensure that all the interfaces of Unity Connection must be secured and use configured minimum TLS version or higher version for communication. However, you can configure the minimum TLS version for inbound interfaces of Unity Connection.
Table 3 lists the supported interfaces for which you can configure the minimum TLS version on Unity Connection.
| Ports |
Executable/Service or Application |
Service Account |
Comments |
|---|---|---|---|
| 8443, 443, 8444 | tomcat/Cisco Tomcat | tomcat |
Both client and administrative workstations must connect to these ports. Servers in a Unity Connection cluster must be able to connect to each other on these ports for communications that use HTTP-based interactions like REST. |
| 7443 | jetty/Unity Connection Jetty | jetty |
Exchange 2010 and above, single inbox: Jabber and Web Inbox notifications |
| 993 | CuImapSvr/Unity Connection IMAP Server | cuimapsvr |
Client workstations must be able to connect to port 993 for IMAP over SSL inbox access. |
| 25 | CuSmtpSvr/Unity Connection SMTP Server | cusmtpsvr |
Servers delivering SMTP to Unity Connection port 25, such as other servers in a UC Digital Network. |
| 5061-5199 | CuCsMgr/Unity Connection Conversation Manager | cucsmgr |
Unity Connection SIP Control Traffic handled by conversation manager. SIP devices must be able to connect to these ports. |
| LDAP (outbound interface) |
CuMbxSync CuCsMgr tomcat |
cumbxsync cucsmgr tomcat |
Unity Connection uses port 636 when you select LDAPS for the protocol used to communicate with domain controllers. |
For more information on supported inbound interfaces of Cisco Unity Connection, see "Service Ports" section.
Configuring Minimum TLS Version
To configure the minimum TLS version in Cisco Unity Connection, execute the following CLI command:
In cluster, you must execute the CLI command on both publisher and subscriber.
In addition to this, you can execute the following CLI command to check the configured value of minimum TLS version on Unity Connection:
For detailed information on the CLI, see Command Line Interface Reference Guide for Cisco Unified Communications Solutions available at http://www.cisco.com/c/en/us/support/unified-communications/unified-communications-manager-callmanager/products-maintenance-guides-list.html.
![]() Caution | After configuring minimum TLS version, the Cisco Unity Connection server restart automatically. |

Feedback