Thursday, December 16, 2010

Introducing the Cisco Smart Business CCIE Security Training Institute in Gurgaon

Network Bulls
http://www.networkbulls.com/
Best Institute for CCNA CCNP CCSP CCIP CCIE Training in India
M-44, Old Dlf, Sector-14 Gurgaon, Haryana, India
Call: +91-9654672192

The core of the SBCS is the UC 500 Series for Small Business. This multiservice appliance incorporates routing, firewall,
VPN, IPS, PoE switchports, WAN and PSTN connectivity options, and wireless options. The SBCS incorporates CME
4.2 and CUE 3.1.1, with the features found on larger ISR hardware. The Catalyst 520 switch allows for expansion of the
system to support more endpoints than the UC500 core unit supports.
For more complex wireless deployments, the Cisco Mobility Express Solution with the Cisco 521 Wireless Express
Access Point and the Cisco 526 Wireless Express Mobility Controller provide scalable, manageable, and secure wireless
connectivity for both data and voice endpoints.
The SBCS supports a wide range of Cisco IP phones, including video and wireless capabilities. Specialized applications,
both from Cisco and third-party vendors, can integrate with the SBCS to further leverage the productivity gains offered
by unified communications.
The SBCS comes in two form factors: A desktop or wall-mount unit for installations of up to 16 users and a rack-mount
unit for 32-48-user deployments; the smaller units support ISDN BRI PSTN, FXO, and FXS connections, and the larger
units add support for Tl and El interfaces, both PRI and CAS.
© 2008 Cisco Systems Inc. All rights reserved. This publication is protected by copyright.
Please see page 147 for more details.
Telephony Features
The SBCS supports most of the features desired in a business phone system, including the following:
PBX mode or keyswitch mode
System features
Language
Date format
System message
• Network features
System speed dials
Voice VLAN
DHCP scope settings
IP addressing
SIP Trunk settings
Dial Plan settings
Extension length
Outgoing call handling
Incoming call handling
Voice-mail features
Voice-mail pilot numbers
Auto Attendant
Voice features
MOH
• Intercom
Paging
Hunt Group
Call Pickup
Caller ID Blocking
Call blocking
Call Park
Conferencing
Users
Name
Association with a device
Phone
MAC address
Extension number(s)
Permissions
Additional features are documented online.
Call Forward
Security Features
The SBCS supports the Cisco IOS firewall, Easy VPN Server and Remote, NAT, and 802. lx authentication.
Wireless Features
The smaller SBCS can be ordered with an integrated wireless AP, or external 521 Series wireless APs can be connected.
The larger SBCS models do not support internal APs. The standalone administrative capability of the Cisco Configuration
Assistant will support up to three connected APs. For support of up to 12 APs, the use of a Cisco 526 Wireless Express
Mobility Controller for every 6 APs is required. The SBCS systems provide full support for wireless security, including
WPA and WPA2, LEAP, PEAP, WEP, as well as voice VLANs with QoS.
Cisco Configuration Assistant
The CCA is a powerful and simple GUI tool for administering the UC500 Series platforms. This tool is used to deploy,
configure, and maintain the SBCS devices, allowing control of the following:
Switching
• Wireless
• Security
Telephony
Network services
The GUI tool provides a network map view, showing the devices discovered in the system, as well as a front-panel view
of the SBCS system, showing ports and their status. The CCA even allows drag-and-drop upgrades to IOS software,
phone firmware, and language files.
Internet connectivity
CCNA Voice Quick Reference
by Michael Valentine
Implementing Smart Business Communications System Voice Features
The SBCS is remarkably simple to use; in fact, it ships with a default configuration that automatically assigns extensions
to phones as they are plugged in, enables the device to place and receive calls on the PSTN interface, and sets up default
© 2008 Cisco Systems Inc. All rights reserved. This publication is protected by copyright.
Please see page 147 for more details.
configurations for the firewall, wireless (if applicable), NAT, VLANs, and telephony features. This is as close to a plugand-
play phone system as it gets.
FIGURE 26
.) When you run the software, it will ask for the IP address of the system to connect to; the default configuration
The CCA Device
Setup Wizard—
Step 1
1.
device you want to configure. (Only devices in the UC500 Series will be available.) Click Next.
Select a Device: With the CCA open, choose Setup, Device Setup Wizard. From the drop-down menu, choose the
2.
Click Next.
3.
Power Up Device: You are prompted to power up the device; if it is already powered up, click Next.
4.
cable. Wait until your PC has obtained an IP address; then click Next. The CCA will verify connectivity to the
device.
Connect Device to Your PC/Laptop: You must connect to one of the PoE ports with a straight-through Ethernet
5.
two.
Verifying Connectivity: The CCA will contact the device and confirm connectivity to it. This may take a minute or
6.
Hostname and User Authentication: Enter the administrator username and password. Click Next.
7.
manually. If you want to use NTP for the device's time synchronization, you can skip this step and configure NTP
later.
Enter Date and Time Information: You have the choice of synchronizing the time to the PC's clock or setting it
8.
choose to disable DHCP and set a static IP address.
Enter IP Address and Other Device Setup Parameters: In this screen, you select the WAN interface and can then
9.
language as appropriate to the device's location. These settings change the ring cadence on the phones as well as the
languages displayed and/or heard on the system.
Enter Other Device Setup Parameters: In this section, you select the Region, Phone Language, and Voicemail
10.
update may take up to 10 minutes.
When you launch the CCA application, the Connect window appears. Here you can enter a specific community, IP
address, or hostname of a device to connect to, modify options for connection port numbers, or create a new community
of devices.
A community is a group of SBCS devices (including 500 Series routers, 520 Series switches, wireless APs, and wireless
access controllers). The devices might not be in the same physical location or logical subnet. Communities make centralized
management of a related set of devices simpler; for example, if you have several customers, each of whom has an
SBCS system, you could create a community for each customer, making your administrative organization simpler.
Summary: A brief summary of the configuration you have entered is displayed along with a brief caution that the
CCA Menus
After connection to the device or community, you have access to the menus in the left pane.
Features
Implementing Additional Smart Business Communications System
The SBCS includes support for many features beyond the telephone system; it is also a router, a firewall, an Ethernet
switch, a DHCP server, and optionally a wireless AP. This section will review the configuration of these elements.
Port Settings
From the Configure menu, select Ports, Port Settings.
©
enable or disable PoE negotiation.
The Configuration Settings tab (shown in Figure 43) allows you to enable and disable ports, set duplex and speed, and
here you see that ports have actually negotiated Full Duplex/100 Mbps and PoE.) At the top of the table you can see the
allocated PoE, expressed as Consumed and Remaining values. The display shows Unknown, Cisco, and IEEE under the
Device column; these relate to the different PoE delivery types (IEEE being the current standard, and Cisco being the
prestandard proprietary implementation. Unknown typically means the attached device does not need PoE).
The Runtime Status tab shows what the port is actually doing. (In contrast to the setting of Auto in the Configuration tab,
Security
Under the Security menu, you will find submenus for NAT, VPN Server, Security Audit, and Firewall and DMZ.
NAT
Network Address Translation serves three purposes: First, it hides internal addresses from the outside network (typically
the Internet). Second, it can allow many internal addresses to access the Internet using a single, registered Internet IP.
FIGURE 45
The NAT Page
These first two capabilities are enabled by default on the SBCS. Third, it can provide selective access to internal IPO
addresses from the outside in a controlled manner; this is useful for reaching mail and FTP servers from the Internet, for
example.
The NAT page allows you to configure these specific server targets, as well as firewall service configuration.
VPN Server
The VPN Server page lists and allows you to create the user accounts that can access the system via VPN (to a maximum
of 10 concurrent sessions). You must define a preshared key, which is used in the authentication and encryption process.
Next, define the IP address range that will be assigned to remote clients connecting to the system. The option of enabling
Split Tunneling allows clients to use their own Internet connection for any network other than the ones listed; this is
commonly used if security is less of a concern.
Security Audit
The Security Audit link allows you to inspect and report on the security configuration of a particular device. You are
presented with a list of security checks and an indication of whether the device has passed the check; from here, you can
© 2008 Cisco Systems Inc. All rights reserved. This publication is protected by copyright.
Please see page 147 for more details.
© 2008 Cisco Systems Inc. All rights reserved. This publication is protected by copyright.
Please see page 147 for more details.
select one or more checks and click OK to have the CCA fix the security problem automatically. Although it is convenient
and simple, be aware that increasing the security settings of a device may block connectivity to some applications. If
this is the case, the change can also be undone in this interface, until the best course of action to both resolve the security
issue and allow the intended operation can be determined.
Firewall and DMZ
The Firewall and DMZ page allows you to configure the basic security level (High, Medium, or Low) of the firewall to
apply a preconfigured set of typical restrictions, define which interfaces are trusted and untrusted, and also to define
which interface is the DMZ (Demilitarized Zone—a term that describes a screened network where certain servers and
resources are placed so that controlled access to them can be provided without risking the private network).
Routing
Although the SBCS does not typically run dynamic routing protocols (being designed for smaller installations where such
power is not required or will be handled by other devices), you do have the ability to configure static routes to ensure the
device can reach remote subnets not directly connected.
DHCP
Configuring a DHCP server allows the SNCS to allocate IP address, subnet mask, and default gateway values to hosts on
the LAN. The interface allows you to create a scope of addresses for each VLAN. (A typical system will have one VLAN
for the phones and at least one more for the data devices, such as PCs.) You can also configure static DHCP bindings (so
that you can predict what IP a given MAC address will be assigned) and which addresses or range of addresses will be
excluded from the DHCP scope. The SBCS DHCP server is suited to the task of a small network deployment and should
not be used for larger environments.
Smartports
FIGURE 46
Smartports
The Smartports feature allows for rapid configuration of common interface settings appropriate to different device types;
for example, selecting Switch or Router from the pull-down list associated with a port will activate the 802.1Q trunking
protocol; selecting IP Phone + Desktop will configure multiple-VLAN functionality and QoS settings. The interface also
allows you to view and set the Access (data) and Voice VLANs per port. You can also view the port configuration for the
entire device by clicking its image and then clicking Details.
Wireless
If the SBCS is equipped with or connected to a wireless device, by selecting Configure, WLANs you can view and
change settings for the SSIDs for data and voice (for use with wireless IP Phones such as the 7920 and 7921). Selecting
an SSID allows you to view and configure the wireless settings for the SSID, including the following:
Broadcast in Beacon: Select whether to make the SSID visible to wireless devices.
Security Settings: Change from the default of no security to a setting that may include authentication, encryption,
This screen allows you to view and change the settings for the WAN interface. You can enable or disable the interface,
specify the use of PPPoE if your Internet provider requires it, and choose the addressing method. DHCP can be used, or
if your service provider has allocated you a static IP, you can specify the IP, mask, and default gateway. If you have
selected PPPoE, you can choose IP Negotiated, which relies on the negotiation capabilities of PPPoE to determine an IP
address.
Save Configuration
This simple screen allows you to save the configuration of one or all devices to NVRAM, making it the startup configuration
at the next reboot of the device.
Maintaining a Smart Business Communications System
Several tools are included in CCA to monitor and maintain the SBCS. The Monitor menu includes Reports, with links for
Inventory and VPN Status; Views, with links to Front Panel and Topology (discussed previously), Health; Event
Notification; and System Messages.
Internet Connection

The Cisco SBCS is a unified communications appliance aimed squarely at the small-business market. These all-in-one
devices support data, voice, video, AA, voice mail, security, and wireless for up to 50 users. They leverage UC500 Series
devices, including PoE switches, to provide the expansion capability to scale to the maximum endpoint capacity. Many
connectivity modules for WAN, Internet, and PSTN options are available, and a simple-to-use graphical interface configuration
tool makes it cost effective for small businesses to take advantage of Cisco's Unified Communications products.

Hardware Components

No comments:

Post a Comment