Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kulo shicilelo ndiza kubonisa kwaye ndichaze ezinye zeentsonkothi zokuseta iseva yeCMS kwimowudi yeqela le-faillover.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

IingcamangoNgokubanzi, kukho iintlobo ezintathu zokusasazwa kweseva yeCMS:

  • I-Single idibeneyo(Single sidityanisiwe), i.e. Lo ngumncedisi omnye apho zonke iinkonzo eziyimfuneko zisebenza. Kwiimeko ezininzi, olu hlobo lokuthunyelwa lufanelekile kuphela ukufikelela kumxhasi wangaphakathi kunye nakwiindawo ezincinci apho i-scalability kunye nokunciphisa ukulinganiselwa komncedisi omnye akuyona into ebalulekileyo, okanye kwiimeko apho i-CMS yenza imisebenzi ethile kuphela, njenge-ad hoc. iinkomfa kwiCisco UCM.

    Uqikelelo lweskimu somsebenzi:
    Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

  • I-Split enye(I-Single Split) yandisa uhlobo lokusasazwa lwangaphambili ngokongeza iseva eyahlukileyo yofikelelo lwangaphandle. Ekuhanjisweni kwelifa, oku kuthetha ukuhambisa iseva yeCMS kwi-demilitarized network segment (DMZ) apho abathengi bangaphandle banokufikelela kuyo, kunye nomncedisi omnye weCMS kwi-core network apho abathengi bangaphakathi banokufikelela kwi-CMS. Le modeli ethile yokuthunyelwa ngoku ithathelwe indawo yinto ebizwa ngokuba luhlobo Umda omnye, equka abancedisi Cisco Expressway, enokuthi ibenayo okanye enokuba nezinto ezininzi ezifanayo zokudlula i-Firewall ukuze abathengi bangadingi ukongeza umncedisi weCMS ozinikeleyo.

    Uqikelelo lweskimu somsebenzi:
    Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

  • I-Scalable kwaye iyanyamezela(I-Scalable kunye neFault Tolerant) Olu hlobo lubandakanya ukungafuneki kwecandelo ngalinye, ukuvumela inkqubo ukuba ikhule kunye neemfuno zakho kumthamo wayo omkhulu ngelixa inikezela ngokuphinda-phinda kwimeko yokusilela. Ikwasebenzisa ingcamango ye-Single Edge ukubonelela ngokufikelela kwangaphandle okukhuselekileyo. Olu luhlobo esiza kulujonga kwesi siqendu. Ukuba siyayiqonda indlela yokuhambisa olu hlobo lweqela, asiyi kuqonda kuphela ezinye iintlobo zokuthunyelwa, kodwa siya kuba nako ukuqonda indlela yokwenza amaqela eeseva zeCMS ukulungiselela ukukhula okunokwenzeka kwimfuno.

Ngaphambi kokuba uqhubeke nokuthunyelwa, kufuneka uqonde ezinye izinto ezisisiseko, ezizezi

Amacandelo aphambili esoftware yeCMS:

  • database: Ikuvumela ukuba udibanise ulungelelwaniso oluthile, olufana nesicwangciso sokucofa, izithuba zabasebenzisi, kunye nabasebenzisi ngokwabo. Ixhasa ukuhlanganisana ngokufumaneka okuphezulu (inkosi enye) kuphela.
  • Fowunela iBridge: inkonzo yenkomfa yomsindo kunye nevidiyo enikezela ngolawulo olupheleleyo kulawulo kunye nokuqhutyelwa kweefowuni kunye neenkqubo zemultimedia. Ixhasa ukuhlanganisana ngokufumaneka okuphezulu kunye nokulinganisa.
  • Iseva ye-XMPP: uxanduva lobhaliso kunye nokuqinisekiswa kwabathengi usebenzisa iSicelo seNtlanganiso yeCisco kunye/okanye iWebRTC(unxibelelwano lwexesha lokwenyani, okanye ngokulula kwibhrawuza), kunye nomqondiso we-intercomponent. Inokudityaniswa ngokufumaneka okuphezulu kuphela.
  • Ibhulorho yeWebhu: Ibonelela ngofikelelo lomxumi kwiWebRTC.
  • Umlayishi: Ibonelela ngenqaku elinye loqhagamshelo kwi-Cisco Meeting Apps kwimowudi yoKukwahlulwa okuNye. Imamela ujongano lwangaphandle kunye nezibuko lodibaniso olungenayo. Ngokulinganayo, umlinganisi womthwalo wamkela uxhulumaniso lwe-TLS olungenayo kwi-XMPP iseva, apho inokutshintsha uxhulumaniso lwe-TCP kubaxhasi bangaphandle.
    Kwimeko yethu akuyi kufuneka.
  • Jika iseva: Ibonelela ngeteknoloji ye-Firewall bypass evumela
    beka i-CMS yethu emva kweFirewall okanye i-NAT ukudibanisa abathengi bangaphandle usebenzisa i-Cisco Meeting App okanye izixhobo ze-SIP. Kwimeko yethu akuyi kufuneka.
  • Web Admin: I-interface yolawulo kunye nokufikelela kwe-API, kubandakanywa neenkomfa ezikhethekileyo ze-CM ezidibeneyo.

Iindlela zoqwalaselo

Ngokungafaniyo nezinye iimveliso zeCisco, i-Cisco Meeting Server ixhasa iindlela ezintathu zoqwalaselo ukulungiselela naluphi na uhlobo lokuthunyelwa.

  • Umgca womyalelo (CLI): Ujongano lwelayini yomyalelo eyaziwa ngokuba yiMMP yoqwalaselo lokuqala kunye nemisebenzi yesatifikethi.
  • Umlawuli wewebhu: Ngokuyintloko kuqwalaselo olunxulumene neCallBridge, ngakumbi xa useka iseva enye engadityaniswanga.
  • I-API yokuphinda: Isetyenziselwa uqwalaselo oluntsonkothileyo lwemisebenzi kunye nemisebenzi enxulumene nesiseko sedatha.

Ukongeza koku ngasentla, iprotocol isetyenziswa SFTP ukudlulisa iifayileβ€”ngokuqhelekileyo iilayisensi, izatifikethi, okanye iilogiβ€”ukuya nokusuka kwiseva yeCMS.

Kwizikhokelo zokuthunyelwa ezivela eCisco kubhalwe ngomhlophe nangesiNgesi ukuba iqela kufuneka lisetyenziswe. ezintathu ubuncinane abancedisi (iindawo) kumxholo wogcino-lwazi. Ngokuba Kuphela linani elingumnqakathi leendawo apho indlela yokukhetha umsebenzi omtsha weDatabase Master, kwaye ngokubanzi uMphathi weDatha weDatha unoqhagamshelo kunye noninzi lwedathabheyisi yeseva yeCMS.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwaye njengoko uqheliselo lubonisa, iiseva ezimbini (iindawo zokuhlala) azanelanga kwaphela. Indlela yokukhetha isebenza xa i-Master iqalwa ngokutsha, iseva yekhoboka iba yiNkosi kuphela emva kokuba iseva eqalwe ngokutsha inyusiwe. Nangona kunjalo, ukuba kwiqela leeseva ezimbini i-Master server iphuma ngokukhawuleza, i-server ye-Slave ayiyi kuba yiNkosi, kwaye ukuba ikhoboka liyaphuma, i-Master server eseleyo iya kuba likhoboka.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kodwa kumxholo we-XMPP, kuya kuba yimfuneko ngokwenene ukudibanisa iqela labancedisi abathathu, kuba ukuba, ngokomzekelo, ukhubaza inkonzo ye-XMPP kwenye yeeseva apho i-XMMP ikwimo yeNkokeli, ngoko kumncedisi oseleyo XMPP izakusala kubume boMlandeli kwaye uqhagamshelo lweCallBridge kwi XMPP luza kuwa, ngokuba I-CallBridge iqhagamshela kuphela kwi-XMPP enemo yeNkokeli. Kwaye oku kubaluleke kakhulu, kuba ... akukho nomnxeba omnye oza kudlula.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwakhona kwizikhokelo ezifanayo zokusasaza i-cluster ene-XMPP server ibonakalisiwe.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwaye kuthathela ingqalelo oku ngasentla, kuyacaca ukuba kutheni: isebenza kuba ikwimowudi ye-faillover.

Kwimeko yethu, iseva ye-XMPP iya kubakho kuzo zontathu iindawo.

Kucingelwa ukuba zontathu iiseva zethu ziphezulu.

DNS irekhodi

Ngaphambi kokuba uqale ukuseta iiseva, kufuneka udale iirekhodi zeDNS А и I-SRV iintlobo:

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Nceda uqaphele ukuba kwiirekhodi zethu ze-DNS kukho imimandla emibini umzekelo.com kunye conf.example.com. Umzekelo.com yisizinda apho bonke ababhalisi beCisco Umphathi woNxibelelwano oluManyeneyo banokulusebenzisa kwii-URIs zabo, ezinokuthi zibekhona kwiziseko zophuhliso okanye ezinokuthi zibe khona. Okanye umzekelo.com uhambelana nesizinda esifanayo esisetyenziswa ngabasebenzisi kwiidilesi zabo ze-imeyile. Okanye umxhasi weJabber kwilaptop yakho unokuba ne-URI [imeyile ikhuselwe]. Domain conf.example.com yisizinda esiza kumiselwa kubasebenzisi beSeva yeNtlanganiso yeCisco. Isizinda seSeva yeNtlanganiso yeCisco iya kuba conf.example.com, ke kumsebenzisi ofanayo weJabber, umsebenzisi@ URI kuya kufuneka isetyenziswe ukungena kwiSeva yeNtlanganiso yeCisco.conf.example.com.

Ubumbeko olusisiseko

Zonke izicwangciso ezichazwe ngezantsi ziboniswa kwiseva enye, kodwa kufuneka zenziwe kumncedisi ngamnye kwiqela.

I-QoS

Ekubeni iCMS ivelisa Ixesha elilungile i-traffic enomdla wokulibaziseka kunye nokulahleka kwepakethi, kwiimeko ezininzi kuyacetyiswa ukuba uqwalasele umgangatho wenkonzo (QoS). Ukufezekisa oku, i-CMS ixhasa iipakethi zokuthega ngeeKhowudi zeeNkonzo eziDifferentiated (DSCPs) ezivelisayo. Nangona ukubekwa phambili kwetrafikhi esekwe kwi-DSCP kuxhomekeke kwindlela i-traffic ecutshungulwa ngayo ngamacandelo enethiwekhi yesiseko sakho, kwimeko yethu siya kumisela i-CMS yethu ngokubeka phambili kwe-DSCP okuqhelekileyo okusekwe kwiindlela ezilungileyo zeQoS.

Kumncedisi ngamnye siya kufaka le miyalelo

dscp 4 multimedia 0x22
dscp 4 multimedia-streaming 0x22
dscp 4 voice 0x2E
dscp 4 signaling 0x1A
dscp 4 low-latency 0x1A

Ngaloo ndlela, yonke i-traffic yevidiyo iphawulwe AF41 (DSCP 0x22), yonke i-traffic traffic yaphawulwa i-EF (DSCP 0x2E), ezinye iintlobo ze-low latency traffic ezifana ne-SIP kunye ne-XMPP sebenzisa i-AF31 (DSCP 0x1A).

Ukuhlola:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

NTP

IProtocol yeXesha leNethiwekhi (NTP) ayibalulekanga kuphela ekuboneleleni ngezitempu zexesha ezichanekileyo zeefowuni kunye neenkomfa, kodwa kunye nokuqinisekisa izatifikethi.

Yongeza iiseva ze-NTP kwisiseko sakho ngomyalelo onje

ntp server add <server>

Kwimeko yethu, kukho ezimbini iiseva ezinjalo, ngoko kuya kubakho amaqela amabini.
Ukuhlola:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Kwaye usete indawo yexesha leseva yethu
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

DNS

Songeza iiseva ze-DNS kwiCMS ngomyalelo onje:

dns add forwardzone <domain-name> <server ip>

Kwimeko yethu, kukho ezimbini iiseva ezinjalo, ngoko kuya kubakho amaqela amabini.
Ukuhlola:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Uqwalaselo loNxibelelwano lweNethiwekhi

Siqwalasela ujongano ngomyalelo onje:

ipv4 <interface> add <address>/<prefix length> <gateway>

Ukuhlola:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Igama leseva (Igama lomamkeli)

Siseta igama leseva ngomyalelo onje:

hostname <name>

Kwaye siqalisa kwakhona.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Oku kugqiba uqwalaselo olusisiseko.

Izatifikethi

IingcamangoI-Cisco Meeting Server ifuna unxibelelwano olufihliweyo phakathi kwamacandelo ahlukeneyo, kwaye ngenxa yoko, izatifikethi ze-X.509 ziyafuneka kuzo zonke ii-deployments ze-CMS. Banceda ukuqinisekisa ukuba iinkonzo / umncedisi uthenjiwe ngamanye amaseva / iinkonzo.

Inkonzo nganye ifuna isatifikethi, kodwa ukwenza izatifikethi ezahlukeneyo kwinkonzo nganye kunokukhokelela ekubhidekeni kunye nobunzima obungeyomfuneko. Ngethamsanqa, singenza isitshixo sesatifikethi sikawonke-wonke-sabucala kwaye siphinde sisebenzise kwiinkonzo ezininzi. Kwimeko yethu, isatifikethi esifanayo siya kusetyenziswa kwi-Call Bridge, i-XMPP Server, i-Web Bridge kunye ne-Web Admin. Ke ngoko, kufuneka wenze iperi yezitshixo zesatifikethi zikawonke-wonke nezabucala zomncedisi ngamnye kwiqela.

Ukuhlanganiswa kwesiseko sedatha, nangona kunjalo, kuneemfuno zesatifikethi ezikhethekileyo kwaye ke ngoko kufuna izatifikethi zayo ezahlukileyo kwezo zezinye iinkonzo. I-CMS isebenzisa isatifikethi somncedisi, esifana nezatifikethi ezisetyenziswa ngabanye abancedisi, kodwa kukwakho nesatifikethi somxhasi esisetyenziselwa uqhagamshelwano lwesiseko sedata. Izatifikethi zeDatabase zisetyenziselwa zombini ungqinisiso kunye noguqulelo oluntsonkothileyo. Endaweni yokubonelela ngegama lomsebenzisi kunye negama lokugqitha ukuze umxhasi aqhagamshele kuvimba wedatha, inika isatifikethi somthengi esithenjwa ngumncedisi. Umncedisi ngamnye kwiqela lesiseko sedatha uya kusebenzisa isitshixo esifanayo sikawonke-wonke nesabucala. Oku kuvumela bonke abancedisi kwiqela ukuba baguqulele ngokuntsonkothileyo idatha ngendlela enokuthi ikhunjulwe kuphela ngabanye abancedisi ababelana ngesibini esitshixo esifanayo.

Ukunciphisa umsebenzi, amaqela e-database kufuneka abe ubuncinane beeseva ezi-3, kodwa zingabi ngaphezu kwe-5, kunye nexesha elide lokuya nokubuya le-200 ms phakathi kwawo nawaphi na amalungu e-cluster. Lo mda uthintelwe ngakumbi kunokuhlanganiswa kwe-Call Bridge, ngoko ke ihlala ingumba osisithintelo kukusasazwa ngokwejografi.

Indima yedatabase yeCMS inenani leemfuno ezizodwa. Ngokungafaniyo nezinye iindima, kufuna umxhasi kunye nesatifikethi somncedisi, apho isatifikethi somthengi sinendawo ethile ye-CN enikezelwa kumncedisi.

I-CMS isebenzisa i-database ye-postgres enenkosi enye kunye neekopi ezininzi ezifanayo. Kukho isiseko sedatha enye kuphela ngexesha ("umncedisi wesiseko sedatha"). Amalungu ashiyekileyo eqela zii-replicas okanye "database clients".

Iqela lesiseko sedatha lifuna isatifikethi somncedisi ozinikeleyo kunye nesatifikethi somthengi. Kufuneka zisayinwe zizatifikethi, ngokuqhelekileyo ngugunyaziwe wangaphakathi wesatifikethi sabucala. Ngenxa yokuba naliphi na ilungu leqela lesiseko sedatha linokuba yinkosi, iseva yedathabheyisi kunye nezibini zesatifikethi somthengi (eziqulethe izitshixo zikawonke-wonke nezabucala) kufuneka zikhutshelwe kuzo zonke iiseva ukuze zithathe isazisi somxhasi okanye iseva yedatha. Ukongeza, isatifikethi sengcambu ye-CA kufuneka silayishwe ukuqinisekisa ukuba umxhasi kunye nezatifikethi zeseva zinokungqinwa.

Ke, senza isicelo sesatifikethi esiza kusetyenziswa zizo zonke iinkonzo zeseva ngaphandle kwesiseko sedatha (kuya kubakho isicelo esahlukileyo sale nto) ngomyalelo onje:

pki csr hostname CN:cms.example.com subjectAltName:hostname.example.com,example.com,conf.example.com,join.example.com

Kwi-CN sibhala igama eliqhelekileyo lamaseva ethu. Umzekelo, ukuba iinginginya zeeseva zethu umncedisi01, umncedisi02, umncedisi03, ngoko i-CN iya kuba iseva.example.com

Senza okufanayo kwiiseva ezimbini ezishiyekileyo ngomahluko wokuba imiyalelo iya kuqulatha "amagama abamkeli" ahambelanayo.

Senza izicelo ezibini zezatifikethi eziya kusetyenziswa yinkonzo yedathabheyisi enemiyalelo efana nale:

pki csr dbclusterserver CN:hostname1.example.com subjectAltName:hostname2.example.com,hostname3.example.com

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

pki csr dbclusterclient CN:postgres

apho dbclusterserver ΠΈ dbclusterclient amagama ezicelo zethu kunye nezatifikethi zexesha elizayo, igama lomamkeli1(2)(3) amagama abancedisi abahambelanayo.

Senza le nkqubo kuphela kwiseva enye (!), Kwaye siya kulayisha izatifikethi kunye neefayile ezihambelanayo .key kwezinye iiseva.

Vula imo yesatifikethi somthengi kwi-AD CSIseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kufuneka kwakhona udibanise izatifikethi zomncedisi ngamnye zibe yifayile enye.Kwi-*NIX:

cat server01.cer server02.cer server03.cer > server.cer

KwiWindows/DOS:

copy server01.cer + server02.cer + server03.cer  server.cer

Kwaye ulayishe kwiseva nganye:
1. Isatifikethi seseva β€œsomntu ngamnye”.
2. Isatifikethi sengcambu (kunye nabaphakathi, ukuba kukho).
3. Izatifikethi zesiseko sedatha ("umncedisi" kunye "nomthengi") kunye neefayile ezine-.key extension, ezenziwe xa kudalwa isicelo sezatifikethi zedatha "yeseva" kunye "nomthengi". Ezi fayile kufuneka zifane kuzo zonke iiseva.
4. Ifayili yazo zontathu izatifikethi β€œzomntu ngamnye”.

Ngenxa yoko, kufuneka ufumane into efana nalo mfanekiso wefayile kumncedisi ngamnye.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Iqela leDatha

Ngoku ekubeni unazo zonke izatifikethi ezilayishwe kwiiseva zeCMS, ungaqwalasela kwaye wenze ukuhlanganisana kwesiseko sedatha phakathi kweenodi ezintathu. Isinyathelo sokuqala kukukhetha umncedisi omnye njenge-master node yeqela ledatha kwaye uyiqwalasele ngokupheleleyo.

I-Master Database

Inyathelo lokuqala ekumiseleni uphindaphindo lwedathabheyisi kukucacisa izatifikethi eziya kusetyenziselwa iziko ledatha. Oku kwenziwa ngokusebenzisa umyalelo onje:

database cluster certs <server_key> <server_crt> <client_key> <client_crt> <ca_crt>

Ngoku masixelele i-CMS ukuba yeyiphi i-interface ekufuneka isetyenziselwe ukuhlanganiswa kwedatha kunye nomyalelo:

database cluster localnode a

Emva koko siqalisa isiseko sedatha yeqela kwiseva ephambili ngomyalelo:

database cluster initialize

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

IiNodi zeDatha yoMxumi

Senza inkqubo efanayo, kuphela endaweni yomyalelo Iqela lesiseko sedata qalisa ngenisa umyalelo njengo:

database cluster join <ip address existing master>

apho idilesi ye-ip ekhoyo ekhoyo yedilesi ye-ip yomncedisi weCMS apho iqela laqaliswa khona, ngokulula Master.

Sijonga indlela iqela lethu ledatha esebenza kuzo zonke iiseva ngomyalelo:

database cluster status

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Senza okufanayo kwiseva yesithathu eseleyo.

Ngenxa yoko, kuvela ukuba umncedisi wethu wokuqala yiNkosi, abanye ngamakhoboka.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Inkonzo yoLawulo lweWebhu

Vula inkonzo yomlawuli wewebhu:

webadmin listen a 445

I-Port 445 yakhethwa kuba i-port 443 isetyenziselwa ukufikelela komsebenzisi kumxumi wewebhu

Siqwalasela inkonzo yoLawulo lweWebhu ngeefayile zesatifikethi ezinomyalelo onje:

webadmin certs <keyfile> <certificatefile> <ca bundle>

Kwaye uvule uMlawuli weWebhu ngomyalelo:

webadmin enable

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ukuba konke kulungile, siya kufumana imigca ye-SUCCESS ebonisa ukuba uMlawuli weWebhu ulungiselelwe ngokuchanekileyo kwinethiwekhi kunye nesatifikethi. Sijonga ukusebenza kwenkonzo sisebenzisa isikhangeli sewebhu kwaye singenise idilesi yomphathi wewebhu, umzekelo: cms.example.com: 445

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Fowunela iBridge Cluster

I-Call Bridge kuphela kwenkonzo ekhoyo kuyo yonke i-CMS yokuthunyelwa. I-Call Bridge yeyona ndlela iphambili yenkomfa. Ikwabonelela nge-SIP interface ukwenzela ukuba iifowuni zihanjiswe okanye zisuka kuyo, umzekelo, i-Cisco Unified CM.

Imiyalelo echazwe ngezantsi kufuneka isetyenziswe kwiseva nganye enezatifikethi ezifanelekileyo.
Ngoko:

Sinxulumanisa izatifikethi kunye nenkonzo yeCall Bridge enomyalelo ofana no:

callbridge certs <keyfile> <certificatefile>[<cert-bundle>]

Sibophelela iinkonzo zeCallBridge kujongano esilufunayo ngomyalelo:

callbridge listen a

Kwaye uqale kabusha inkonzo ngomyalelo:

callbridge restart

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngoku ukuba iiBridges zethu zeFowuni ziqwalaselwe, sinokuyiqwalasela iCall Bridge clustering. I-Call Bridge clustering yahlukile kwi-database okanye i-XMPP clustering. I-Call Bridge Cluster inokuxhasa ukusuka kwi-2 ukuya kwi-8 nodes ngaphandle kwezithintelo. Ayiboneleli kuphela ngokuphindaphinda, kodwa kwakhona ukulinganisa umthwalo ukuze iinkomfa zisasazwe ngokusebenzayo kuzo zonke iiseva zeCall Bridge zisebenzisa ukuhanjiswa kweefowuni ezikrelekrele. I-CMS ineempawu ezongezelelweyo, amaqela e-Call Bridge kunye neempawu ezinxulumene nazo ezingasetyenziselwa ulawulo olongezelelweyo.

Ukuhlanganisana kwebhulorho yokufowuna kuqwalaselwe ngokuyintloko ngojongano lolawulo lwewebhu
Inkqubo echazwe ngezantsi kufuneka iqhutywe kumncedisi ngamnye kwiqela.
Kwaye ke,

1. Yiya kwiwebhu ukuya kuLungiselelo > Iqela.
2.In Fowunela isazisi Bridge Njengegama elikhethekileyo, ngenisa i-callbridge[01,02,03] ehambelana negama leseva. La magama akanamkhethe, kodwa kufuneka ahluke kweli qela. Zichaza ngokwendalo kuba zibonisa ukuba zizazisi zeseva [01,02,03].
3.B IiBridges zeCall ezidibeneyo ngenisa ii-URL zomphathi wewebhu zeeseva zethu kwiqela, CMS[01,02,03].example.com:445, kwindawo yedilesi. Qinisekisa ukuba ukhankanya izibuko. Ungayishiya i-Peer link SIP idomeyini ingenanto.
4. Yongeza isatifikethi kwiCallBridge trust yomncedisi ngamnye, ifayile equlethe zonke izatifikethi zeeseva zethu, esizidibanise kule fayile kwasekuqaleni, ngomyalelo onje:

callbridge trust cluster <trusted cluster certificate bundle>

Kwaye uqale kabusha inkonzo ngomyalelo:

callbridge restart

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngenxa yoko, kwiseva nganye kufuneka ufumane lo mfanekiso:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

XMPP Iqela

Inkonzo ye-XMPP kwi-CMS isetyenziselwa ukuphatha lonke ubhaliso kunye nokuqinisekiswa kwe-Cisco Meeting Apps (CMA), kubandakanywa umxhasi wewebhu we-CMA WebRTC. I-Call Bridge ngokwayo ikwasebenza njengomthengi we-XMPP ngeenjongo zokuqinisekisa kwaye ke kufuneka iqwalaselwe njengabanye abaxumi. Ukunyamezela impazamo ye-XMPP luphawu oluye lwaxhaswa kwiindawo zemveliso ukusukela kwinguqulelo 2.1

Imiyalelo echazwe ngezantsi kufuneka isetyenziswe kwiseva nganye enezatifikethi ezifanelekileyo.
Ngoko:

Sinxulumanisa izatifikethi kunye nenkonzo ye-XMPP ngomyalelo ofana no:

xmpp certs <keyfile> <certificatefile>[<cert-bundle>]

Emva koko chaza ujongano lokumamela ngomyalelo:

xmpp listen a

Inkonzo ye-XMPP ifuna indawo eyodwa. Eli ligama lokungena kubasebenzisi. Ngamanye amazwi, xa umsebenzisi ezama ukungena esebenzisa i-app ye-CMA (okanye ngomxhasi weWebRTC), bangena userID@logindomain. Kwimeko yethu iya kuba userid@conf.example.com. Kutheni ingeyiyo nje i-example.com? Ekuhanjisweni kwethu ngokukodwa, sikhethe i-domain yethu ye-CM edibeneyo abasebenzisi be-Jabber abaza kuyisebenzisa kwi-CM edibeneyo njenge-example.com, ngoko ke sasidinga i-domain eyahlukileyo kubasebenzisi be-CMS ukuhambisa iifowuni ukuya kunye ne-CMS ngokusebenzisa i-SIP domains.

Cwangcisa ithambeka le-XMPP usebenzisa umyalelo onje:

xmpp domain <domain>

Kwaye uvule inkonzo ye-XMPP ngomyalelo:

xmpp enable

Kwinkonzo ye-XMPP, kufuneka udale iinkcazi kwi-Call Bridge nganye eza kusetyenziswa xa ubhalisa ngenkonzo ye-XMPP. La magama akanamkhethe (kwaye awanxulumananga namagama awodwa owaqwalaseleyo ukuhlanganisana kwebhulorho yokufowuna). Kufuneka wongeze iibhulorho zokufowuna ezintathu kwiseva enye ye-XMPP kwaye emva koko ungenise ezo nkcukacha kwezinye iiseva ze-XMPP kwiqela kuba olu qwalaselo alungeni kuvimba weenkcukacha weqela. Kamva siza kumisela iBhulorho yokuFowuna nganye ukusebenzisa eli gama nemfihlo yokubhalisa ngenkonzo ye-XMPP.

Ngoku kufuneka siqwalasele inkonzo ye-XMPP kwi-server yokuqala ngee-Call Bridges ezintathu ze-callbridge01, i-callbridge02 kunye ne-callbridge03. I-akhawunti nganye iya kunikwa amagama ayimfihlo angaqhelekanga. Baza kufakwa kamva kwezinye iiseva zeCall Bridge ukungena kulo mncedisi we XMPP. Faka le miyalelo ilandelayo:

xmpp callbridge add callbridge01
xmpp callbridge add callbridge02
xmpp callbridge add callbridge03

Ngenxa yoko, sijonga ukuba kwenzeke ntoni ngomyalelo:

xmpp callbridge list

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Ngokuchanekileyo umfanekiso ofanayo kufuneka uvele kwiiseva eziseleyo emva kwamanyathelo achazwe ngezantsi.

Emva koko, songeza useto olufanayo kwiiseva ezimbini eziseleyo, kuphela ngemiyalelo

xmpp callbridge add-secret callbridge01
xmpp callbridge add-secret callbridge02
xmpp callbridge add-secret callbridge03

Songeza iMfihlo ngononophelo ukwenzela ukuba, umzekelo, akukho zithuba ezongezelelweyo kuyo.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngenxa yoko, umncedisi ngamnye kufuneka abe nomfanekiso ofanayo:

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Okulandelayo, kubo bonke abancedisi kwiqela, sikhankanya ngokuthemba ifayile equlethe zonke izatifikethi ezithathu, ezenziwe ngaphambili ngomyalelo onje:

xmpp cluster trust <trust bundle>

Sivumela imowudi yeqela le-xmpp kuzo zonke iiseva zeqela ngomyalelo:

xmpp cluster enable

Kumncedisi wokuqala weqela, siqalisa ukuyilwa kweqela le xmpp ngomyalelo:

xmpp cluster initialize

Kwezinye iiseva, yongeza iqela kwi-xmpp ngomyalelo onje:

xmpp cluster join <ip address head xmpp server>

Sijonga kwiseva nganye impumelelo yokudala iqela le-XMPP kwiseva nganye enemiyalelo:

xmpp status
xmpp cluster status

Iseva yokuqala:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yesibini:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yesithathu:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ukuqhagamshela i-Call Bridge kwi-XMPP

Ngoku ekubeni iqela le-XMPP lisebenza, kufuneka uqwalasele iinkonzo zeBridge Bridge ukuqhagamshela kwiqela le-XMPP. Olu lungelelwaniso lwenziwa ngolawulo lwewebhu.

Kwiseva nganye, yiya kuLungiselelo> Ngokubanzi nakwintsimi Igama leBhulorho yokuFowuna eyodwa bhala amagama awodwa ahambelana nomncedisi Call Bridge callbridge[01,02,03]... Ebaleni thambeka conf.example.ru kunye namagama agqithisiweyo ahambelanayo, ungawahlola
nakuwuphi umncedisi kwiqela elinomyalelo:

xmpp callbridge list

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Shiya indawo ethi "Umncedisi" ingenanto ICallbridge iyakwenza ujongo lwe-DNS SRV _xmpp-component._tcp.conf.example.comukufumana iseva ye-XMPP ekhoyo. Iidilesi ze-IP zokuqhagamshela i-callbridges kwi-XMPP zinokwahluka kumncedisi ngamnye, kuxhomekeke ekubeni ngawaphi amaxabiso abuyiselwe kwisicelo serekhodi. _xmpp-component._tcp.conf.example.com callbridge, nto leyo ixhomekeke kwizicwangciso eziphambili zerekhodi elinikiweyo leDNS.

Okulandelayo, yiya kwiSimo> Ngokubanzi ukuze uqinisekise ukuba inkonzo yoMtshakazi yokuFowuna iqhagamshelwe ngempumelelo kwinkonzo ye-XMPP.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ibhulorho yeWebhu

Kumncedisi ngamnye kwiqela, yenza inkonzo yeWebhu yeBhulorho ngomyalelo:

webbridge listen a:443

Siqwalasela inkonzo yeBhulorho yeWebhu ngeefayile zesatifikethi ezinomyalelo onje:

webbridge  certs <keyfile> <certificatefile> <ca bundle>

Ibhulorho yeWebhu ixhasa iHTTPS. Iza kuqondisa kwakhona i-HTTP kwi-HTTPS ukuba iqwalaselwe ukusebenzisa "http-redirect".
Ukuvumela ulwalathiso lwe-HTTP, sebenzisa lo myalelo ulandelayo:

webbridge http-redirect enable

Ukuvumela iBridge Bridge yazi ukuba iBhulorho yeWebhu inokuthembela kuqhagamshelo oluvela kwiBhulorho yokuFowuna, sebenzisa lo myalelo:

webbridge trust <certfile>

apho le yifayile equlathe zontathu izatifikethi kumncedisi ngamnye kwiqela.

Lo mfanekiso kufuneka ube kumncedisi ngamnye kwiqela.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngoku kufuneka senze umsebenzisi ngendima ye "appadmin", siyayifuna ukuze sikwazi ukuqwalasela iqoqo lethu (!), Kwaye kungekhona umncedisi ngamnye kwiqela ngokwahlukileyo, ngale ndlela izicwangciso ziya kusetyenziswa ngokulinganayo kumncedisi ngamnye nangona inyaniso yokuba ziya kwenziwa kube kanye.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ukuseta ngakumbi siya kusebenzisa Iposi.

Ngogunyaziso, khetha Undoqo kwicandelo loGunyaziso

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ukuthumela imiyalelo ngokuchanekileyo kwiseva yeCMS, kufuneka usete ukhowudo olufunekayo

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Sichaza iWebbridge ngomyalelo POST ngeparameter url kunye nexabiso cms.example.com

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwi-webbridge ngokwayo, sibonisa iiparitha ezifunekayo: ukufikelela kwiindwendwe, ukufikelela okukhuselweyo, njl.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Call Bridge Groups

Ngokungagqibekanga, iCMS ayisoloko isenza olona setyenziso lufanelekileyo lwezixhobo zenkomfa ezifumanekayo kuyo.

Umzekelo, kwintlanganiso kunye nabathathi-nxaxheba abathathu, umthathi-nxaxheba ngamnye unokugqiba kwiiBridges zeFowuni ezintathu ezahlukeneyo. Ukuze aba bathathi-nxaxheba bathathu banxibelelane omnye nomnye, iiBridges zeFowuni ziya kuseka ngokuzenzekelayo unxibelelwano phakathi kwazo zonke iiseva kunye nabaxhasi kwiSithuba esifanayo, ukuze kubonakale ngathi bonke abathengi bakwiseva efanayo. Ngelishwa, i-downside kule nto kukuba inkomfa yomntu omnye we-3 ngoku iya kudla izibuko zeendaba ze-9. Ngokucacileyo oku kukusetyenziswa ngokungafanelekanga kwemithombo. Ukongeza, xa iBhulorho yokuFowuna igcwele kakhulu, indlela engagqibekanga kukuqhubeka nokwamkela iifowuni kunye nokubonelela ngenkonzo ethotyiweyo esemgangathweni kubo bonke ababhalisi beCall Bridge.

Ezi ngxaki zisonjululwa kusetyenziswa inqaku leCall Bridge Group. Eli nqaku laziswa kuguqulelo 2.1 lwesoftware yeNhlangano yeCisco kwaye yandisiwe ukuxhasa ulungelelwaniso lomthwalo kuzo zombini eziphumayo neziphumayo zeCisco Meeting App (CMA), kuquka nabathathi-nxaxheba beWebRTC.

Ukusombulula ingxaki yoqhagamshelo kwakhona, imida yomthwalo eqwalaselweyo emithathu yazisiwe kwiBhulorho yeFowuni nganye:

LoadLimit β€” lo ngowona mthwalo wamanani uphezulu kwiBhulorho yokuFowuna ethile. Iqonga ngalinye linomda womthwalo ocetyiswayo, njenge-96000 ye-CMS1000 kunye ne-1.25 GHz nge-vCPU nganye kumatshini wenyani. Iifowuni ezahlukeneyo zidla isixa esithile sezibonelelo ngokuxhomekeke kwisisombululo kunye nesantya sesakhelo somthathi-nxaxheba.
NewConferenceLoadLimitBasisPoints (i-default 50% loadLimit) - ibeka umda womthwalo weseva, emva koko iinkomfa ezintsha ziyanqatshwa.
EkhoyoConferenceLoadLimitBasisPoints (i-default 80% ye-loadLimit) - ixabiso lomthwalo weseva emva kokuba abathathi-nxaxheba bajoyina inkomfa ekhoyo baya kugatywa.

Nangona eli nqaku lenzelwe ukuhanjiswa kweefowuni kunye nokulinganisa umthwalo, amanye amaqela afana ne-TURN Servers, i-Web Bridge Servers kunye neeRekhoda nazo zingabelwa kwi-Call Bridge Groups ukwenzela ukuba nazo zifakwe ngokufanelekileyo ukuze zisetyenziswe ngokufanelekileyo. Ukuba naziphi na ezi zinto azibelwanga kwiqela leefowuni, zithathwa njengezifumaneka kuzo zonke iiseva ngaphandle kokubaluleka okukhethekileyo.

Ezi parameters ziqwalaselwe apha: cms.example.com:445/api/v1/system/configuration/cluster

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Okulandelayo, sibonisa kwi-callbridge nganye ukuba leliphi iqela le-callbridge ekulo:

I-callbridge yokuqala
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
I-callbridge yesibini
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
I-callbridge yesithathu
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngaloo ndlela, silungiselele iqela le-Call Brdige ukuba lisebenzise ngokufanelekileyo izixhobo ze-Cluster ye-Cisco Meeting Server.

Ukungenisa ngaphandle abasebenzisi ukusuka kwi-Active Directory

Inkonzo yoLawulo lweWebhu inecandelo loqwalaselo lwe-LDAP, kodwa ayinikezeli iinketho zoqwalaselo oluntsonkothileyo, kwaye ulwazi alugcinwanga kwisiseko sedatha yeqela, ngoko ke uqwalaselo luya kufuneka lwenziwe, mhlawumbi ngesandla kumncedisi ngamnye nge-Web interface, okanye i-API, kwaye ukuze "izihlandlo ezithathu" Musa ukuvuka "sisaseta idatha nge-API.

Ukusebenzisa i-URL ukufikelela cms01.example.com:445/api/v1/ldapServer zenza into ye-LDAP Server, ichaza iiparamitha ezinje:

  • IP yomncedisi
  • inombolo yezibuko
  • Igama lomsebenzisi
  • iphasiwedi
  • yokuvikela

Khusela - khetha inyaniso okanye ubuxoki ngokuxhomekeke kwi-port, i-389 - ingakhuselekanga, i-636 - ikhuselwe.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Imephu ye-LDAP yomthombo weparameters ukuya kuphawu kwi-Cisco Meeting Server.
Imephu ye-LDAP yenza imephu yeempawu kulawulo lwe-LDAP ukuya kwiimpawu ze-CMS. Ezona mpawu:

  • jidMapping
  • igamaMapping
  • coSpaceNameMapping
  • coSpaceUriMapping
  • coSpaceSecondaryUriMapping

Inkcazo yeempawuIADB imele isazisi sokungena somsebenzisi kwiCMS. Kuba le iyiseva kaMicrosoft eSebenzayo ye-LDAP, i-CMS JID imaphu ukuya kwi-sAMAccountName kwi-LDAP, eyi-ID yokungena kuVimba weefayili oSebenzayo. Kwakhona qaphela ukuba uthatha i-sAMAccountName kwaye wongeze i-domain conf.pod6.cms.lab ukuya ekupheleni kwayo kuba oku kukungena abasebenzisi bakho abaya kukusebenzisa ukungena kwi-CMS.

igamaMapping ihambelana nokuqulethwe kuluhlu lwegama eliSebenzayo lokubonisa Igama kumhlaba wegama lomsebenzisi weCMS.

coSpaceNameMapping yenza igama lesithuba seCMS ngokusekelwe kwindawo yokubonisaName. Olu phawu, kunye ne-coSpaceUriMapping uphawu, yinto efunekayo ukwenza isithuba somsebenzisi ngamnye.

coSpaceUriMapping ichaza indawo yomsebenzisi ye-URI ehambelana nendawo yomsebenzisi. Eminye imimandla ingaqwalaselwa ukuba ifowunelwe esithubeni. Ukuba indawo yomsebenzisi ihambelana nale ndawo kwenye yale mimandla, umnxeba uya kubhekiswa kwindawo yaloo msebenzisi.

coSpaceSecondaryUriMapping ichaza i-URI yesibini ukufikelela kwindawo. Oku kunokusetyenziselwa ukudibanisa inani lamanani lokufowunela umzila kwisithuba somsebenzisi othathwe kumazwe angaphandle njengenye indlela ye-alphanumeric URI echazwe kwiparamitha ye-coSpaceUriMapping.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Iseva ye-LDAP kunye nemephu ye-LDAP zibunjiwe. Ngoku kufuneka uzidibanise ngokudala umthombo we-LDAP.

Ukusebenzisa i-URL ukufikelela cms01.example.com:445/api/v1/ldapSource yenza into ye-LDAP yeMthombo, ichaza iiparamitha ezinje:

  • Mncedisi
  • imephu
  • baseDn
  • isihluzo

Ngoku ulungelelwaniso lwe-LDAP lugqityiwe, unokwenza umsebenzi wongqamaniso owenziwe ngesandla.

Senza oku nokuba kujongano lweWebhu lomncedisi ngamnye ngokucofa Vumelanisa ngoku kwicandelo Active Directory
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

okanye nge-API enomyalelo POST usebenzisa i-URL ukufikelela cms01.example.com:445/api/v1/ldapSyncs

Iinkomfa ze-Ad-Hoc

Yintoni le?Kwingqiqo yemveli, inkomfa kuxa abathathi-nxaxheba ababini bethetha omnye nomnye, kwaye omnye wabathathi-nxaxheba (esebenzisa isixhobo esibhaliswe kwi-CM edibeneyo) cofa iqhosha elithi "Conference", libiza omnye umntu, kwaye emva kokuthetha naloo mntu wesithathu. , icofa iqhosha lika-"Conference" kwakhona ukujoyina bonke abathathi-nxaxheba kwinkomfa yamacandelo amathathu.

Yintoni eyahlula inkomfa ye-Ad-Hoc kwinkomfa ecwangcisiweyo kwi-CMS kukuba inkomfa ye-Ad-Hoc ayikho nje i-SIP call kwi-CMS. Xa umqalisi wenkomfa ecofa iqhosha leNkomfa okwesibini ukumema wonke umntu kwintlanganiso enye, i-CM ehlangeneyo kufuneka yenze umnxeba we-API kwi-CMS ukudala inkomfa ehamba-hamba apho zonke iifowuni zithunyelwa khona. Konke oku kwenzeka kungakhange kuqatshelwe ngabathathi-nxaxheba.

Oku kuthetha ukuba i-CM edibeneyo kufuneka ilungiselele iziqinisekiso ze-API kunye nedilesi ye-WebAdmin / i-port yenkonzo kunye ne-SIP Trunk ngqo kwi-server ye-CMS ukuqhubeka nomnxeba.

Ukuba kuyimfuneko, i-CUCM inokudala ngamandla indawo kwi-CMS ukwenzela ukuba ifowuni nganye ifikelele kwi-CMS kwaye ifanise umgaqo wokufowuna ongenayo ojoliswe kwiindawo.

Ukudityaniswa neCUCM iqwalaselwe ngendlela efanayo njengoko kuchaziwe kwinqaku ngaphambili ngaphandle kokuba kwiCisco UCM kufuneka udale iziqu ezintathu ze-CMS, iiBridges ezintathu zeNkomfa, kwiProfayili yoKhuseleko ye-SIP ichaza amagama amathathu eSifundo, amaQela eNdlela, uLuhlu lweNdlela, amaQela oNcedo lweMedia kunye noLuhlu lweQela leMedia Resourse, kwaye wongeze imithetho embalwa yokuhamba. kwiSeva yeNtlanganiso yeCisco.

Iprofayile yoKhuseleko lwe-SIP:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Iziqu:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Isiqu ngasinye sibukeka ngokufanayo:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ibhulorho yeNgqungquthela
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ibhulorho nganye yeNkomfa ijongeka ngokufanayo:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Iqela leNdlela
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Uluhlu lweNdlela
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Iqela lemithombo yeendaba
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Uluhlu lweQela leZixhobo zeMedia
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Call Rules

Ngokungafaniyo neenkqubo zolawulo lweefowuni eziphucukileyo ezifana ne-CM eManyeneyo okanye i-Expressway, i-CMS ijonga kuphela i-domain kwindawo ye-SIP yesicelo-i-URI yeefowuni ezintsha. Ke ukuba i-SIP INVITE yeyesip: [imeyile ikhuselwe]I-CMS ikhathalele kuphela i-domain.com. I-CMS ilandela le migaqo ukumisela indawo yokuthumela umnxeba:

1. I-CMS izama kuqala ukutshatisa i-domain ye-SIP kunye ne-domain elungiselelwe kwimigaqo yokufowuna engenayo. Ezi fowuni zinokuthunyelwa kwiindawo ("ezijoliswe kuzo") okanye kubasebenzisi abathile, ii-IVR zangaphakathi, okanye ezidityaniswe ngokuthe ngqo iMicrosoft Lync/Skype yeBusiness (S4B).
2. Ukuba akukho mdlalo kwimigaqo yokufowuna engenayo, i-CMS iya kuzama ukufanisa i-domain elungiselelwe kwitheyibhile yokuthumela ifowuni. Ukuba umdlalo wenziwa, umthetho ungakhaba ngokucacileyo umnxeba okanye udlulise umnxeba. Ngeli xesha, i-CMS inokuphinda ibhale i-domain, eluncedo ngamanye amaxesha ukubiza i-Lync domains. Unokukhetha kwakhona ukudlula ukuphosa, okuthetha ukuba akukho nalinye ibala eliya kulungiswa ngakumbi, okanye usebenzise isicwangciso sokudayela sangaphakathi seCMS. Ukuba akukho kungqamana kwimigaqo yogqithiso lwefowuni, ukungagqibeki kukwala ifowuni. Gcina ukhumbule ukuba kwi-CMS, nangona umnxeba "udluliselwa phambili", abeendaba basabophekile kwi-CMS, oku kuthetha ukuba kuya kuba kwi-signing and media traffic path.
Emva koko kuphela iifowuni ezithunyelwayo zixhomekeke kwimigaqo yefowuni ephumayo. Olu seto lumisela iindawo apho kuthunyelwa khona iminxeba, uhlobo lwe-trunk (nokuba yifowuni entsha ye-Lync okanye ifowuni ye-SIP eqhelekileyo), kunye naluphi na uguqulelo olunokwenziwa ukuba ugqithiselo alukhethwanga kumthetho wogqithiso lomnxeba.

Nantsi eyona log yento eyenzekayo ngexesha lenkomfa ye-Ad-Hoc

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Umfanekiso weskrini ubonisa kakubi (andazi ukuba ndingayenza njani ibe ngcono), ngoko ndiza kubhala ilogi ngolu hlobo:

Info	127.0.0.1:35870: API user "api" created new space 7986bb6c-af4e-488d-9190-a75f16844e44 (001036270012)

Info	call create failed to find coSpace -- attempting to retrieve from database

Info	API "001036270012" Space GUID: 7986bb6c-af4e-488d-9190-a75f16844e44 <--> Call GUID: 93bfb890-646c-4364-8795-9587bfdc55ba <--> Call Correlator GUID: 844a3c9c-8a1e-4568-bbc3-8a0cab5aed66 <--> Internal G

Info	127.0.0.1:35872: API user "api" created new call 93bfb890-646c-4364-8795-9587bfdc55ba

Info	call 7: incoming SIP call from "sip:[email protected]" to local URI "sip:[email protected]:5060" / "sip:[email protected]"

Info	API call leg bc0be45e-ce8f-411c-be04-594e0220c38e in call 434f88d0-8441-41e1-b6ee-6d1c63b5b098 (API call 93bfb890-646c-4364-8795-9587bfdc55ba)

Info	conference 434f88d0-8441-41e1-b6ee-6d1c63b5b098 has control/media GUID: fb587c12-23d2-4351-af61-d6365cbd648d

Info	conference 434f88d0-8441-41e1-b6ee-6d1c63b5b098 named "001036270012"

Info	call 7: configured - API call leg bc0be45e-ce8f-411c-be04-594e0220c38e with SIP call ID "[email protected]"

Info	call 7: setting up UDT RTP session for DTLS (combined media and control)
Info	conference "001036270012": unencrypted call legs now present

Info	participant "[email protected]" joined space 7986bb6c-af4e-488d-9190-a75f16844e44 (001036270012)

Info	participant "[email protected]" (e8371f75-fb9e-4019-91ab-77665f6d8cc3) joined conference 434f88d0-8441-41e1-b6ee-6d1c63b5b098 via SIP

Info	call 8: incoming SIP call from "sip:[email protected]" to local URI "sip:[email protected]:5060" / "sip:[email protected]"

Info	API call leg db61b242-1c6f-49bd-8339-091f62f5777a in call 434f88d0-8441-41e1-b6ee-6d1c63b5b098 (API call 93bfb890-646c-4364-8795-9587bfdc55ba)

Info	call 8: configured - API call leg db61b242-1c6f-49bd-8339-091f62f5777a with SIP call ID "[email protected]"

Info	call 8: setting up UDT RTP session for DTLS (combined media and control)

Info	call 9: incoming SIP call from "sip:[email protected]" to local URI "sip:[email protected]:5060" / "sip:[email protected]"

Info	API call leg 37a6e86d-d457-47cf-be24-1dbe20ccf98a in call 434f88d0-8441-41e1-b6ee-6d1c63b5b098 (API call 93bfb890-646c-4364-8795-9587bfdc55ba)

Info	call 9: configured - API call leg 37a6e86d-d457-47cf-be24-1dbe20ccf98a with SIP call ID "[email protected]"

Info	call 9: setting up UDT RTP session for DTLS (combined media and control)
Info	call 8: compensating for far end not matching payload types

Info	participant "[email protected]" joined space 7986bb6c-af4e-488d-9190-a75f16844e44 (001036270012)

Info	participant "[email protected]" (289e823d-6da8-486c-a7df-fe177f05e010) joined conference 434f88d0-8441-41e1-b6ee-6d1c63b5b098 via SIP

Info	call 7: compensating for far end not matching payload types
Info	call 8: non matching payload types mode 1/0
Info	call 8: answering offer in non matching payload types mode
Info	call 8: follow-up single codec offer received
Info	call 8: non matching payload types mode 1/0
Info	call 8: answering offer in non matching payload types mode
Info	call 8: sending response to single-codec additional offer
Info	call 9: compensating for far end not matching payload types

Info	participant "[email protected]" joined space 7986bb6c-af4e-488d-9190-a75f16844e44 (001036270012)

Info	participant "[email protected]" (d27e9a53-2c8a-4e9c-9363-0415cd812767) joined conference 434f88d0-8441-41e1-b6ee-6d1c63b5b098 via SIP

Info	call 9: BFCP (client role) now active
Info	call 9: sending BFCP hello as client following receipt of hello when BFCP not active
Info	call 9: BFCP (client role) now active
Info	call 7: ending; remote SIP teardown - connected for 0:13
Info	call 7: destroying API call leg bc0be45e-ce8f-411c-be04-594e0220c38e

Info	participant "[email protected]" left space 7986bb6c-af4e-488d-9190-a75f16844e44 (001036270012)

Info	call 9: on hold
Info	call 9: non matching payload types mode 1/0
Info	call 9: answering offer in non matching payload types mode
Info	call 8: on hold
Info	call 8: follow-up single codec offer received
Info	call 8: non matching payload types mode 1/0
Info	call 8: answering offer in non matching payload types mode
Info	call 8: sending response to single-codec additional offer
Info	call 9: ending; remote SIP teardown - connected for 0:12

Inkomfa ye-Ad-Hoc ngokwayo:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Imithetho yokufowuna engenayo
Ukuqwalasela iiparamitha zeefowuni ezingenayo kuyimfuneko ukuze ukwazi ukufumana ifowuni kwiCMS. Njengoko ubonile kulungiselelo lwe-LDAP, bonke abasebenzisi bathathwe ngaphandle kunye nesizinda conf.pod6.cms.lab. Ke ngoko ubuncinci, ufuna iifowuni kule domain ukujolisa izithuba. Uya kufuneka kwakhona ukuseta imithetho kuyo yonke into ehloselwe igama lesizinda esifanelekileyo (kwaye mhlawumbi nedilesi ye-IP) nganye yeeseva zeCMS. Ulawulo lwethu lomnxeba lwangaphandle, i-CM eManyeneyo, iya kumisela iziqu ze-SIP ezinikezelwe kwiseva nganye yeCMS. Kuxhomekeka ekubeni indawo ekuyiwa kuyo ezi trunks ze-SIP yidilesi ye-IP okanye i-FQDN yomncedisi iya kugqiba ukuba i-CMS ifuna ukuqwalaselwa ukuze yamkele iminxeba ejoliswe kwidilesi yayo ye-IP okanye i-FQDN.

I-domain enowona mgaqo uphezulu wokungena kuqala usetyenziswa njengesizinda sayo nayiphi na izithuba zomsebenzisi. Xa abasebenzisi bevumelanisa nge-LDAP, i-CMS yenza ngokuzenzekelayo izithuba, kodwa kuphela inxalenye yomsebenzisi we-URI (coSpaceUriMapping), umzekelo, umsebenzisi. Icandelo thambeka I-URI epheleleyo iveliswa ngokusekelwe kulo mgaqo. Ngapha koko, ukuba ungangena kwiBhulorho yeWebhu okwangoku, uya kubona ukuba i-Space URI ayinayo isizinda. Ngokumisela lo mgaqo njengowona mba uphambili uphezulu, umisela i-domain yeendawo eziveliswayo ukuba zibe conf.umzekelo.com.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Imithetho yeFowuni ephumayo

Ukuvumela abasebenzisi ukuba benze iminxeba ephumayo kwi-Unified CM cluster, kufuneka uqwalasele imithetho ephumayo. I-domain of endpoints ebhaliswe ne-Unified CM, njengeJabber, umzekelo.com. Iifowuni eziya kwesi sizinda kufuneka zihanjiswe njengeefowuni eziqhelekileyo ze-SIP ukuya kwiindawo zokusetyenzwa kweefowuni zeCM eziManyeneyo. Umncedisi oyintloko yi-cucm-01.example.com, kwaye enye eyongezelelweyo yi-cucm-02.example.com.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo
Umgaqo wokuqala uchaza eyona ndlela ilula yokufowuna phakathi kweeseva zeqela.

Intsimi Yasekuhlaleni isuka kwindawo unoxanduva lwento eza kuboniswa kwi-SIP-URI yomnxeba kumntu obizwa emva kwesimboli "@". Ukuba siyishiya ingenanto, ngoko emva kwesimboli "@" kuya kubakho idilesi ye-IP yeCUCM apho le fowuni idlula khona. Ukuba sikhankanya idomeyini, emva koko emva kwesimboli "@" kuya kubakho indawo. Oku kuyimfuneko ukuze ukwazi ukufowunela kwakhona, kungenjalo akuyi kuba nako ukuphinda ufowunele nge-SIP-URI name@ip-address.

Fowuna xa ukhankanyiwe Yasekuhlaleni isuka kwindawo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Fowuna xa HAYI kubonisiwe Yasekuhlaleni isuka kwindawo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Qiniseka ukuba ukhankanya ngokucacileyo Uguqulelo Oluntsonkothileyo okanye Olungafihlwanga kwiifowuni eziphumayo, kuba akukho nto isebenza ngeAuto parameter.

Ukurekhoda

Iinkomfa zevidiyo zirekhodwa ngumncedisi weRekhodi. Irekhoda iyafana ncam neSeva yeNtlanganiso yeCisco. Irekhoda ayifuni kufakelo lwazo naziphi na iilayisensi. Iilayisensi zokurekhoda ziyafuneka kwiiseva eziqhuba iinkonzo zeCallBridge, okt. Ilayisensi yokurekhoda iyafuneka kwaye kufuneka isetyenziswe kwicandelo leCallBridge, kwaye kungekhona kwiseva eqhuba iRekhoda. Umrekhoda uziphatha njengeProtocol yeMiyalezo eyandisiweyo kunye noBukho (XMPP) umxhasi, ngoko ke iseva ye-XMPP kufuneka yenziwe ukuba isebenze kwi-CallBridge yomncedisi.

Ngokuba Sineqela kwaye ilayisenisi kufuneka "yolulwe" kuzo zontathu iiseva kwiqela. Ke ngokulula kwiakhawunti yakho yobuqu kwiilayisensi esizinxulumanisa (zongeza) iidilesi ze-MAC ze-a-interface yazo zonke iiseva ze-CMS ezibandakanyiweyo kwiqela.

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwaye lo ngumfanekiso omele ukuba kumncedisi ngamnye kwiqela

Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngokubanzi, kukho iimeko ezininzi zokubeka iRekhoda, kodwa siya kunamathela koku:
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Ngaphambi kokuseta iRecorder, kufuneka ulungiselele indawo apho iinkomfa zevidiyo ziya kurekhodwa. Ngokwenene apha unxibelelwano, njani ukuseta zonke Recording. Ndigxila kumanqaku abalulekileyo kunye neenkcukacha:

1. Kungcono ukutyibilika isatifikethi kumncedisi wokuqala kwiqela.
2. Impazamo ethi "Irekhodi ayifumaneki" inokwenzeka ngenxa yokuba isatifikethi esingalunganga sichazwe kwiTrasti yoMrekhodi.
3. Ukubhala akunakusebenza ukuba uvimba weefayili we-NFS ukhankanyiwe ukuba urekhodwe ayingovimba weefayili.

Ngamanye amaxesha kukho imfuneko yokurekhoda ngokuzenzekelayo inkomfa yomsebenzisi omnye okanye indawo.

Kule nto, iiCallProfiles ezimbini zenziwe:
Ukurekhoda kuvaliwe
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwaye nomsebenzi wokurekhoda ngokuzenzekelayo
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Emva koko, "sincamathela" i-CallProfile enomsebenzi wokurekhoda ngokuzenzekelayo kwindawo efunekayo.
Iseva yeNtlanganiso yeCisco 2.5.2. Iqela kwimowudi eScalable kunye neResilient enomsebenzi wokurekhoda wevidiyo

Kwi-CMS kumiselwe ukuba i-CallProfile ibotshelelwe ngokucacileyo nakweyiphi na indawo okanye indawo, ke le CallProfile isebenza kuphela ngokunxulumene nezi zithuba zithile. Kwaye ukuba iCallProfile ayibotshwanga nakwesiphi na isithuba, ngoko ngokungagqibekanga isetyenziswa kwezo zithuba kungekho CallProfile ibotshelelwe ngokucacileyo.

Ngexesha elizayo ndiza kuzama ukuchaza indlela i-CMS efumaneka ngayo ngaphandle kwenethiwekhi yangaphakathi yombutho.

Imithombo:

umthombo: www.habr.com

Yongeza izimvo