Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

CUCM, remote sites, and VPN's

Status
Not open for further replies.

atibbets

Technical User
Jul 10, 2008
1
US
Quick question for those with experience here: We are in the process of deploying CUCM 6.x in our corporate office with about 150 local phones (mix of older phones and newer phones, all are using SCCP today, not SIP).

We have about 20 remote offices which are all small and very mobile (they physically move locations frequently). Because of this, we have a mix of cable, DSL, and T1's to remote sites. All remote sites connect to corporate over IPSEC VPN's (PIX 501 or ASA in remote office, ASA 55xx in corporate). Our corporate office has plenty of stable bandwidth available via a DS3.

I'm looking for some guidance on connecting phones in my remote offices (1-6 phones max in most offices) to my call manager. {I understand the implications with 911, lack of QoS, and lack of survivability with this setup}

Given that there are existing VPN connections, should we look at putting the phone traffic "in" the tunnel, or look at options for an external proxy to let the traffic go outside the tunnel to a proxy? I don't fully understand the proxy...it's my understanding that the issue is in NAT and that we can't just simply "publish" the callmanager the way we would something like a web server. The communications to remote offices really doesn't need to be encrypted, I'm just looking for the best performing, most stable solution given what we have.

Anyone using several remote sites over ipsec VPN's? I'm really just curious what others are doing and what your recomendations would be here.

Thanks in advance!
 
We used IPSec VPN tunnels in our remote offices, but each site has a T1 so we dont have any bandwdith limitations. When the T1's are remotes fail the DSL connection kicks in over EzVPN IPSec Tunnel setup connecting to an IOS router or a Concentrator. We dont really allow voice over the DSL connection, hogs the bandwidith. Instead we have POTS lines which we use for 911, but in the case of failover they use these POTS to get by. We just config the router to go into SRST mode.

We have alot of home users also, that have DSL and we *do* run voice over them. I wouldnt want to run voice over DSL for more than 2 or 3 users. We do get alot of QoS complaints of just the 1 phone running over DSL. But thats limitation of no SLA on a home DSL account ;-P.


Hope this helps.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top