# Setting up ILS and Global Dial Plan Replication in Unified CM

Systems: Cisco Unified CM

For Unified CM administrators who connect two or more clusters with ILS and use Global Dial Plan Replication to share numbers and directory URIs between them.

Canonical: https://warmtransfer.net/guides/cucm-ils-gdpr-setup

Last verified: 2026-10-01

Global Dial Plan Replication (GDPR) uses ILS to replicate directory URIs, alternate numbers, advertised patterns, PSTN failover numbers and route strings to the other clusters in the ILS network[^24]. Cisco's 12.x Preferred Architecture states that GDPR uses ILS as its transport, so a multi-cluster deployment that uses GDPR must set up ILS between all of its Unified CM clusters[^28].

## Before you start

The end of software maintenance releases for Unified CM Version 14 was 7 April 2026[^67]. WarmTransfer's reading of the sources is that, as of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, so new deployments and [upgrades](https://warmtransfer.net/knowledge/cucm-backup-upgrade) would normally target 15SU4a or later[^68]. Call Control Discovery via Service Advertisement Framework is deprecated in Release 15, and Cisco directs customers to ILS instead[^69].

CVE-2026-20045 is a Critical-rated vulnerability in the Unified CM web management interface, and through it an unauthenticated attacker can gain OS access and escalate to root[^70]. It has no workarounds, and Cisco PSIRT reports attempted exploitation in the wild[^71]. It is fixed in Unified CM 14SU5 and 15SU4, or by the patch ciscocm.CSCwr21851_Remote_Code_Execution_v1[^72].

- The ILS service runs only on the Unified CM publisher node, so ILS configuration and verification are done on the publisher of each cluster[^45].
- Each cluster in an ILS network needs a unique Cluster ID[^13].
- Each cluster advertises its own route string[^20], and a route string can be up to 250 alphanumeric characters and may include dots and dashes[^48].
- Cisco's ILS networking capacities for Release 15 are up to 10 hub clusters per ILS network, up to 20 spoke clusters per hub, and at most 200 clusters in total[^8].
- A third-party call control system cannot join an ILS network, and a third-party catalog can be imported only on a hub cluster[^54].

## What changes by situation

- How will the ILS network be shaped? One hub cluster with spoke clusters; Several hub clusters, each with its own spokes; Every cluster is a hub.
- How will clusters authenticate ILS connections? TLS certificates; Shared ILS password; TLS certificates and a password together.
- Will you advertise directory URIs as well as numbers? Numbers only; Numbers and directory URIs.
- How will numbers be advertised? Per-directory-number alternate numbers; Summarizing advertised patterns.
- Will intercluster calls cross a Cisco Unified Border Element? No border element between clusters; A Cisco Unified Border Element sits between clusters.

## Step 1: Choose cluster roles and check capacity

**One hub cluster with spoke clusters**

### Do
Make one cluster the hub and the others its spokes, because a hub can have many spokes but a spoke can have only one hub[^53]. Field reports suggest that practitioners commonly make the Session Management Edition cluster the ILS hub and the leaf clusters spokes[^22]. Cisco's 12.x Preferred Architecture recommends Session Management Edition to centralize dial plan and trunking for 4 or more clusters, and a full mesh of SIP trunks for smaller deployments[^39].
### Verify
Count the spokes, because Cisco's Release 15 capacities allow up to 20 spoke clusters per hub[^8]. Cisco warns that running hub and spoke clusters at or above the ILS capacity maximums may affect performance[^9].

**Several hub clusters, each with its own spokes**

### Do
Choose the hub clusters, up to 10 per ILS network[^8]. Assign each spoke to exactly one hub, because a spoke connects only to its local hub and never directly to other hubs or spokes[^53]. Hub clusters use automesh to build a full mesh with the other hub clusters and relay information across the network[^25].
### Verify
Check the design against Cisco's limits of 10 hub clusters, 20 spoke clusters per hub and 200 clusters in total[^8]. Cisco warns that running at or above these maximums may affect performance[^9].

**Every cluster is a hub**

### Do
Make every cluster a hub, and the hubs will use automesh to build a full mesh with each other[^25].
### Verify
WarmTransfer's reading of the sources is that a design in which every cluster is a hub cannot exceed 10 clusters, because an ILS network supports at most 10 hub clusters, and larger networks need spokes[^27].

## Step 2: Give every cluster a unique Cluster ID

### Do
On each cluster's publisher, set a Cluster ID that is unique across the ILS network under System > Enterprise Parameters[^13]. WarmTransfer's reading of the sources is that the Cluster ID should be set and confirmed on every cluster before ILS is enabled, because ILS will not work with a cluster that still has StandAloneCluster[^12].

### Verify
Confirm that no cluster keeps the default StandAloneCluster value, because ILS does not work if remote clusters keep it[^13]. Before adding a hub cluster, Cisco lists these checks: a unique Cluster ID, a configured FQDN, UDS and EM services running on the hub nodes, working forward and reverse DNS, and consolidated Tomcat certificates imported[^26].

### Rollback
Suggested rollback: record each cluster's previous Cluster ID before you change it, and enter that value again if the change must be reversed. ILS does not work with remote clusters that keep the default StandAloneCluster value[^13].

## Step 3: Prepare ILS authentication

**TLS certificates**

### Do
Exchange the Tomcat certificates of every cluster's publisher, using Bulk Certificate Management in Cisco Unified OS Administration to export, consolidate and import them[^55]. Cisco's Preferred Architecture warns that a CA-signed Tomcat certificate used for ILS must carry the TLS Web Client Authentication extended key usage, because the initiating side also uses it as a client certificate[^57]. From Unified CM 15SU5 onwards, if a cluster's Tomcat server and Tomcat client certificates differ, upload both to the peer's trust store[^1]. A Cisco TAC note gives the ILS port for TLS authentication as 7501[^29].
### Verify
Suggested check: confirm that each publisher's trust store holds the certificate of every peer cluster. In ILS traces, certificate problems show as Certificate verification failed, and the hub logs X509_STORE_get_by_subject failed when a spoke's certificate was not imported[^10].
### Rollback
Suggested rollback: delete the imported peer certificates from each publisher's trust store.

**Shared ILS password**

### Do
Configure the same ILS password on every cluster in the ILS network[^40]. A Cisco TAC note gives the ILS port for password authentication as 7502[^29].
### Verify
Suggested check: confirm that the administrator of every cluster has the identical password value, stored securely. In ILS traces, a password mismatch shows as DecryptData failed together with the ILSPwdAuthenticationFailed alarm[^46].

**TLS certificates and a password together**

### Do
From 11.5, ILS can use TLS certificates and a password together, and this mode needs externally CA-signed certificates with the root CA in tomcat-trust[^56]. Configure the same ILS password on every cluster in the ILS network[^40]. Cisco's Preferred Architecture warns that a CA-signed Tomcat certificate used for ILS must carry the TLS Web Client Authentication extended key usage[^57]. From Unified CM 15SU5 onwards, if a cluster's Tomcat server and Tomcat client certificates differ, upload both to the peer's trust store[^1]. A TAC-documented method joins clusters first with password authentication and switches to TLS once the connection is established[^41].
### Verify
Suggested check: confirm that the root certificate authority certificate is present in the trust store on every publisher. Certificate problems show in ILS traces as Certificate verification failed[^10], and a password mismatch shows as DecryptData failed with the ILSPwdAuthenticationFailed alarm[^46].
### Rollback
Suggested rollback: remove the imported root certificate authority certificates from each publisher's trust store.

## Step 4: Configure ILS and GDPR on the first hub

### Do
On the first hub's publisher, open Advanced Features > ILS Configuration in Cisco Unified CM Administration and set Role to Hub Cluster[^14]. Check Exchange Global Dial Plan Replication Data with Remote Clusters and enter this cluster's route string in Advertised Route String[^20]. Select Use TLS Certificates, Use Password, or both, to match the authentication prepared earlier[^5][^56]. After you save, leave Registration Server blank in the ILS Cluster Registration pop-up because this is the first hub, and keep Activate the Intercluster Lookup Service checked[^47].

### Verify
On this publisher, open Advanced Features > ILS Configuration, where the ILS Clusters and Global Dial Plan Imported Catalogs section should show the ILS network topology[^66].

### Rollback
Suggested rollback: clear the global dial plan replication check box and the advertised route string, and test the effect of deactivating the lookup service on learned data in a lab before doing it in production.

## Step 5: Join the remaining clusters

**One hub cluster with spoke clusters**

### Do
On each spoke's publisher, open Advanced Features > ILS Configuration and set Role to Spoke Cluster[^14]. Check Exchange Global Dial Plan Replication Data with Remote Clusters and enter that spoke's own Advertised Route String[^20]. In the ILS Cluster Registration pop-up, enter the hub publisher's IP address or FQDN as Registration Server and keep Activate the Intercluster Lookup Service checked[^47]. ILS then connects the clusters and tells both of them the wider network topology[^32].
### Verify
On the hub's publisher, the ILS Clusters and Global Dial Plan Imported Catalogs section should show every spoke[^66]. Cisco notes that cluster information can take time to propagate depending on the synchronization settings[^43].
### Rollback
Suggested rollback: clear the lookup service settings on the spoke's publisher, after testing the effect on learned data in a lab.

**Several hub clusters, each with its own spokes**

### Do
On each additional hub's publisher, set Role to Hub Cluster[^14], enable GDPR with that cluster's own Advertised Route String[^20], and point Registration Server at an existing hub[^32]. Then join each spoke with Role set to Spoke Cluster and Registration Server set to its own hub's publisher, because a spoke connects only to its local hub[^53][^47].
### Verify
Any hub publisher's ILS Configuration page should show the whole ILS network topology[^66]. Cisco notes that cluster information can take time to propagate depending on the synchronization settings[^43].
### Rollback
Suggested rollback: clear the lookup service settings on each joined cluster, spokes before hubs, after testing the effect on learned data in a lab.

**Every cluster is a hub**

### Do
On each remaining cluster's publisher, set Role to Hub Cluster[^14], enable GDPR with that cluster's own Advertised Route String[^20], and point Registration Server at any existing hub[^32]. The hubs then use automesh to build a full mesh with each other[^25].
### Verify
Each hub publisher's ILS Configuration page should show the ILS network topology, including the other hubs[^66]. Cisco notes that cluster information can take time to propagate depending on the synchronization settings[^43].
### Rollback
Suggested rollback: clear the lookup service settings on the joined cluster, after testing the effect on learned data in a lab.

## Step 6: Verify the ILS network

### Do
On each publisher, open Advanced Features > ILS Configuration and read the ILS Clusters and Global Dial Plan Imported Catalogs section[^66]. On the CLI, run `run sql select * from remotecluster`, which the TAC note uses to check ILS registration alongside the ILS Configuration window[^65].

### Verify
Suggested check: confirm that every expected cluster appears both on the configuration page and in the command output on each publisher. If a cluster is missing, look for the ILSHubClusterUnreachable, ILSPwdAuthenticationFailed and ILSTLSAuthenticationFailed alerts, which the Release 15 RTMT guide lists among its ILS alerts[^49]. The TAC note gives the ILS debug trace location as activelog /cm/trace/ils/sdl/[^30]. In the field, practitioners temporarily lower the ILS Synchronize Clusters Every interval to 1 minute while testing a new hub-spoke join and refresh the ILS Configuration page[^23].

## Step 7: Set SIP profile and trunk options for intercluster trunks

**Numbers only**

### Do
Keep the SIP Profile's Dial String Interpretation at its default, which treats 0-9, * and + as phone numbers and anything else as a URI[^17]. Keep the trunk's Calling and Connected Party Info Format at Deliver DN only, which is the default[^58].
### Verify
Suggested check: confirm that the intercluster SIP profile and trunk still show their default values.

**Numbers and directory URIs**

### Do
Cisco says that when directory URI patterns are advertised, the SIP Profile's Dial String Interpretation must stop URI patterns from being treated as directory number patterns[^60]. Set Dial String Interpretation on the intercluster SIP profile accordingly, since that setting chooses whether dial strings are treated as URIs or phone numbers[^17]. On the SIP trunk, set Calling and Connected Party Info Format to Deliver URI only if available, or to Deliver URI and DN if available, which sends a blended address[^58].
### Verify
Suggested check: confirm that the SIP profile and trunk show the new values, and that a test directory URI call in Step 14 carries the URI.
### Rollback
Suggested rollback: restore the previous dial string interpretation value on the SIP profile. Deliver DN only is the trunk's default Calling and Connected Party Info Format[^58].

## Step 8: Carry the route string across a border element

**No border element between clusters**

### Do
The SIP Profile check box Send ILS Learned Destination Route String is needed in GDPR deployments that route calls across a Cisco Unified Border Element[^50].
### Verify
Suggested check: confirm that no border element sits in the intercluster call path, so that this check box is not required.

**A Cisco Unified Border Element sits between clusters**

### Do
On the SIP profile of the trunk toward the Cisco Unified Border Element, check Send ILS Learned Destination Route String, which is needed in GDPR deployments that route calls across a Cisco Unified Border Element[^50].
### Verify
Suggested check: confirm that the check box is set on the SIP profile actually assigned to that trunk.
### Rollback
Suggested rollback: clear the check box on that SIP profile.

## Step 9: Create SIP route patterns for learned route strings

### Do
Go to Call Routing > SIP Route Pattern, set Pattern Usage to Domain Routing, enter the learned route string in the IPv4 or IPv6 pattern field, and select the SIP trunk or route list to the next-hop cluster, repeating this for each learned route string[^52]. If a SIP route pattern name contains dashes, there must be no numerical digits between the dashes[^51]. In the field, practitioners in a Session Management Edition design build 1 SIP route pattern per leaf cluster route string on the Session Management Edition cluster and a single SIP route pattern on each leaf pointing toward it[^21].

### Verify
When a caller dials a directory URI or alternate number homed in another cluster, Unified CM takes the associated route string, matches it to a SIP route pattern and sends the call there[^31]. Suggested check: confirm that each remote route string matches exactly one SIP route pattern and that the pattern points to a reachable trunk.

### Rollback
Suggested rollback: delete the SIP route patterns added in this step.

## Step 10: Put learned data in reachable partitions and set the database limit

### Do
At Call Routing > Global Dial Plan Replication > Partitions for Learned Numbers and Patterns, assign the partitions for learned data, where the predefined ones are Global Learned Enterprise Numbers, Global Learned E.164 Numbers, Global Learned Enterprise Patterns and Global Learned E.164 Patterns[^35]. A learned number or learned pattern cannot be assigned to the NULL partition[^34]. Add these partitions to the calling search spaces of the callers who should reach remote clusters, because directory URIs and alternate numbers are dialable only from a partition included in the calling party's calling search space[^15][^73]. When a calling search space is assigned to both the caller's device and directory number, Unified CM concatenates the two to form the effective [calling search space](https://warmtransfer.net/knowledge/cucm-config-route-patterns-and-partitions)[^74]. The 12.x Preferred Architecture dial plan uses a partition named onNetRemote for all remote on-net destinations, including number ranges learned through GDPR[^37]. Check the ILS Max Number of Learned Objects in Database service parameter (Cisco Intercluster Lookup Service, clusterwide), which defaults to 100,000 with a maximum of 1,000,000[^36].

### Verify
Suggested check: confirm that the relevant calling search spaces include the learned partitions and that the expected volume of learned data stays below the configured limit.

### Rollback
Suggested rollback: remove the learned partitions from the calling search spaces and restore the previous parameter value. Lowering the learned-objects limit does not delete existing entries; it only blocks new ones[^36].

## Step 11: Advertise numbers

**Per-directory-number alternate numbers**

### Do
On each directory number, set an enterprise and/or +E.164 alternate number mask; for example, mask 5XXXX on extension 4001 gives enterprise alternate number 54001[^4]. For each alternate number, check Advertise Globally via ILS, and optionally use Add to Local Route Partition with a partition[^18]. Optionally set the Advertised Failover Number, which makes the enterprise or +E.164 alternate number the PSTN failover when routing over VoIP fails[^44]. Cisco's Preferred Architecture describes GDPR as advertising, per directory number, 1 +E.164 number, 1 enterprise significant number and up to 5 alphanumeric URIs[^38]. For large numbers of users, Cisco recommends configuring global dial plan data in universal line templates and applying them through LDAP sync or [Bulk Administration](https://warmtransfer.net/knowledge/cucm-bulk-administration-tool)[^7].
### Verify
A receiving ILS cluster does not write learned information until its database replication has completed, even when the data was exchanged successfully[^16]. Suggested check: dial an advertised alternate number from a remote cluster once that cluster's database replication is complete.
### Rollback
Suggested rollback: clear Advertise Globally via ILS on the affected directory numbers.

**Summarizing advertised patterns**

### Do
At Call Routing > Global Dial Plan Replication > Advertised Patterns, add each pattern (such as 54XXX) with a type of Enterprise or E.164 Number Pattern and a PSTN failover option[^2]. Advertised patterns summarize a range of enterprise or +E.164 alternate numbers so the pattern is replicated instead of individual numbers, which saves database space in remote clusters[^3]. Individual alternate numbers that fall inside an advertised pattern's range do not need to be advertised separately[^42].
### Verify
A receiving ILS cluster does not write learned information until its database replication has completed[^16]. Suggested check: from a remote cluster, place a call into each advertised range and confirm it routes through the expected SIP route pattern.
### Rollback
Suggested rollback: delete the advertised patterns added in this step.

## Step 12: Advertise directory URIs

**Numbers only**

### Do
Leave clear the Advertise Globally via ILS check box that each line-based directory URI carries, since that check box is what puts a URI in advertised catalogs[^63].
### Verify
Suggested check: confirm that no local directory URIs appear in the learned data of remote clusters.

**Numbers and directory URIs**

### Do
Give each directory number up to 5 line-based directory URIs, each with its own partition, and check Advertise Globally via ILS on each one to put it in advertised catalogs[^63]. Directory URIs provisioned through LDAP synchronization are user-based and are placed in the local Directory URI partition[^33]. By default the user part of a directory URI is case sensitive, and the URI Lookup Policy enterprise parameter makes it case insensitive[^59]. A directory URI takes the form user@domain or user@ip_address, with a user part of at most 47 characters and a host part of at least 2 characters, and percent-encoded special characters lengthen the stored value[^61]. We infer that advertising directory URIs adds up to 5 learned URI objects per directory number in remote clusters, so URI-heavy networks should check totals against ILS Max Number of Learned Objects[^64].
### Verify
Suggested check: place a directory URI call from a remote cluster and confirm that it connects. If ILS learns the same directory URI from 2 remote clusters, calls route to whichever cluster's URI was learned first[^19]. Physical phones cannot set call forward to a URI, and applications can set it only when the URI already exists in the Unified CM database[^62].
### Rollback
Suggested rollback: clear Advertise Globally via ILS on the directory URIs.

## Step 13: Block unwanted learned numbers or patterns (optional)

### Do
At Call Routing > Global Dial Plan Replication > Block Learned Numbers and Patterns, add any learned numbers or patterns this cluster must not route to[^6].

### Verify
ILS checks local blocking rules before routing, and the rules are not replicated to the ILS network[^6]. Suggested check: confirm that a call to a blocked learned number fails on this cluster and still connects from the other clusters.

### Rollback
Suggested rollback: delete the blocking rule.

## Step 14: Test end to end and troubleshoot replication

### Do
If learned data is missing on a cluster, check that cluster's database replication first, because a receiving ILS cluster does not write learned information until its database replication has completed[^16]. Then check RTMT, because the Release 15 RTMT guide lists 6 ILS alerts: ILSDuplicateURI, ILSHubClusterUnreachable, ILSPeerLimitApproachingWarning, ILSPeerLimitExceeded, ILSPwdAuthenticationFailed and ILSTLSAuthenticationFailed[^49]. In ILS traces, a password mismatch shows as DecryptData failed with the ILSPwdAuthenticationFailed alarm[^46], and certificate problems show as Certificate verification failed[^10].

### Verify
Suggested check: from every cluster, place a test call to an advertised number on each other cluster, and to a directory URI where URIs are advertised. A call to a remote directory URI or alternate number should match a SIP route pattern by its route string, and the PSTN failover number can be used if VoIP routing fails[^31].

## Applicability

Applies to: Cisco Unified Communications Manager and Cisco Unified Real-Time Monitoring Tool. Deployments: on-premises and dedicated instance. Sources checked 2026-10-01. From Unified CM 15SU5 onwards, the note on differing Tomcat server and client certificates applies to ILS TLS[^1]. The option of combining TLS certificates with a password is documented from 11.5[^56]. Version 15 is the latest Unified CM major release listed on Cisco's support pages, released on 16 October 2023[^75]. Cisco Unified CM Version 14 is Not Orderable and its last date of support is 30 April 2027[^76].

## What remains uncertain

Whether current release documentation confirms the ILS ports given in the TAC note is not covered by the sources below. The default and allowed range of the Synchronize Clusters Every field is not covered by the sources below. What deactivating ILS, clearing a cluster's ILS settings, or changing a hub to a spoke does to learned data is not covered by the sources below. Whether a release supports wildcard SIP route patterns for route strings is not covered by the sources below. When 15SU5 becomes available is not covered by the sources below. The descriptions and default settings of the RTMT ILS alerts are not covered by the sources below. Configuring the border element to route on the learned destination route string is not covered by the sources below. The procedure for importing third-party catalogs is not covered by the sources below.

## Sources

[^1]: From Unified CM 15SU5 onwards, if a cluster's Tomcat server and Tomcat client certificates differ, both certificates must be uploaded to the peer's trust store for ILS TLS. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, step 5 (note). Checked 2026-10-01.
[^2]: An advertised pattern is set at Call Routing > Global Dial Plan Replication > Advertised Patterns with a pattern (such as 54XXX), a type of Enterprise or E.164 Number Pattern, and a PSTN failover option. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Set Up Advertised Pattern for Alternate Numbers, procedure. Checked 2026-10-01.
[^3]: Advertised patterns summarize a range of enterprise or +E.164 alternate numbers so the pattern is replicated instead of individual numbers, which saves database space in remote clusters. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Set Up Advertised Pattern for Alternate Numbers. Checked 2026-10-01.
[^4]: Alternate numbers are aliases of a directory number made by applying a mask; for example, mask 5XXXX on extension 4001 gives enterprise alternate number 54001. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Overview > alternate numbers. Checked 2026-10-01.
[^5]: ILS authentication between clusters uses TLS certificates (the Use TLS Certificates check box) or a password (the Use Password check box), both set in the ILS Configuration window. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, step 5. Checked 2026-10-01.
[^6]: Learned numbers and patterns can be blocked at Call Routing > Global Dial Plan Replication > Block Learned Numbers and Patterns; ILS checks local blocking rules before routing, and the rules are not replicated to the ILS network. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Block a Learned Pattern; Interactions and Restrictions. Checked 2026-10-01.
[^7]: For large numbers of users, Cisco recommends configuring global dial plan data in universal line templates and applying them through LDAP sync or Bulk Administration. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Provision Global Dial Plan Data (note). Checked 2026-10-01.
[^8]: Cisco's ILS networking capacities for Release 15 are up to 10 hub clusters per ILS network, up to 20 spoke clusters per hub, and at most 200 clusters in total. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Networking Capacities. Checked 2026-10-01.
[^9]: Cisco warns that running hub and spoke clusters at or above the ILS capacity maximums may affect performance. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Networking Capacities. Checked 2026-10-01.
[^10]: In ILS traces, certificate problems show as Certificate verification failed, and the hub logs X509_STORE_get_by_subject failed when a spoke's certificate was not imported. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Troubleshoot > certificate failures. Checked 2026-10-01.
[^11]: The Release 15 CLI reference documents utils ils showpeerinfo, which returns the ILS peer info vector for one named cluster or, with no argument, for all clusters in the ILS network. Source: [Command Line Interface Reference Guide for Cisco Unified Communications Solutions, Release 15 and SUs - Utils Commands](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/cli_ref/15/cucm_b_cli_reference_guide_release_15/cucm_b_cli_reference_guide_release_1401_chapter_01001.html), Utils Commands > utils ils showpeerinfo. Checked 2026-10-01.
[^12]: Set and confirm a unique Cluster ID on every cluster before enabling ILS, because ILS will not work with a cluster that still has StandAloneCluster (inferred). Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Configuration Task Flow (task order: Configure Cluster IDs precedes Configure ILS). Checked 2026-10-01.
[^13]: Each cluster in an ILS network needs a unique Cluster ID, set under System > Enterprise Parameters on the publisher; ILS does not work if remote clusters keep the default StandAloneCluster value. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Configuration Task Flow > Configure Cluster IDs. Checked 2026-10-01.
[^14]: ILS is configured at Advanced Features > ILS Configuration in Cisco Unified CM Administration on the publisher, where the Role drop-down sets the cluster as Hub Cluster or Spoke Cluster. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, steps 1-3. Checked 2026-10-01.
[^15]: To be dialable, directory URIs, enterprise alternate numbers and +E.164 alternate numbers must be in a partition included in the calling party's calling search space. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Interactions and Restrictions > Calling Search Space. Checked 2026-10-01.
[^16]: Even when global dial plan data is exchanged successfully, a receiving ILS cluster does not write learned information until its database replication has completed. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Interactions and Restrictions > Database Replication Status. Checked 2026-10-01.
[^17]: The SIP Profile's Dial String Interpretation setting chooses whether dial strings are treated as URIs or phone numbers; the default treats 0-9, * and + as phone numbers and anything else as a URI. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Configure SIP Profiles. Checked 2026-10-01.
[^18]: On a directory number, each enterprise and +E.164 alternate number takes a number mask, an optional Add to Local Route Partition with a partition, and an optional Advertise Globally via ILS check box. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Provision Global Dial Plan Data. Checked 2026-10-01.
[^19]: If ILS learns the same directory URI from two remote clusters, calls route to whichever cluster's URI was learned first. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Interactions and Restrictions > Duplicated URI. Checked 2026-10-01.
[^20]: GDPR is enabled under Advanced Features > ILS Configuration by checking Exchange Global Dial Plan Replication Data with Remote Clusters and entering the local cluster's route string in Advertised Route String. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Enable ILS Support for Global Dial Plan Replication. Checked 2026-10-01.
[^21]: In an SME design, practitioners build one SIP route pattern per leaf cluster route string on the SME and a single SIP route pattern on each leaf pointing toward the SME (field report). Source: [UC Valley: SME - Global Dial Plan Replication(GDPR)](https://colinzhong.blogspot.com/2019/03/sme-global-dial-plan-replicationgdpr.html), SIP route pattern section. Checked 2026-10-01.
[^22]: Practitioners commonly make the Session Management Edition cluster the ILS hub and the leaf clusters spokes (field report). Source: [UC Valley: SME - Global Dial Plan Replication(GDPR)](https://colinzhong.blogspot.com/2019/03/sme-global-dial-plan-replicationgdpr.html), ILS configuration (role selection). Checked 2026-10-01.
[^23]: While testing a new hub-spoke join, practitioners temporarily lower the ILS Synchronize Clusters Every interval to 1 minute and refresh the ILS Configuration page (field report). Source: [UC Valley: SME - Global Dial Plan Replication(GDPR)](https://colinzhong.blogspot.com/2019/03/sme-global-dial-plan-replicationgdpr.html), verification / troubleshooting tip. Checked 2026-10-01.
[^24]: Global Dial Plan Replication uses ILS to replicate directory URIs, alternate numbers, advertised patterns, PSTN failover numbers and route strings to the other clusters in the ILS network. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Overview. Checked 2026-10-01.
[^25]: ILS hub clusters form the backbone of an ILS network and use automesh to build a full mesh with the other hub clusters, relaying information across the network. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure Intercluster Lookup Service > ILS Overview > ILS Network Components. Checked 2026-10-01.
[^26]: Before adding a hub cluster, Cisco lists these checks: a unique Cluster ID, a configured FQDN, UDS and EM services running on the hub nodes, working forward and reverse DNS, and consolidated Tomcat certificates imported. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Interactions and Restrictions > ILS Hub. Checked 2026-10-01.
[^27]: An ILS design in which every cluster is a hub cannot exceed 10 clusters, because an ILS network supports at most 10 hub clusters; larger networks need spokes (inferred). Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Networking Capacities (derived). Checked 2026-10-01.
[^28]: GDPR uses ILS as its transport, so a multi-cluster deployment that uses GDPR must set up ILS between all of its Unified CM clusters. Source: [Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control](https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Collaboration/enterprise/12x/120/collbcvd/control.html), Call Control > multi-cluster deployments (GDPR). Checked 2026-10-01.
[^29]: A Cisco TAC note gives the ILS ports as 7501 for TLS authentication and 7502 for password authentication. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Background / ILS ports. Checked 2026-10-01.
[^30]: The TAC note gives the ILS debug trace location as activelog /cm/trace/ils/sdl/. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Troubleshoot. Checked 2026-10-01.
[^31]: When a caller dials a directory URI or alternate number homed in another cluster, Unified CM takes the associated route string, matches it to a SIP route pattern and sends the call there; the PSTN failover number can be used if VoIP routing fails. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Call Routing for Global Dial Plan Replication. Checked 2026-10-01.
[^32]: After ILS runs on a hub, a new cluster joins by enabling ILS and pointing to an existing hub; ILS then connects the clusters and tells both of them the wider network topology. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Overview. Checked 2026-10-01.
[^33]: Directory URIs provisioned through LDAP synchronization are user-based and are placed in the local Directory URI partition, while line-based URIs can each be given their own local partition. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Interactions and Restrictions > Partitioning with URI Dialing. Checked 2026-10-01.
[^34]: A learned number or learned pattern cannot be assigned to the NULL partition. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Assign Partitions for Learned Numbers and Patterns (note). Checked 2026-10-01.
[^35]: Learned numbers and patterns go into partitions set at Call Routing > Global Dial Plan Replication > Partitions for Learned Numbers and Patterns; the predefined ones are Global Learned Enterprise Numbers, Global Learned E.164 Numbers, Global Learned Enterprise Patterns and Global Learned E.164 Patterns. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Assign Partitions for Learned Numbers and Patterns. Checked 2026-10-01.
[^36]: The ILS Max Number of Learned Objects in Database service parameter (Cisco Intercluster Lookup Service, clusterwide) defaults to 100,000 with a maximum of 1,000,000; lowering it does not delete existing entries, it only blocks new ones. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Set Database Limits for Learned Data. Checked 2026-10-01.
[^37]: The 12.x Preferred Architecture dial plan uses a partition named onNetRemote for all remote on-net destinations, including number ranges learned through GDPR, and makes it reachable through calling search spaces. Source: [Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control](https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Collaboration/enterprise/12x/120/collbcvd/control.html), Call Control > dial plan partitions (onNetRemote). Checked 2026-10-01.
[^38]: Cisco's Preferred Architecture describes GDPR as advertising, per directory number, one +E.164 number, one enterprise significant number and up to five alphanumeric URIs. Source: [Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control](https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Collaboration/enterprise/12x/120/collbcvd/control.html), Call Control > GDPR. Checked 2026-10-01.
[^39]: Cisco's 12.x Preferred Architecture recommends Session Management Edition to centralize dial plan and trunking for four or more clusters, and a full mesh of SIP trunks for smaller deployments. Source: [Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control](https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Collaboration/enterprise/12x/120/collbcvd/control.html), Call Control > multi-cluster deployments. Checked 2026-10-01.
[^40]: With ILS password authentication, the same password must be configured on every cluster in the ILS network. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Configure > Password authentication. Checked 2026-10-01.
[^41]: A TAC-documented method joins clusters first with password authentication and switches to TLS once the connection is established. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Configure > switching to TLS after connection. Checked 2026-10-01.
[^42]: Individual alternate numbers that fall inside an advertised pattern's range do not need to be advertised separately. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Interactions and Restrictions > Advertised Patterns. Checked 2026-10-01.
[^43]: The ILS procedure is repeated on every cluster's publisher, and Cisco notes that cluster information can take time to propagate depending on the synchronization settings. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, step 8 (note). Checked 2026-10-01.
[^44]: The Advertised Failover Number on a directory number makes its enterprise or +E.164 alternate number the PSTN failover, used when routing over VoIP to the global dial plan element fails. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Provision Global Dial Plan Data; Global Dial Plan Replication Overview > PSTN failover. Checked 2026-10-01.
[^45]: The ILS service runs only on the Unified CM publisher node, so ILS configuration and verification are done on the publisher of each cluster. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Interactions and Restrictions > ILS Service; Configure ILS step 1. Checked 2026-10-01.
[^46]: In ILS traces, a password mismatch shows as DecryptData failed together with the ILSPwdAuthenticationFailed alarm. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Troubleshoot > password mismatch. Checked 2026-10-01.
[^47]: After the ILS settings are saved, the ILS Cluster Registration pop-up asks for the hub publisher's IP address or FQDN as Registration Server, left blank on the first hub, and needs Activate the Intercluster Lookup Service checked. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, steps 6-7. Checked 2026-10-01.
[^48]: An ILS route string can be up to 250 alphanumeric characters and may include dots and dashes. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Import Global Dial Plan Data (catalog route string); Global Dial Plan Replication Interactions and Restrictions. Checked 2026-10-01.
[^49]: The Release 15 RTMT guide lists six ILS alerts: ILSDuplicateURI, ILSHubClusterUnreachable, ILSPeerLimitApproachingWarning, ILSPeerLimitExceeded, ILSPwdAuthenticationFailed and ILSTLSAuthenticationFailed. Source: [Cisco Unified Real-Time Monitoring Tool Administration Guide, Release 15 and SUs - Performance Counters and Alerts](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/service/15/rtmt/cucm_b_cisco-unified-rtmt-administration-15/cucm_m_performance-counters-and-alerts-15.html), Performance Counters and Alerts > Voice and Video alerts (alert list). Checked 2026-10-01.
[^50]: The SIP Profile check box Send ILS Learned Destination Route String is needed in GDPR deployments that route calls across a Cisco Unified Border Element. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Configure SIP Profiles (trunk-specific settings). Checked 2026-10-01.
[^51]: If a SIP route pattern name contains dashes, there must be no numerical digits between the dashes. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Configure SIP Route Patterns (note). Checked 2026-10-01.
[^52]: A SIP route pattern for a learned route string is added at Call Routing > SIP Route Pattern with Pattern Usage set to Domain Routing, the route string in the IPv4 or IPv6 pattern field and the SIP trunk or route list to the next-hop cluster; repeat for each learned route string. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Configure SIP Route Patterns. Checked 2026-10-01.
[^53]: An ILS spoke cluster connects only to its local hub and never directly to other hubs or spokes; a hub can have many spokes but a spoke can have only one hub. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Overview > ILS Network Components; ILS Interactions and Restrictions > Clusters. Checked 2026-10-01.
[^54]: A third-party call control system cannot join an ILS network, and a third-party catalog can be imported only on a hub cluster. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), ILS Interactions and Restrictions > ILS Network; Cluster Import. Checked 2026-10-01.
[^55]: With TLS authentication, the Tomcat certificates of every cluster's publisher must be exchanged, using Bulk Certificate Management in Cisco Unified OS Administration to export, consolidate and import them. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS (post-procedure note on TLS certificate exchange). Checked 2026-10-01.
[^56]: From 11.5, ILS can use TLS certificates and a password together; this mode needs externally CA-signed certificates with the root CA in tomcat-trust. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Configure > TLS with password. Checked 2026-10-01.
[^57]: Cisco's Preferred Architecture warns that a CA-signed Tomcat certificate used for ILS must carry the TLS Web Client Authentication extended key usage, because the initiating side also uses it as a client certificate. Source: [Preferred Architecture for Cisco Collaboration 12.x Enterprise On-Premises Deployments, CVD - Call Control](https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Collaboration/enterprise/12x/120/collbcvd/control.html), Call Control > certificate guidance for Tomcat (ILS and UDS). Checked 2026-10-01.
[^58]: The SIP trunk's Calling and Connected Party Info Format offers Deliver DN only (the default), Deliver URI only if available, and Deliver URI and DN if available, which sends a blended address. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Configure SIP Trunks for URI Dialing. Checked 2026-10-01.
[^59]: By default the user part of a directory URI (before the @) is case sensitive; the URI Lookup Policy enterprise parameter makes it case insensitive. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Interactions and Restrictions > Directory URI Case Sensitivity. Checked 2026-10-01.
[^60]: When directory URI patterns are advertised, Cisco says the SIP Profile's Dial String Interpretation must stop URI patterns from being treated as directory number patterns. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Configure ILS, step 4 (note). Checked 2026-10-01.
[^61]: A directory URI takes the form user@domain or user@ip_address, with a user part of at most 47 characters and a host part of at least 2 characters; special characters are percent-encoded, which lengthens the stored value. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), URI Dialing > Directory URI Format. Checked 2026-10-01.
[^62]: Physical phones cannot set call forward to a URI, and applications can set it only when the URI already exists in the Unified CM database. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Global Dial Plan Replication Interactions and Restrictions > Call Forwarding to URI. Checked 2026-10-01.
[^63]: A directory number can carry up to five line-based directory URIs, each with its own partition and an Advertise Globally via ILS check box that puts it in advertised catalogs. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Provision Global Dial Plan Data; Interactions and Restrictions. Checked 2026-10-01.
[^64]: Advertising directory URIs as well as numbers adds up to five learned URI objects per directory number in remote clusters, so URI-heavy networks should check totals against ILS Max Number of Learned Objects (inferred). Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Global Dial Plan Replication](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010101.html), Provision Global Dial Plan Data; Set Database Limits for Learned Data (derived). Checked 2026-10-01.
[^65]: The TAC note checks ILS registration with the CLI command run sql select * from remotecluster, alongside the ILS Configuration window. Source: [Configure and Troubleshoot Joining Clusters for ILS](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200694-Configure-and-Troubleshoot-Joining-Clust.html), Verify. Checked 2026-10-01.
[^66]: To verify ILS, open Advanced Features > ILS Configuration on any cluster's publisher; the ILS Clusters and Global Dial Plan Imported Catalogs section should show the ILS network topology. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Intercluster Lookup Service](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010100.html), Verify that ILS is Running, steps 1-3. Checked 2026-10-01.
[^67]: The end of software maintenance releases for Unified CM Version 14 was 7 April 2026. Source: [End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual](https://www.cisco.com/c/en/us/products/collateral/unified-communications/unified-communications-manager-callmanager/v-14-premises-calling-applications-eol.html), Table 1 End-of-life milestones, row End of SW Maintenance Releases Date. Checked 2026-09-30.
[^68]: As of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, and Version 14 has passed its end of software maintenance, so new deployments and upgrades would normally target 15SU4a or later (inferred). Source: [ReadMe for Cisco Unified Communications Manager Release 15SU4a](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/sustaining/cucm_b_readme-15su4a.html), Document header (Last Updated July 29 2026); combined with cisco-eol-v14-onprem-calling-apps Table 1. Checked 2026-09-30.
[^69]: Call Control Discovery via Service Advertisement Framework is deprecated in Release 15, and Cisco directs customers to Intercluster Lookup Service (ILS). Source: [Release Notes for Cisco Unified Communications Manager Release 15SU4a and the IM and Presence Service Release 15SU4](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/rel_notes/15/SU4/cucm_b_release-notes-for-cucm-imp-15su4.html), Deprecated/Removed Features, Call Control Discovery via Service Advertisement Framework. Checked 2026-09-30.
[^70]: CVE-2026-20045 (cisco-sa-voice-rce-mORhqY4b) is a Critical-rated vulnerability, CVSS base 8.2, in the web management interface of Unified CM, SME, IM and Presence, Unity Connection and Webex Calling Dedicated Instance. An unauthenticated attacker can gain OS access and escalate to root. Source: [Cisco Unified Communications Products Remote Code Execution Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b), Summary; Affected Products. Checked 2026-09-30.
[^71]: CVE-2026-20045 has no workarounds, and Cisco PSIRT reports attempted exploitation in the wild. Source: [Cisco Unified Communications Products Remote Code Execution Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b), Workarounds; Exploitation and Public Announcements. Checked 2026-09-30.
[^72]: CVE-2026-20045 is fixed in Unified CM 14SU5 and 15SU4, or by the patch ciscocm.CSCwr21851_Remote_Code_Execution_v1; Release 12.5 customers must migrate to a fixed release. Source: [Cisco Unified Communications Products Remote Code Execution Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b), Fixed Software table. Checked 2026-09-30.
[^73]: A calling search space is a prioritized list of partitions. A caller can reach a destination only if the destination's partition is in the caller's calling search space. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Partitions](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010000.html), Configure Partitions, Calling Search Spaces overview. Checked 2026-09-30.
[^74]: When a calling search space is assigned to both the caller's device and the caller's directory number, Unified CM concatenates the two to form the effective CSS. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Partitions](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010000.html), Configure Partitions, Calling Search Spaces overview. Checked 2026-09-30.
[^75]: Version 15 is the latest Cisco Unified Communications Manager major release listed on Cisco's support pages; it was released on 16 October 2023 and its status is Available. Source: [Cisco Unified Communications Manager (CallManager) - Support](https://www.cisco.com/c/en/us/support/unified-communications/unified-communications-manager-callmanager/series.html), Product status and Latest release fields; Supported versions list. Checked 2026-09-30.
[^76]: Cisco Unified CM Version 14 is Not Orderable and its last date of support is 30 April 2027. Source: [End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual](https://www.cisco.com/c/en/us/products/collateral/unified-communications/unified-communications-manager-callmanager/v-14-premises-calling-applications-eol.html), Table 1 End-of-life milestones, row Last Date of Support. Checked 2026-09-30.
