Source record · tier 2 current vendor documentation
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_basic-configuration.html
- Published
- 2024-10-15
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- MRA Access Control on Expressway-C sets the authentication path. The options include SAML SSO, UCM/LDAP basic authentication and combinations of the two. OAuth token with refresh can also be enabled. in context
- The MRA Configuration chapter presents the setup in this order: UC mode, server addresses, SIP, intrusion protection, domains, discovery of UC servers, authentication path, optional OAuth and SAML, then the Unified Communications traversal zone. in context
- On Expressway-C the administrator adds the publisher nodes of Unified CM, IM and Presence Service and Unity Connection. Expressway then discovers the subscriber nodes when Refresh Servers is run. in context
- MRA is enabled by setting Unified Communications mode to Mobile and Remote Access on both Expressway-C and Expressway-E. in context
- Expressway-C and Expressway-E are linked for MRA by a traversal zone of type Unified Communications traversal, with TLS and media encryption. in context
- Discovery makes Expressway-C generate non-configurable neighbor zones to Unified CM whose TLS verify mode is On when discovery used TLS verify. in context
- IM and Presence nodes are discovered on Expressway-C at Configuration > Unified Communications > IM and Presence Service nodes with a Standard AXL API Access account. in context
- Expressway-C discovers Unified CM at Configuration > Unified Communications > Unified CM servers using an account with the Standard AXL API Access role and a chosen TLS verify mode, then Refresh servers discovers the other nodes. in context
- At Configuration > Domains each MRA domain enables SIP registrations and provisioning on Unified CM and where used IM and Presence Service. in context
- MRA is enabled on both Expressway-C and Expressway-E at Configuration > Unified Communications > Configuration by setting Unified Communications mode to Mobile and remote access. in context
- Expressway validates received certificates using the Subject Alternative Name attribute and not the Common Name. in context
- Traversal credentials are created in the Expressway-E local authentication database and entered as connection credentials on Expressway-C; the zone authentication policy is Do not check credentials. in context
- In the UC traversal zone Expressway-E uses SIP port 7001 by default with TLS verify subject name set to the name in the Expressway-C certificate, and Expressway-C uses the same port with Peer 1 address set to the Expressway-E FQDN. in context
- The MRA traversal zone is created at Configuration > Zones > Zones with type Unified Communications traversal which sets SIP TLS with TLS verify On and media encryption Force encrypted. in context
Cite this source record
APA
WarmTransfer. (2024, October 15). Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-exwy-mra-guide-x152-configuration
BibTeX
@misc{warmtransfer-cisco-exwy-mra-guide-x152-configuration,
title = {Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/cisco-exwy-mra-guide-x152-configuration},
note = {Cisco Systems, accessed 2026-09-24}
}