Source record · tier 2 current vendor documentation
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html
- Published
- 2024-10-15
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- The Expressway server certificate used for MRA must include the Client Authentication extension, and Expressway refuses to upload a certificate without it. in context
- The Expressway-E certificate's Subject Alternative Names must include the Unified CM registration domains and the XMPP federation domains, plus IM and Presence chat node aliases when federated group chat is used. in context
- MRA requires internal forward and reverse DNS records for every Unified Communications node used with MRA. in context
- The external firewall must allow inbound TCP 5061 (SIP), TCP 8443 (HTTPS), TCP 5222 (XMPP) and UDP 36002-59999 (media) to Expressway-E for MRA. in context
- With multiple Unified CM clusters, MRA requires Home Cluster Discovery. End users must have the Home Cluster field set in End User Configuration so that Expressway-C can send them to the correct cluster, and ILS is the recommended approach. in context
- The X15.2 MRA guide lists these MRA-compatible Jabber minimums: Windows 9.7, iPhone/iPad 9.6.1, Android 9.6 and Mac 9.6. in context
- The X15.2 MRA guide lists minimum versions of Expressway X8.1.1, Unified CM 10.0 and IM and Presence Service 10.0. in context
- For Mobile and Remote Access, public external DNS must contain _collab-edge._tls.<domain> SRV records so that endpoints can discover the Expressway-E servers. in context
- Cisco recommends internal _cisco-uds._tcp.<domain> SRV records for MRA, but from Expressway X12.5 they are no longer a requirement. in context
- _cisco-uds SRV records must not be resolvable from outside the internal network; if they are, Jabber will not start MRA negotiation through Expressway-E. in context
- CAPF certificate operations are not supported over MRA; MRA supports encrypted TFTP configuration files only when CAPF enrollment was completed on premises. in context
- The X15.2 MRA guide lists the IP Phone 7800 and 8800 Series (minimum 11.0(1)) as supported over MRA and excludes the 8821, 8821-EX and 8831. in context
- The external firewall must allow inbound TCP 5061 for SIP and TCP 8443 for HTTPS to the Expressway-E for MRA. in context
- For MRA, public external DNS must hold _collab-edge._tls.<domain> SRV records so endpoints can discover the Expressway-E. in context
- Remote endpoints find Expressway-E through a public DNS SRV record named _collab-edge._tls.<domain>. in context
- The minimum Unified CM version for basic MRA is 10.0. in context
- MRA cannot provision certificates to remote endpoints, CAPF included. CAPF enrollment has to be done on premises, inside the firewall, before the device goes remote. in context
- Cisco does not support third-party network load balancers between MRA clients and Expressway-E. in context
- MRA with OAuth refresh logins needs Unified CM 11.5(1)SU3 or later. in context
- Cisco recommends a single domain with split DNS as the ideal MRA configuration. in context
- The AXL Web Service must be enabled on the Unified CM publisher node for Expressway-C to discover Unified CM for MRA. in context
- Expressway-C must trust the Unified CM and IM and Presence certificates and the Expressway-E certificate while Expressway-E must trust the Expressway-C certificate. in context
- The _cisco-uds SRV records must not resolve outside the internal network or Jabber will not start MRA negotiation through the Expressway-E. in context
- Cisco recommends internal _cisco-uds._tcp.<domain> SRV records but they have not been a requirement since X12.5. in context
- The X15.2 MRA guide requires both Expressway-C and Expressway-E certificates to include the Client Authentication extension. in context
- Public DNS must publish _collab-edge._tls.<domain> SRV records on port 8443 whose targets are the Expressway-E systems. in context
- Cisco recommends a dual-NIC Expressway-E and in that design the Expressway-E address given to Expressway-C is an FQDN resolving to the internal interface IP. in context
- Forward and reverse DNS entries are required for each Expressway-E system when IM and Presence Service is used over MRA (XCP TLS). in context
- The MRA X15.2 requirements chapter lists UDP 36002-59999 as the inbound media range to Expressway-E. disputed in context
- MRA requires at least Expressway X8.1.1 with Unified CM 10.0 and IM and Presence Service 10.0. in context
- Expressway-C and Expressway-E must have separate IP addresses and must not share a NAT address because the firewall cannot tell them apart. in context
- Third-party network load balancers between MRA clients and Expressway-E are not supported. in context
- With self-signed Unified CM certificates TLS verify and secure device registrations cannot both be used; Cisco's remedy is CA-signed Unified CM certificates. in context
- Cisco does not recommend a single-NIC Expressway-E with static NAT; if used the Expressway-E address must be an FQDN resolving to the public IP and the firewall must support NAT reflection. in context
- The MRA guide describes a single common domain served by separate internal and external DNS servers (split DNS) as aligning with Jabber service discovery. in context
- Unified CM must trust the Expressway-C certificate in CallManager-trust and Tomcat-trust and IM and Presence must trust it in cup-xmpp-trust and Tomcat-trust. in context
- The Unified CM default region caps video session bit rate at 384 kbps and the Expressway-C default call bandwidth is also 384 kbps which Cisco warns may be too low for MRA video. in context
- Public DNS must publish _collab-edge._tls.<domain> SRV records so that endpoints outside the network can discover the Expressway-E servers for MRA. in context
- For MRA, the external firewall must allow inbound connections to the Expressway-E on TCP 5061 (SIP), TCP 8443 (HTTPS), TCP 5222 (XMPP) and UDP 36002-59999 (media). in context
- Cisco warns that the Unified CM default region's Maximum Session Bit Rate for Video Calls of 384 kbps may be too low for the expected video quality on MRA-connected devices. in context
Cite this source record
APA
WarmTransfer. (2024, October 15). Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-exwy-mra-guide-x152-requirements
BibTeX
@misc{warmtransfer-cisco-exwy-mra-guide-x152-requirements,
title = {Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/cisco-exwy-mra-guide-x152-requirements},
note = {Cisco Systems, accessed 2026-09-24}
}