46-5
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 46 Configuring Cisco Unified Presence
Information About Cisco Unified Presence
XMPP Federation Deployments
Figure 46-4 provides an example of an XMPP federated network between Cisco Unified Presence
enterprise deployment and an IBM Sametime enterprise deployment. TLS is optional for XMPP
federation. adaptive security appliance acts only as a firewall for XMPP federation; it does not provide
TLS proxy functionality or PAT for XMPP federation.
Figure 46-4 Basic XMPP Federated Network between Cisco Unified Presence and IBM Sametime
There are two DNS servers within the internal Cisco Unified Presence enterprise deployment. One DNS
server hosts the Cisco Unified Presence private address. The other DNS server hosts the Cisco Unified
Presence public address and a DNS SRV records for SIP federation (_sipfederationtle), and XMPP
federation (_xmpp-server) with Cisco Unified Presence. The DNS server that hosts the Cisco Unified
Presence public address is located in the local DMZ.
For further information about configuring Cisco Unified Presence Federation for XMPP Federation, see
the Integration Guide for Configuring Cisco Unified Presence Release 8.0 for Interdomain Federation:
http://www.cisco.com/en/US/products/ps6837/products_installation_and_configuration_guides_list.ht
ml
Configuration Requirements for XMPP Federation
For XMPP Federation, adaptive security appliance acts as a firewall only. You must open port 5269 for
both incoming and outgoing XMPP federated traffic on adaptive security appliance.
XMPP
Client
(Tom)
277887
Internet
CUCM
CUCM
Enterprise X Enterprise Z
DMZ DMZprivate private network
ASA functions as:
• Firewall
• Open Port 5269
Passthrough for
XMPP Requesting
No Termination
of connections
*ASA
8.0
XMPP
CUP (US)
CUP
CUP
CUP (UK)
CUP
CUP
Inter-cluster
communication
*Cisco Adaptive Security Appliance
Sametime
(Bob)
Sametime
(Bill)
IBM
Sametime
Gateway
Directory
IBM
Sametime
Gateway
IBM
Sametime
Server
XMPP
Client
(Ann)