3. For the Authentication realm, choose from the set of configured SIP domains to determine the traversal
zone through which credential checking is delegated.
Additional information
n The system clocks on the VCS Control and the VCS Expressway must be within 100 seconds of each
other. We recommend that all VCSs are configured to use a common NTP server.
n The VCS Expressway can still perform "local" non-delegated authentication for specific domains. If this is
required, ensure that:
l Those domains have Traversal zone for delegated credential checking set to Do not delegate.
l The relevant authentication mechanisms are configured on the VCS Expressway.
n The VCS Control can still perform authentication in the normal manner, as well as providing a delegated
credential checking service for the VCS Expressway. Note that:
l The NTLM protocol challenges setting on the VCS Control only applies if the VCS Control itself is
making an authentication challenge.
l The authentication policy configuration on the traversal client on the VCS Control has no effect on the
delegated credential checking requests received by the VCS Control.
Enabling delegated credential checking does not affect any other message routing; there is no need to
amend any existing transforms, search rules and so on.
Cisco VCS Administrator Guide (X8.1.1) Page 111 of 507
Device authentication
About device authentication