Manual

Table Of Contents
The VCS Expressway can be added to Cisco TMS with the IP address 10.0.10.2 (or with IP address 64.100.0.10 if FW
A allows this), since Cisco TMS management communications are not affected by static NAT mode settings on the
VCS Expressway.
Why We Advise Against Using These Types of Deployment
For deployments that use only one NICon the VCS Expressway, but also require static NAT for the public address, the
media must "hairpin" or reflect on the external firewall whenever media is handled by the VCS Expressway's back to
back user agent (B2BUA).
For all calls coming in on a Unified Communications Traversal Server zone, or another zone where SIPMedia
encryption mode is not Auto, the VCS Expressway's B2BUAcould be engaged to decrypt or encrypt the media
packets. In these deployments, the B2BUAsees the public IPaddress of the VCS Expressway instead of its private
IPaddress, so the media stream must go through the network address translator to get to the private IPaddress.
Not all firewalls will allow this reflection, and it is considered by some to be a security risk.
Each call where the B2BUAis engaged will consume three times as much bandwidth as it would using the
recommended dual NICdeployment. This could adversely affect call quality.
Figure 15 Media Path in Dual NICStatic NAT Example (Recommended)
72
Cisco VCS Expressway and VCS Control - Basic Configuration Deployment Guide
Appendix 4: Advanced Network Deployments