Table 37: Cisco VXC VPN operation as determined by VXC VPN Option and Challenge settings
Result after enabling the VXC VPN
feature (with Cisco VXC connected
to the phone)
VXC Challenge setting
VXC VPN Option setting
The phone displays the VXC VPN
Sign In window to prompt the user
to enter a password. If one-time
password is configured on the VPN
concentrator (that is, a new
password is always required to
reauthenticate the tunnel), the user
must enter a password for the Cisco
VXC VPN that differs from the
password that was used for the
phone VPN tunnel.
Challenge (default)
Dual Tunnel (default)
The phone attempts to reuse the
phone VPN credentials for the
Cisco VXC VPN tunnel. Note that
if the VPN concentrator is
configured for one-time passwords,
the attempt fails, and the phone
displays the VXC VPN Sign In
window for the user to enter a
different password from the phone
VPN password.
No Challenge
Dual Tunnel (default)
The phone disconnects the phone
VPN tunnel, and then displays the
Phone VPN Sign In window to
prompt the user to enter a password
and reestablish the phone VPN
tunnel. If the user is on an active
call, the phone waits until the call
ends before tearing down the
tunnel.
Challenge
Single Tunnel
Cisco VXC traffic receives silent
permission to go over the phone
VPN with no challenge.
No Challenge
Single Tunnel
The following table describes how a change in the VXC VPN Option setting alters the operation of the VXC
VPN feature when the feature is already enabled.
Cisco Unified IP Phone 8961, 9951, and 9971 Administration Guide for Cisco Unified Communications Manager 10.0
(SIP)
207
Features, Templates, Services, and User Setup
Cisco VXC VPN Setup
REVIEW DRAFT - CISCO CONFIDENTIAL