Cisco CUCM - Self Provisioning, Feature Groups, User Device Templates, User Profiles - What it all means and how to use it to get zero-touch deployment! - Part 2

CUCM Self Provisioning


Hi Guys

In part 1 of CUCM provisioning we talked about the new features available in CUCM 9 to make life easier for adding users, in continuation of this theme we are going to look at Self-provisioning, which allows the user to provision their own phone. LDAP is used to provide this information.

The feature is available in CUCM 10 and is quite nifty.

If you have not read part 1 of this blog, I strongly recommend you do so before continuing.

Overview

The basic premise of this feature is very similar to a technology many of you will already be familiar with: Cisco TAPS. Cisco TAPS allowed you to bulk insert phones and then, using a UCCX script have users phone a number in order to self-provision their phones. This is like TAPS but with a few important differences:

- You don't need UCCX
- You don't bulk insert the phones.


Configuration

The first thing you will need to do (other than setting up the universal device template and user line template that I already outlined in blog post 1) is configure a CTI route point and assign it a number, this CTI route point doesn't have to be anything special but you should assign it a DN that is reachable by phones configured for auto-registration




Second thing, is to enable auto registration with a CSS that can reach the number you assigned to your CTI Route point


Next, you must create an application user, ensure it is enabled for "Standard CTI Enabled" access control group and also ensure that it controls this CTI device you just created


Once this is done, go to the self-provision section under User Management -> Self provisioning


 Once this is done, you will be prompted to reset the service, obviously this is a good idea.

The final step is to configure our LDAP directory:

Go to your LDAP directory page after configuring your LDAP system and specify a directory containing the users, note you could use filters here to control which users from which area in your business are imported into LDAP, so for example, if you had users in NJ who should receive a CSS that is allowed to call international, you would create a seperate LDAP directory entry for these groups that uses a custom LDAP filter that looks for membership in a particular Windows Group. Or you could place them into a separate OU, the point is that you will need to create multiple LDAP directories.
 
 In the example below I have just pointed to the default AD CN for simplicity


 Next, you will assign the "Feature group" that controls what universal device template and what user line template are assigned to users contained in this LDAP directory.

It's important to select "Apply mask to Synched Telephone numbers to create a new line for the inserted users" also, and enter the mask as you want it to appear based on the imported telephone number field.

Once this is done. Sync the directory, what should happen is that every entry in your LDAP directory with a phone number assigned in LDAP will now create a DN in CUCM that has not yet been associated with a phone:

 When a user first plugs in a phone, and then dials the CTI Route point number (in our case, 9999) they will be prompted to enter the extension of the phone they wish to provision. Once this is done, the phone will be created based on the settings in the line and device template!!

See below an example:




 There you have it!!! Now all you have to do to create a user is simply create it in LDAP, grab a phone, dial 9999 and enter your extension, you could even have the users do this, and the phone will be provisioned!

Finally LDAP integration worth configuring!!

I hope this helps someone out there






10 comments:

  1. The DNs were not created, what did I do wrong? Where should I troubleshoot?

    ReplyDelete
  2. Thanks for sharing this useful information. Everyone can also enhance their skills by doing some IT Certifications like Juniper JN0-1301 exams to improve their competency.

    ReplyDelete
  3. A Great and excellent post shared by admin.
    I like to see more quality content on your website. you explained everything nicely
    If you want to pass Cisco exam in first attempt
    You can get Cisco Business Architecture Specialist Practice Test Questions.

    ReplyDelete
  4. Thanks for sharing this useful information
    Get valid and latest Cisco 500-301 exam dumps with competitive price. our CertificationGenie gives you the questions and answers are available in two easy formats, PDF and Practice software

    ReplyDelete
  5. This is the content I was looking for, Keep up the good work.
    If anyone want Paloalto Networks exam dumps this is your opportunity.

    Palo Alto Networks is a Security Operating Platform Technology company that offer various certifications exams. Palo Alto Networks Certifications enables users to protect networks from cutting edge cyber threats anywhere on a variety of devices. Millions of users use Palo Alto Networks products worldwide. Palo Alto Networks Certifications are designed to reflect the needs of organizations and IT Professionals. A Palo Alto Networks Certified Network Security Engineer (PCNSE) is capable of designing, deploying, configuring, maintaining and trouble-shooting the vast majority of Palo Alto Networks Operating Platform implementations.

    If you want to be successful in Paloalto Networks exams in first attempt
    You can get Palo Alto Networks PCNSE.

    ReplyDelete
  6. Thank you for sharing such great information. can you help me in finding out more detail on CompTIA Certification Exams

    ReplyDelete

  7. dailyblogzone is a leading manufacturing company of commercial playground equipment for parks, schools
    dailyblogzone

    ReplyDelete
  8. We offer safety-tested, premium quality commercial playground equipment. Browse through our inventory and select the play area equipment of your choice kids playground equipment

    ReplyDelete

Popular old posts.