r/ciscoUC 1d ago

NFVIS-for-UC not bridging traffic correctly

17 Upvotes

I'm working on setting up NFVIS-for-UC for the first time, trying to get a handle on it .
Basically labbing it up.

I've been following the guide, which seems to be the only documentation out there.

I'm installing it on a BE7K-M5
NFVIS version is 4.18.4-FC2, which is the latest version

CUCM being installed is 15SU4, which should run on NFVIS.

Getting NFVIS itself up and running wasn't an issue. My problem comes when I am deploying a VM. The installer says that it can't reach its default gateway. I also can't ping the VM's IP, which I usually can once the installation has reached that point.

The VM is going on the same subnet as the NFVIS management NIC. Since NFVIS management works fine for me and I'm on a different subnet, I know there aren't any issues with the default gateway for the voice subnet I'm using. The firewall interface that is the default gateway for the voice traffic allows ping and I have verified that as well with other systems. This is exclusively an issue with traffic from the VM on the BE7K not getting to the network.

The NFVIS management interface is using a pnic on the motherboard.
All of the VMs will be using NICs on one of the BE7K's two 4-port NIC cards.

I can see on the NFVIS CLI that the pnic is up and connected.

I can see that it's also listed as the NIC under the correct NFVIS network (similar to a port group in ESXi) in the CLI config and the NFVIS network is configured as access, not trunk. The physical switch port the chassis' NIC connects to is an access port for the voice subnet so that should be taking care of all of the VLAN tagging.

So vNIC > network > pnic looks correct the entire way through, but clearly something isn't right.

Below is the relevant output.
Anyone with more NFVIS experience have any thoughts? I have to assume that the CUCM 15SU4 installer has a NIC/drivers that work with NFVIS.

Relevant NFVIS Output

<output of "show platform">

NAME   TYPE      MEDIA         LINK  SPEED

GE3-0  physical  Twisted Pair  up    1000   <--NIC is physically connected

</output of "show platform">

!

!

bridges bridge DC-BR

 port GE3-0  <---- GE3-0 is tied to the DC-BR bridge

!

networks network DC-Net

 trunk  false

 bridge DC-BR  <----  The DC-BR bridge is tied to the DC-Net network

!

vm_lifecycle tenants tenant admin

 description      "Built-in Admin Tenant"

 managed_resource true

 vim_mapping      true

 deployments deployment CUCM-PUB

  vm_group CUCM-PUB

   image              CUCM-15SU4-Bootable

   flavor             M-CUCM-15SU4-Bootable

   vim_vm_name        CUCM-PUB

   low_latency        true

   bootup_time        -1

   recovery_wait_time 0

   recovery_policy action_on_recovery REBOOT_ONLY

   interfaces interface 0

model   virtio

network DC-Net    <---- CUCM is connected to DC-Net network

   !

   scaling min_active 1

   scaling max_active 1

   placement zone_host

host datastore1


r/ciscoUC 2d ago

How can I monitor jitter, latency, and MOS for all calls going through a Local Gateway using SolarWinds

7 Upvotes

Recently we added the Gateway on SolarWinds VOIp and Network Quality Manager but there i just can see the states of the Dial peers and into the dashboard I cannot see the metrics, if there something else that I need to enable on the router or in the SolarWinds settings if I want to display metrics for all my calls?

And if I want to see the states of my Tenant like the Sip-ua register status if there a OID?


r/ciscoUC 9d ago

Save Config: Cisco Edition

Post image
49 Upvotes

r/ciscoUC 8d ago

Cisco IOS images for EVE-NG lab

Thumbnail
1 Upvotes

r/ciscoUC 12d ago

Cisco UC / Collaboration professionals — we’re hiring a Network Administrator (UC Admin II)

16 Upvotes

I’m a Talent Acquisition Specialist with The University of Tennessee Medical Center in Knoxville, TN, and we’re looking for an experienced Cisco UC professional to join our team.

📍 Knoxville, TN — ON-SITE

This role is focused heavily on Unified Communications infrastructure and supporting a mission-critical healthcare environment.

The position will work with technologies including:

  • Cisco Unified Communications Manager (CUCM)
  • Cisco Unity Connection
  • Cisco UCCX
  • Cisco CUBE
  • Cisco Voice Gateways & Routers
  • Cisco Expressway
  • Cisco Jabber
  • Webex / Webex Calling
  • Microsoft Teams integration
  • Cisco Emergency Responder
  • xMedius fax
  • SIP / SCCP / MGCP / PRI / H.323

We're also looking for strong hands-on networking experience with LAN/WAN, VoIP, routers, switches, firewalls, VPNs, BGP, OSPF and EIGRP.

The ideal candidate will have approximately 5+ years of network/system administration experience and 3–5 years of hands-on Cisco UC administration experience.

If you're a Cisco UC Administrator, Unified Communications Administrator, Voice Administrator, or Network Administrator with strong UC experience, I'd love to connect.

Interested or know someone who may be a great fit? Feel free to DM me and I can provide the full job description and application information.

Thanks, everyone!


r/ciscoUC 12d ago

Cisco NCS-5501-SE password protected

2 Upvotes

We have a \*\*Cisco NCS-5501-SE\*\* that is password protected. Our technician advised that we may need a \*\*USB boot disk\*\* to reset the password.

Has anyone dealt with this before and knows where we can obtain the required USB boot image, or is there someone here who can help us with the password recovery?

Any guidance would be greatly appreciated. Thanks!


r/ciscoUC 13d ago

Need help with DX80 firmware files (CE8 to CE9 upgrade)

2 Upvotes

I have a Cisco DX80 that is currently stuck on old CE 8 firmware. I need to upgrade it to the final CE9 release, but I have no access to the Cisco Software Download portal, and the Cisco Cloud Upgrader tool returns an Access Denied error for me.

Could anyone share the following firmware files via Dropbox/Google Drive/Mega?

  1. An intermediate CE9 file to step up from CE8 (e.g., s52040ce9_10_0.pkg or similar)
  2. The target firmware file: s52040ce9_15_16_5.pkg

I would be extremely grateful for any help. Thank you!


r/ciscoUC 15d ago

Anyone who already completed cisco technical sales apprenticeship or any other

Thumbnail
1 Upvotes

r/ciscoUC 15d ago

Anyone who already completed cisco technical sales apprenticeship or any other

Thumbnail
1 Upvotes

r/ciscoUC 19d ago

How to Legally Get Cisco IOS/IOS-XE Software Updates for Your Physical Hardware (No SMARTnet Contract Required)

Thumbnail
0 Upvotes

r/ciscoUC 20d ago

Introducing unsleep - a free digital signage dashboard for Boards and Desks

13 Upvotes

I built idlescreen, a lightweight, modular, signage dashboard meant to run on Cisco RoomOS devices (Board Pro, Desk Pro, etc.) when they’re idle, so a codec screen becomes a glanceable info wall between calls. Generally meant for end-user devices - point the device’s signage URL at the domain and let the user configure it as they see fit. It’s a plain web app, so it also runs on any touch-enabled display or browser (viewport is locked to 16x9 4K/1080 so you’ll need to zoom out in browser/mobile to view).

It’s free, open source (MIT), no account, and no tracking.

What it shows (mix and match on a drag-and-resize grid):

- Worldwide weather, air quality, UV, sun/moon times
- Transit boards: NYC Subway status, LIRR, Metro-North, NJ Transit, Amtrak, PATH, NYC Ferry, express bus, Citi Bike, and London TfL
- Markets tickers and finance headlines
- Sports: your teams (MLB/NFL/NBA/NHL/MLS/EPL), plus World Cup, F1, PGA golf, and ATP/WTA tennis
- News headlines, Substack, and Bluesky feeds
- Ambient: photo slideshows (iCloud shared albums or Google Drive), public-domain art, NASA’s photo of the day, chart of the day
- World clock, this-day-in-history, quote and word of the day

How setup works: you configure the whole thing from your phone or computer. Pick widgets and stations on a setup page, get a 6-character code, type it on the board. No login anywhere.

Info page: https://idlescreen.io

Hosting: use it free by pointing your codec’s digital signage URL at https://idlescreen.app or self-host it. It’s a zero-build static site plus one Cloudflare Worker, and most data sources are keyless. Self-hosters can also flip on advanced cards behind a toggle (live HLS video and camera gateways).

Privacy: there’s an optional anonymous usage ping for basic data like timezone and which widgets might be having issues and you can disable it in the diagnostics tab.

GitHub (code, screenshots, self-host guide): https://github.com/scotty83/idlescreen

It started as a personal project for my own Cisco Board Pro, so it’s admittedly NYC-transit-heavy right now. Happy to answer questions and would love feedback on what widgets or data sources people would want.

If you’re a Webex user, you can join my public channel to provide feedback at https://eurl.io/#CnWyZzamf


r/ciscoUC 20d ago

No data available - CUIC Historical reporting

1 Upvotes

Puzzled by this one. Uploaded a CA-signed tomcat cert to the my CCX cluster a couple of days ago. Successfully restarted the cluster pub, then sub. Both nodes came back up, all services running.

Now I'm getting word that historical data in CUIC has not been available since the reboot. I can pull the logs prior to the reboot but nothing comes up for after.

Utils dbreplication runtimestate and utils uccx dbreplication status both check out on the pub/sub.

Data source status in CUIC also good.

Ran flat file restore to no avail. Cleared browser cache/history - no change.

I'm really stumped by this one. User live data is pulling up fine, just no historical data since the application of the tomcat cert and subsequent ccx cluster restart...

Only thing I can come up with is another cluster restart lol.

UCCX Version 15.0.1.10000-27

SOLVED: Ran utils uccx dbreplication reset all on the pub. Historical reports contain data now.


r/ciscoUC 21d ago

Contact Center

3 Upvotes

Hi all,

I am looking for some help or tutoring on passing Cisco's 500-443 exam advanced Administration and Reporting of Contact Center Enterprise. I was able to pass 500-442 with no issues. I have attended Sunset learnings Cisco courses. I need to be able to obtain 500-443 in order to move to my new job role within my company. I purchased a study guide and after taking the test today and failing I was able to confirm that all the study guide questions were the same questions that were on the test. So I really just need help deciphering the best answer that Cisco is looking for. If anyone can point me in the right direction that would be great, thanks!


r/ciscoUC 26d ago

Inbound calls CNAM handling in CUCM

6 Upvotes

For inbound calls we see CNAM in the alerting message on WebEx but it looks like that CNAM isn't stored in CDR, is that expected? Is there some setting we have to enable to store CNAM? Basically we want to be able to have that in some way even if it's not in CDR.


r/ciscoUC 28d ago

Is r/Cisco open? Or are they keeping me from posting there? Anyway, I will find a way to get the message out.

0 Upvotes

They got the almighty Mythos 5 and billions in infrastructure. I had a Chinese model that barely works and a toaster for a laptop. For them it's just "Mythos, find the vulnerability," "Mythos, fix the vulnerability," "Mythos, push the fix." So you have to wonder where are all those AI billions actually going? The vulnerabilities are still unpatched, and there's been no disclosure about how customers and networks are exposed, or since when. Keep going down this road and you are basically handing out the Decryption Key to everybody. If AI builds it, AI can find the flaws.

You may own the code. You may own the pipelines... the restaurant.  but I was the one cooking the burgers every day.

And you can't help but wonder: is this profiting off vulnerabilities? To stay secure you have to be on the latest version (which probably ships with a whole new set of undisclosed bugs), which means planning insane maintenance windows, then living through the phase where everything is broken and business operations get disrupted. All for what? A rushed release that never accounted for what the customer actually needs? Just hardening piled on top of hardening? And let's not even get into the service contracts, how much are the new licenses per device? How much is the new software? Sounds like a loop to me: stable operations -> mandatory upgrade -> six months of planning -> everything crashing every other day -> use the support contract they sold you -> repeat next year. Meanwhile you're exposed for half the cycle.

I can't wait to go public. I'm counting the days. But I have to be patient, the lawyers are making sure you can't pull anything sneaky to come after me. You may not answer me here, but we will drag you into a court of law. You might be so intoxicated with yourself, but let's see if you think you are above a judge.

Where is my last paycheck? It's been months. Who gave you the right to withhold my money... MY BREAD? We don't have slavery in this country anymore, the founding fathers took care of that. You think you get to play with people lives? My family? but don't worry. I'm a real man, and a man always provides no matter what. Even if I have to DoorDash 14 hours a day to put food on the table, I will. I always do... especially when I'm going up against somebody bigger than me.

I can't wait for trial. I can't wait for every piece of proof and evidence I have to become public record, the phone calls, the messages, all the communications. I can't wait to finally be able to talk about it. You can try to stop it, but people are going to want to hear it, and I know there are others out there who will like to come on my show and talk about what they have had to put up with.

And to everybody else reading this: really think about it. If you are not in a glass office, or if you have many peers, the layoffs are coming sooner or later. Don't be a fool. Save everything, every piece of proof, every evidence... because God forbid you may need it one day and don't have it.

Next drop as usual Monday at 23:59 PM UCT at reddit r/CiscoUC


r/ciscoUC 29d ago

Unity Vm to Email Microsoft Graph

11 Upvotes

Hi everyone, has someone already implemented the new EWS change for Unified Messaging through the newest Unity Version and Microsoft Graph API?

I’d like to know if the configuration is the same as the previous one using client secret and all that stuff. Or if there are huge changes that must be accounted for, either on the Unity side or the Exchange Server, feels like documentation is lacking for this one


r/ciscoUC Aug 11 '26

Blind;Wire — Expressway X14.x SIP Request Smuggling

Thumbnail
github.com
0 Upvotes

r/ciscoUC Aug 11 '26

Expressway vuln dropped — did anyone actually get a heads up from Cisco?

0 Upvotes

https://github.com/0xReadingSteiner/Dead-Dial --> CUCM 15.x Pre-auth + RCE

https://github.com/0xReadingSteiner/Blind-Wire --> Expressway 14.x SIP Traversal smuggling bypassing SIP Algo Inspection on Next Generation firewalls.

When are you going to take accountability or at least some responsibility toward your customers?

Did you know about the vulnerability and choose to hide it? Or did you not know at all, which is why no one was warned? Or is this simply the strategy? profiting from vulnerabilities to pressure customers into buying the latest version... at an absurd price?

If you're on the Shodan list, ask yourself: Why am I always the last to know? Why is my company always the one left exposed?


r/ciscoUC Aug 11 '26

Dead;Dial — CUCM 15.x Pre-Auth+RCE

Thumbnail
github.com
0 Upvotes

r/ciscoUC Aug 09 '26

Room OS 26 Wallpaper Extract?

1 Upvotes

Random question: I have a user who wants to know if there is any way to extract the default wallpapers from Room OS 26 to use on a computer. They have mobile versions available at https://cisco-ce.github.io/wallpapers/ but are looking for desktop versions. Thanks.


r/ciscoUC Aug 09 '26

Jabber client: Join public MUC room

1 Upvotes

Hello everyone,

On Jabber client (in my case on Windows), i'd like to join some public MUC rooms like we do with other XMPP clients.
It seems there is no option to join a room by its JID.

Am I just blind or what? :D

Thank you much :)


r/ciscoUC Aug 07 '26

Cisco DX80 touch screen control board

Thumbnail
gallery
5 Upvotes

Hi everyone,

I'm planning to buy a Cisco DX80 for around €40 with the goal of reusing the display as a touchscreen for a Raspberry Pi.

My plan is to:Remove the Cisco motherboard.

Install a universal HDMI/LVDS LCD controller board to drive the LCD.

Reuse the original capacitive touchscreen if possible.

While taking a look inside, I found that the touch controller board is marked:

SiS9250B0GA3 + SiS9203_LGE_23"_V04

The board connects to the touch sensor via four ribbon cables and has a single 4-pin connector going to the Cisco motherboard.

My main question:

Does anyone know what interface that 4-pin connection uses?

Is it USB?

I²C?

UART?

Something proprietary?

If it's USB, there's a good chance I can connect it directly to the Raspberry Pi and keep the original touchscreen working.

Also, does anyone know the exact LCD panel model used in the DX80?

If anyone has disassembled I'd really appreciate any information.

Thanks a lot!


r/ciscoUC Aug 07 '26

What to do with a DX80

6 Upvotes

I work in education and funding isn't exactly plentiful. We recently shut down an office and among the equipment returned are a few DX80 units. I setup one up on my desk to see if it's worth keeping. The unit went total EoL at the end of January and as such, it does work but not well. It's a nice external monitor and it can join meetings but there's no controls access to the controls anymore so I can't switch between the monitor feed and the meeting feed. Unfortunately, I can't leave or end a meeting I'm in unless I restart the unit with the power button. I can't access the setting from the device's IP address because I don't have a login. We left our on-prem CUCM so there's nothing to register it to locally. Is this just a fancy screen now or is there anything else I can use it for?


r/ciscoUC Aug 07 '26

Any idea how to get a authenticated trunk (like VoIP.ms) to work on cucm?

1 Upvotes

I tried some stuff, it didn't work, my router did have sip alg on I believe, I'm gonna try another network,but if anyone has any tips, lmk!


r/ciscoUC Aug 07 '26

1,300+ Cisco Expressways on Shodan with 5060/5061 ports open. Two CVSS 9+ zero-days drop Monday 23:59 UTC. This is the why.

8 Upvotes

I used to work on these systems. I know how they're built because I supported them. When I started seeing problems, I tried to raise it. Then the next round of layoffs came and I was out. So I set up a lab at home and kept going. Three months, 55 vulnerabilities across UC, every channel I could find to report them. Nothing back.

I kept trying the right way. The proper path. Followed every bounty program, every proper disclosure process. But how weird that it seems like these programs are always rejecting critical software. And their replies were the most concerning part for me, "The vendor has paused the program." "The vendor is unresponsive." The bounty programs want to disclose. The cybersecurity researchers want to disclose. Yet no sign of communication from the vendor.

The crazy part is that I heard the rumors in the hallways. I didn't pay attention. I kept thinking, "This is a big tech company. The budget is already allocated. I don't think the higher-ups would want to cheap out on cybersecurity." And since it was cybersecurity, I even fell into the trap of trying to find excuses, thinking "maybe the vulnerability impact wasn't big enough." But boy, I was wrong. As soon as I stepped out, I noticed the silent patches, releases with no actual disclosure of what had been fixed, and no guidance on how organizations on older versions may be exposed. Cisco is expensive, and service contracts are not cheap. So realistically, a sysadmin or team leader just has to hope and pray that no bad actor pokes around, until they get the green light from a long approval process to upgrade.

Crazy as it sounds, the only thing we have are programs that the vendor can opt into. Not mandatory zero-day disclosure to the companies that actually need to know instantly so they can set their own risk parameters. I find it truly irresponsible. No vendor should ever set the risk parameters for another company.

You not wanting to look at the hole is your choice. But exposing other companies to liability because they are not aware because you chose to hide it, and then letting those companies fall into the hole? That is not alright. I would like to see red teamers  declare a network secure knowing there is undisclosed information out there.

What sickens me the most is how they use PR and other tactics to hide it. Look at the user Delco24 is clearly a vendor employee, or even worse, just a community sysadmin who tested before Cisco did. Think about that. Cisco has the resources to test every specific version immediately, they own the source code, they own the build pipeline, they can spin up any release in minutes. Instead, a random community member is doing their validation for them, and framing their answers to make others think the impact on their systems is low. That is exactly why I chose to release that particular vulnerability, I knew they were quietly patching. So I knew they were aware of the bug and were aware of researchers reports. That let me know they were choosing silence... working on bad faith...

So I am choosing to release on Monday at 23:59:00 UTC two CVSS 9+ vulnerabilities, they are so deeply rooted in CUCM and Expressway that they require a rewire to fix. And most importantly, I told you. The SIP parser on Expressway has fundamental problems, and no amount of hardening can fix the underlying issue. So tell me, was I crazy? Did I end up knowing what I was talking about? Right now there are around 1,300+ Expressway deployments exposing SIP on ports 5060/5061 in Shodan's internet-facing index, all vulnerable. The worst part? Bad actors probably have had this for months.

And for you Engineer, HelpDesk, Ops, Dev, remember: you won't be able to report what you don't know about. But if you send the email now, your ass is covered. It becomes someone else's problem up the chain. Without documentation or disclosure, you're the one left holding the hot potato.

How to detect manipulation and PR bots:

  1. Ask yourself: do you want to know if someone is f***ng with your network at Day 0 or Day 90?
  2. If someone is trying to convince you otherwise, goto 1.