
ຄູ່ມືເຈົ້າຂອງ Cisco Reverse Proxy Installer
ເກີນview
The Cisco Reverse Proxy Installer (referred to as RP Installer in this document) is a component of the Cisco Unified CCE solution. It offers a ready-made reverse proxy solution (based on Open Resty Nginx) for Unified CCE, featuring built-in, battle-tested configurations. These configurations can be used to proxy other Unified CCE components and external applications,such as ADFS, which are commonly used when deploying Unified CCE.
The RP Installer has been pre-tested and load-qualified for various usage scenarios across the deployment models supported by the Unified CCE solution.
The RP Installer facilitates access to the Unified CCE solution from the internet and is typically set up to provide VPN-less access to the Finesse Agent Desktop or enable advanced functionalities like digital channels that require direct internet ingress.
The RP Installer is intended to be deployed in a Demilitarized Zone (DMZ) on a customer-provided and hardened host running the RHEL 9.4 Operating System. The pre-configured proxying rules allow for the proxying of the following components through data-driven configuration files:
- Cisco Finesse
- Cloud Connect
- Cisco Unified Intelligence Center
- ຂໍ້ມູນສົດ
- Cisco Identity Service
- Cisco IM&P Server
- Microsoft ADFS 3.0 or 5.0
ເອົາໃຈໃສ່
The term “upstream servers” is used in this guide to refer to all the solution components such as Finesse, CUIC, IdS, and IM&P servers that are configured to be accessed through reverse-proxy
ເງື່ອນໄຂເບື້ອງຕົ້ນ
To configure VPN-less access to the Finesse desktop:
- Reverse Proxy Installer must be 15.0(1) or above
- Finesse, IdS, and Cisco Unified Intelligence Center must be 12.6(2) ES4 or above.
- In coresident deployments, LiveData and Cisco Unified Intelligence Center should be 12.6(2) or above
- Unified CCE and LiveData standalone must be 12.6 (1) or above with the latest ES for the respective versions
- Cisco IM&P Server
- DMZ with internet connectivity must be available to host the reverse-proxy.
ຄວາມປອດໄພ
ຕົວຕິດຕັ້ງ RP ບໍ່ແມ່ນຕົວແທນເປີດ; ມັນກວດສອບການຮ້ອງຂໍທັງໝົດກ່ອນທີ່ຈະສົ່ງຕໍ່ໄປຫາເຊີບເວີທີ່ເໝາະສົມ. ເຊີບເວີຊັ້ນເທິງຍັງບັງຄັບໃຊ້ການພິສູດຢືນຢັນທ້ອງຖິ່ນກ່ອນທີ່ຈະດໍາເນີນການຮ້ອງຂໍ.
Beyond authentication, there are several additional ຄວາມປອດໄພ measures available to protect the solution. Details about security can be found in the Security chapter.
For information about security guidelines, see the Security Guidelines for Reverse-Proxy Deployment in
Security Guide for Cisco Unified ICM/Contact Center Enterprise.
ສໍາລັບຂໍ້ມູນເພີ່ມເຕີມກ່ຽວກັບການພິສູດຢືນຢັນ, ເບິ່ງການພິສູດຢືນຢັນ.
ແຜນທີ່ເຈົ້າພາບ File ສໍາລັບການແປພາສາເຄືອຂ່າຍ
ການນຳໃຊ້ພຣັອກຊີແບບປີ້ນກັບແມ່ນຂຶ້ນກັບການສ້າງແຜນທີ່ file ສະໜອງໃຫ້ໂດຍຜູ້ເບິ່ງແຍງລະບົບເພື່ອກຳນົດຄ່າລາຍຊື່ຂອງການປະສົມປະສານຂອງຊື່ໂຮສ/ພອດທີ່ເບິ່ງເຫັນພາຍນອກ ແລະການສ້າງແຜນທີ່ຂອງພວກມັນໃຫ້ກັບຊື່ເຊີບເວີ ແລະພອດຕົວຈິງທີ່ໃຊ້ໂດຍເຊີບເວີ Finesse, IdS ແລະ CUIC. ແຜນທີ່ນີ້ file ທີ່ຖືກຕັ້ງຄ່າເທິງເຊີບເວີແມ່ນການຕັ້ງຄ່າຫຼັກທີ່ອະນຸຍາດໃຫ້ລູກຄ້າທີ່ເຊື່ອມຕໍ່ຜ່ານອິນເຕີເນັດຖືກໂອນໄປຫາໂຮດແລະພອດທີ່ຕ້ອງການທີ່ໃຊ້ໃນອິນເຕີເນັດ. ສໍາລັບຂໍ້ມູນເພີ່ມເຕີມກ່ຽວກັບການສ້າງແຜນທີ່, ເບິ່ງຂໍ້ມູນການແປພາສາເຄືອຂ່າຍ Populate.
ໝາຍເຫດ
ມັນໄດ້ຖືກແນະນໍາໃຫ້ໃຊ້ອຸປະກອນທີ່ອຸທິດຕົນ web ເຊີບເວີພາຍໃນ LAN ເພື່ອເປັນເຈົ້າພາບແຜນທີ່ file, ແທນທີ່ຈະໃຊ້ຕົວຕິດຕັ້ງ Reverse Proxy ສໍາລັບຈຸດປະສົງນີ້.
ສໍາລັບການຮ້ອງຂໍທັງຫມົດທີ່ເຂົ້າມາໂດຍຜ່ານ reverse-proxy, ເຄື່ອງແມ່ຂ່າຍ Finesse, IdS, ແລະ CUIC ກວດເບິ່ງແຜນທີ່ໂຮດ file, to translate the internal host names and ports that are used on the LAN. They are translated to the publicly resolvable host names and ports that have to be used on the internet. This mapping file, ເອີ້ນວ່າແຜນທີ່ Proxy-config file, is the key configuration that allows the clients connected over the reverse proxy to be redirected to the required hosts and ports that are used on the internet.
ແຜນທີ່ Proxy-config file ສາມາດຕັ້ງຄ່າໄດ້ໂດຍການໃຊ້ CLI ທີ່ມີຢູ່ໃນເຄື່ອງແມ່ຂ່າຍ Finesse, IdS, ແລະ CUIC. ສໍາລັບລາຍລະອຽດກ່ຽວກັບແຜນທີ່ file ຮູບແບບ ແລະຂໍ້ມູນທີ່ກຳນົດຄ່າ, ອ້າງອີງໃສ່ພາກ Populate Network Translation Data. ສໍາລັບລາຍລະອຽດກ່ຽວກັບ CLI ທີ່ໃຊ້ໃນການຕັ້ງຄ່າ file, refer to the utils system reverse-proxy config-uri CLI in the topic Configure Proxy Mapping by Using CLI.
ແຜນທີ່ Proxy-config file ສາມາດຕັ້ງຄ່າໄດ້ໂດຍການໃຊ້ CLI ທີ່ມີຢູ່ໃນເຊີບເວີ Unified CCX ແລະ Cisco Collaboration Platform servers. ສໍາລັບລາຍລະອຽດກ່ຽວກັບແຜນທີ່ file ຮູບແບບ ແລະຂໍ້ມູນທີ່ຖືກຕັ້ງຄ່າ, ອ້າງອີງໃສ່ພາກຂໍ້ມູນການແປພາສາເຄືອຂ່າຍ Populate ໃນ Cisco Unified Contact Center Express Administration and Operation Guide. ສໍາລັບລາຍລະອຽດກ່ຽວກັບ CLI ທີ່ໃຊ້ໃນການຕັ້ງຄ່າ file, refer to the Configure Proxy Mapping by Using CLI section in Cisco Unified Contact Center Express Administration and Operations Guide available
at https://www.cisco.com/c/en/us/support/customer-collaboration/unified-contact-center-express/products-maintenance-guides-list.html..
ການຄຸ້ມຄອງພອດ
ຫນຶ່ງໃນລັກສະນະການອອກແບບຕົ້ນຕໍໃນການນໍາໃຊ້ຕົວແທນ reverse ແມ່ນໂດເມນແລະພອດທີ່ໃຊ້ໃນການເຂົ້າເຖິງແອັບພລິເຄຊັນ. ລັກສະນະເຫຼົ່ານີ້ແມ່ນຂຶ້ນກັບກັນແລະມີອິດທິພົນເຊິ່ງກັນແລະກັນໃນເວລາທີ່ການອອກແບບການນໍາໃຊ້.
ຕົວແທນ reverse ຈະຕ້ອງສາມາດກໍານົດໄດ້, ທີ່ເຄື່ອງແມ່ຂ່າຍຂອງ upstream, ການຮ້ອງຂໍຂາເຂົ້າສາມາດຖືກສົ່ງຕໍ່ໄປບ່ອນທີ່ຄໍາຮ້ອງຂໍຂາເຂົ້າຄວນຈະຖືກສົ່ງຕໍ່. ນີ້ສາມາດເຮັດໄດ້ໂດຍການປ່ຽນພອດຫຼືຊື່ເຈົ້າພາບທີ່ໃຊ້ໃນການເຂົ້າເຖິງແອັບພລິເຄຊັນ. ໂດຍພື້ນຖານແລ້ວ, ການປະສົມປະສານຂອງໂຮດແລະພອດຕ້ອງເປັນເອກະລັກເພື່ອໃຫ້ຕົວແທນຈໍາແນກຄວາມແຕກຕ່າງແລະເສັ້ນທາງການຈະລາຈອນໄປຫາອົງປະກອບຕົ້ນນ້ໍາທີ່ຖືກຕ້ອງ, ແລະມັນເປັນຂໍ້ກໍານົດສໍາລັບຕົວແທນທີ່ຈະເລີ່ມຕົ້ນຢ່າງຖືກຕ້ອງ.
ເຫຼົ່ານີ້ແມ່ນທາງເລືອກທີ່ມີໃນການອອກແບບໂດເມນແລະການເຂົ້າເຖິງພອດ:
- Use a common domain and differentiate application access using multiple ports.
- Use a common port and differentiate application access using multiple domains
ເມື່ອໂດເມນແລະການແຜ່ກະຈາຍພອດຖືກກໍານົດ, ຂັ້ນຕອນຕໍ່ໄປນີ້ຈໍາເປັນຕ້ອງໄດ້ປະຕິບັດ:
- Proxy map configuration has to be changed to match the port and domain required. See Configure Proxy Mapping by Using CLI.
- The respective upstream component environment configuration in the reverse proxy installer has to be configured with the required hostname and port, see Configure deployment environment configurations
ການນໍາໃຊ້ໂດເມນທົ່ວໄປທີ່ມີພອດຫຼາຍ
ຕໍ່ໄປນີ້ example ສະແດງໃຫ້ເຫັນວິທີການຫຼາຍເຄື່ອງແມ່ຂ່າຍຂອງຄໍາຮ້ອງສະຫມັກສາມາດໄດ້ຮັບການຕັ້ງຄ່າໂດຍນໍາໃຊ້ຮູບແບບການເຂົ້າເຖິງນີ້:
- FinesseA = ReverseProxyDomain.com:8445
- FinesseB = ReverseProxyDomain.com:8446
- Finesse1A = ReverseProxyDomain.com:8447
- Finesse2B = ReverseProxyDomain.com:8448
The following are the benefits of using multiple ports:
- More granular packet level rate-limits applicable to each application can be applied at the ingress point to control rate-limits. Domain-level access means that the rate-limits can’t be granular.
- A single-domain requires only a single SSL certificate to access the application. It could be a factor in reducing costs, unlike a multiple-domain application which requires a wildcard certificate.
ຕໍ່ໄປນີ້ແມ່ນ disadvan ໄດ້tages in using multiple ports:
- Certain network deployments like CDNs don’t support custom ports.
- Security devices that automatically apply security rules might require custom configurations with non-standard ports.
- Multiple ports must be opened in the DMZ firewall (10–15 ports are required for a standard 2k deployment). This isn’t recommended by the network security teams.
- There’s an increased overhead regarding the port manageability.
- Deploying new instances of the application requires firewall/network changes.
ໝາຍເຫດ
Ports other than the ones mentioned in the Proxy Map must be blocked and shouldn’t be available for access on the reverse proxy host. This must be blocked at the ingress point as the proxy doesn’t currently have rules to block this access at network level.
The Cisco provided installer supports running multiple instances which cater to different sets of upstream servers, to aid in ease of maintenance. Multiple instances of the installer don’t allow to use the same ports across different instances of the proxy. Only one process can bind to the same TCP port.
Consider the above two points when deciding the port management strategy against proxy installer configuration.
ການນໍາໃຊ້ພອດທົ່ວໄປແລະກັບຫຼາຍໂດເມນ
ຕໍ່ໄປນີ້ example illustrates how multiple application servers can be configured using this access pattern.:
- FinesseA = FinesseA-ReverseProxyDomain.com:443
- FinesseB = FinesseB-ReverseProxyDomain.com:443
- Finesse1A = Finesse1A-ReverseProxyDomain.com:443
- Finesse2B = Finesse2B-ReverseProxyDomain.com:443
ການຕັ້ງຄ່າພອດດຽວຈະປະຕິເສດຂໍ້ດີ ແລະຂໍ້ເສຍທີ່ລະບຸໄວ້ຂ້າງເທິງດ້ວຍການຕັ້ງຄ່າພອດຫຼາຍອັນ.
ໝາຍເຫດ
Supporting a single port of access requires Unified Intelligence Center and LiveData components to be on 12.6(2)versions.
ການຕັ້ງຄ່າ DNS ສໍາລັບ Finesse, IdS, ແລະເຄື່ອງແມ່ຂ່າຍ CUIC
ແຕ່ລະ Finesse, IdS, CUIC, IM&P, ແລະເຊີບເວີອົງປະກອບພາກສ່ວນທີສາມທີ່ສອດຄ້ອງກັບແມ່ຂ່າຍທີ່ຕ້ອງການເຂົ້າເຖິງອິນເຕີເນັດຈະຕ້ອງສາມາດແກ້ໄຂໄດ້ຈາກອິນເຕີເນັດ. ນີ້ຮຽກຮ້ອງໃຫ້ມີຊື່ໂຮດແລະພອດທີ່ກ່ຽວຂ້ອງເຊິ່ງສາມາດແກ້ໄຂໄດ້ຈາກອິນເຕີເນັດເພື່ອເຮັດແຜນທີ່ກັບພອດສາທາລະນະແລະ IP ທີ່ກົງກັນຂອງຕົວແທນ reverse-proxy ເພື່ອໃຫ້ການຈະລາຈອນຖືກສົ່ງໄປຫາເຄື່ອງແມ່ຂ່າຍອົງປະກອບທີ່ກ່ຽວຂ້ອງ.
DNS registration of the publicly resolvable host names and the corresponding IP addresses is mandatory before the requests reach the reverse-proxy.
ໃບຢັ້ງຢືນ SSL
For the hostnames that are configured, corresponding to each unique hostname that is used by the internet client, the respective certificates must be acquired and configured on the reverse-proxy. Even though self signed certificates are supported, they are risky because the users access directly from the internet. The clients can be more secure by using CA-signed certificates. The best practice is to get CA certificates for proxy servers and third-party-gadget servers.

ເອກະສານ / ຊັບພະຍາກອນ
![]() | Reverse Proxy Installer |
ເອກະສານອ້າງອີງ
- Cisco Unified Contact Center Enterprise - ຄູ່ມືການຕັ້ງຄ່າ - Ciscowww.cisco.com
- Cisco Unified Contact Center Express - Maintain and Operate Guides - Ciscowww.cisco.com
- ຄູ່ມືຜູ້ໃຊ້manual.tools
