IdoNotes (and sleep)

by Chris Miller at 01:27:58 PM on Friday, November 17th, 2006
I had to gather my thoughts on it with all the pings/emails/podcasting and such.  With much discussion about why they picked WebSphere, will it ever run on Domino, why does it require so much hardware out there, we need to focus on the real issue, installation and deployment.  We can blow that smoke till we are blue (bad choice of colors with IBM involved) in the face.  Currently, there is no talks of any other path for RTC than what you see.  It takes whatever hardware it takes.  Now, I am not saying I agree here either.  This area is not the topic of the debate at the moment.  But more like how do we get this thing running?  So I started compiling a checklist.  Not of the step by step, I worked enough helping build those during the beta and they are documented now.  But more of key items to consider and this you should/shouldn't do.  Off we go on revision 1 below.  It was too big to leave on the main page in entirety.  Just click the Read More that is to follow and you get the info on the following:
  • Installation
  • Security
  • Management





Installation
  • By my 5th time now installing it, I can be done in a couple hours total, including SSL and network below
  • Following the documentation steps one by one is key.  They are in order for a reason
  • Do not forget to install the WebSphere fixpack before launching the system
  • Do realize that the initial selection for LDAP should be verified, tested and bound before tossing it in and wasting time
  • Do make the local community connection first before any Clearinghouse attempts
  • Do load the CF1 update for Sametime or you are totally wasting your time overall.  This update needs to be done for the Sametime Connect clients also by the way
  • Do trust the RTC Gateway in stconfig on your Sametime server with the address that it connects to Sametime as, not the external IP address.
  • Do restart Sametime after trusting the gateway address
  • Forget about seeing AOL users as soon as it is up with the wait for provisioning (already had that one)
  • Make sure the system is running and open to the Internet before requesting provisioning and then don't touch it.  Really don't/  If it is not there when they attempt to contact the system and provision, you go back into the cycle
  • Make sure you restart your Sametime client after all connectivity is reached to make sure you get the option to add external users
  • Do make sure you allow for the adding of external users into your Sametime policy
  • Do plan on restarting RTC numerous times as you follow the instalaltion path
  • Do use the proper bin directory specified in the documentation, as there is more than one in WebSphere to be found
  • Do a full restart of the box before going live to clean up anything that did not get cleaned up during install and restarts

Security
  • We couldn't stress this enough on the podcastlet this week
  • Do not forget to obtain a public SSL key form a trusted root.  Do not attempt to use a self signed certificate on WebSphere once into production.  AOL won't take it, no way , no how.
  • You must secure the WebSphere, LDAP, DB2 first
  • Then you must secure the access rights globally and per protocol
  • You must create and apply the right policy tree to the necessary users.  Don't skimp in this planning stage.  You need to work a Sametime policy map plus the mapping of the entire gateway, coupled with each protocol connection
  • You must make some management decisions on placement of the gateway in your infrastructure.  NAT provides some limitations so a DMZ approach might be your path.  Unidirectional presence issues versus bidirectional come into play if you choose a full behind the firewall deployment

Management
  • Do plan on having some monitoring put in place.  Once introduced users will be quite upset if it stops.  This is only the first rev of the production code, so keep that in mind before your skivvies are in a bunch
  • Do plan on visiting for updates and patches as they become available
  • Do not leave trace logging on for any extended period of time on the RTC Gateway.  It constantly chatters with AOL and such for SIP connectivity and presence.  Plus when users subscribe
  • Please manage timeouts and settings for performance.  Do not expect it to continue to perform awesome when you start adding lots of users and never tweak a thing
  • Please configure LDAP appropriately for binding, SSL and filtering for performance

  • 1) So let’s talk RTC Gateway
    Created by Volker Weber at 11/17/2006 2:38:08 PM email | website

    Sounds like a kit car or a portal install to me.

  • 2) re: So let’s talk RTC Gateway
    Created by Chris Miller at 11/17/2006 3:38:55 PM email | website

    A kit car that needs a lot of horsepower instead of giving it in return

  • 3) Did IBM raise unreasonable expectations?
    Created by David Schaffer at 11/17/2006 4:49:36 PM email | website

    Everything I read made it sound like RTC was going to be a standard part of Sametime, not a major engineering project. See for example { Link }

    Since Sametime, at least 7.0, is a fairly simple install and not very demanding on hardware for IM, I feel mislead.

  • 4) So let’s talk RTC Gateway
    Created by Chris Miller at 11/17/2006 8:34:48 PM email | website

    @3) Think about the major reverse enginering though. Each provider has their own idea of SIP and the gateway proxies that information. By making them plug-ins in this architecture, they expanded to multiple providers quickly. By not plugging that into Sametime, an engine that really hasn't been updated much except to add features (I say that lightly pointing out that the client got most of the fixes and changes here), you are still talkig about Sametime server code that has been around for a long time.

    While I aggre and wish it could run on Sametime in some fashion, I can see where they are headed in the idea.

    I read the link but it gave no indicaton of complexity or platform for the gateway unfortunately. Maybe they just didn't want to make that leap on that marketing page.

    You are right, Sametime install for the server is quite simple at this point. I think they met thier goal by making it free in one way, but added a lot of effort in the other.

  • 5) So let’s talk RTC Gateway
    Created by Troy Fulkerson at 11/30/2006 11:00:23 AM email |

    Chris, I have installed ST CF1 (which I did a couple of weeks ago to play with the mobile client, which works well), the RTCGW (while many steps, the documentation is great), and finally the patch for the client. I filled out the Provisioning forms for AOL and Yahoo, and I am currently waiting on that. Now, per the install instructions, I turned on the policy check box for allow external contacts, and added the Community Gateway document with the defaults of True. But my client does not show the External Contact checkbox on the Add Contact dialog. Will I have to wait for the provising to complete before I will see that? Thanks.

  • 6) re: So let’s talk RTC Gateway
    Created by Chris Miller at 12/5/2006 4:32:50 PM email | website

    Nope, you shouldnt have to wait for the provisioning Troy. It should show riht away if you applied it correctly to the policy and have restarted and received the new policy


blog comments powered by Disqus

Entries by Month

Links by Category

Notes Tip Sites

Music Sites

Recent Comments

Yes this is a blatant theft of the outline that Jess uses on her page, but I asked permission. Why?? Because I am a hardcore admin and can make ugly tables to make you developers frustrated, but this was too nice to pass up.

Also Known As: Chris Miller (when awake)

Boring Certifications: (only because someone asked twice)

  • Domino 7 Certified Security Administrator
  • PCLP ND8
  • PCLP ND7
  • PCLP ND6
  • PCLP R5
  • PCLP R4
  • Workplace Collaboration Services 2.5 - Team Collab and Messaging (retired)
  • CLP Collaboration (soon to be retired Aug 2006)
  • random former R4 exams
  • CLI for numerous admin areas including Domino, Sametime and Workplace
  • CLP Insane

Yes, I write some of those dreaded admin cert exams you take. I won't say which ones so you don't come looking for me, but I will say they are the real good recent ones that have been coming out.

Weapons/Equipment:

  • At work an IBM thing
  • At home a plethera of 6 machines with various Windows versions and Red Hat on a wired/wireless LAN
  • A Wii
  • An 8830 Blackberry
  • A Toshiba E740 with 802.11b (yes geek toy)
  • An Apple 40GB iPod that is filled to the brim
  • I cannot even list all of the items I carry I found
  • Compaq RioPort MP3 player (now in storage)
  • An EBook (REB1100) also for travel (Love that darn thing)
  • Verizon and they always seem to know how to find me, damn cell

Animals:

One dog, a Puggle. He eats anything that includes stuffing. Anything

Music:

Non-stop. At my desk, in my car, walking to work and back to my car downtown. In the house there is a crazy zoned set-up for you home automation geeks.

I am a self-proclaimed MP3 fiend, to which I have tried rehab 4 billion times to no avail. Next is the MP3 hard-drive for the car that I found. Now what kind of music you ask? I will never tell.

Languages:

  • Incredibly fast English
  • Very slow Spanish
  • Emoticon-ese
  • Learning Korean
  • HTML
  • Advanced Sarcasm

Geek class special abilities:

  • Notes/Domino overdrive
  • Workplace
  • Sametime
  • Active Directory (huh? kidding)
  • Quickplace
  • LMS, LVC and the other L's of elearning
  • Windoze junk
  • MS Exchange versions
  • LAN
  • TCPIP
  • Server Iron
  • Yeah, yeah it goes on some

Skills:

Get back to you here

Spells:

Hershey’s Stomach of Holding: Jess and I are fighting over who eats more chocolate.

Character Bio:

This will take far more time than I have today. I will start with I was born and still live in St. Louis, MO. Even though for a couple years I was never, ever here and always on the road, this is smack in the middle of the US. Everything is just a few hour flight. That part is nice. No beach/ocean/coast isn't the best. But with the travel I make up for it.

Don't Panic

Looking to find me in person? Here is where I am and will be.





Email Newsletter icon, E-mail Newsletter icon, Email List icon, E-mail List icon Sign up for the IdoNotes Newsletter


Subscribe to the feed Contact via Email Me on Twitter  The IdoNotes Network on Facebook Join me on Google Buzz/Talk/Reader Connect on Skype

Connect on LinkedIn  Join me on TripIt My bookmarks on Diigo Location on Foursquare The IdoNotes Network on YouTube My photos on Flickr

Search this site
Custom Blogger Search
Custom Sametime Search
Help customize results

Installing and Administrating the Sametime Gateway
Book Cover
This blog is hosted by


Copyright © 2004, IdoNotes
Designed by Sean Burgess
Comments? Queries?Contact the webmaster
Powered by DominoBlog, ver. 3.0.2