4.1 Partitions and Calling Search Spaces (CSS)
Key Takeaways
Partitions segregate dialable entities such as directory numbers, route patterns, and translation patterns into administrative groups, while Calling Search Spaces (CSS) define prioritized lists of partitions accessible to a device or line.
CUCM digit analysis uses the closest-match (longest match) rule: when a dialed number matches patterns in several partitions of the CSS, the pattern that matches the fewest possible digit strings wins, regardless of partition order.
When two matching patterns share identical length and specificity, the pattern residing in the partition positioned higher (earlier) in the Calling Search Space wins.
Effective search space concatenation places Line CSS partitions ahead of Device CSS partitions (Effective CSS = Line CSS + Device CSS), enabling granular privileges for shared lines and shared physical endpoints.
The Null Partition (
<None>) is accessible by all devices regardless of CSS configuration, but is evaluated only as a last resort after all explicitly assigned CSS partitions have been searched.
4.1 Partitions and Calling Search Spaces (CSS)
In Cisco Unified Communications Manager (CUCM), call routing decisions depend entirely on two foundational constructs: Partitions and Calling Search Spaces (CSS). Together, they establish a multi-tenant, policy-driven call routing architecture that governs which endpoints, gateways, trunks, and applications can reach specific internal and external destinations.
1. Foundational Architecture: Partitions vs. Calling Search Spaces
A classic physical security analogy illustrates the relationship between Partitions and Calling Search Spaces:
- Partition (The Lock): A logical container or grouping mechanism applied to addressable destinations. Assigning a partition to an entity locks that entity so that only callers possessing the appropriate key can dial it.
- Calling Search Space (The Keyring): An ordered, prioritized collection of partitions assigned to a calling party (such as an IP phone line, physical device, voice gateway port, or SIP trunk). The CSS defines which partitions the caller can search and unlock.
Dialable Entities Residing in Partitions
Partitions can be assigned to virtually any addressable target within the CUCM database, including:
- Directory Numbers (DNs) on IP phones, softphones, and analog ports
- Translation Patterns and Transformation Patterns
- Route Patterns and SIP Route Patterns
- Hunt Pilots and Call Park numbers (Standard and Directed)
- Meet-Me conference numbers and Call Pickup groups
- Cisco Unity Connection voice messaging ports and CTI Route Points
If an entity is created without specifying a partition, CUCM automatically places it into the Null Partition (designated in the interface as <None>).
2. Digit Analysis Engine and Matching Precedence
When a user enters digits or an ingress SIP trunk receives an INVITE with an initial Request-URI, the CUCM Digit Analysis (DA) engine evaluates the dialed digit string against the patterns contained within the caller's effective search space. Digit analysis follows two strict evaluation criteria: the Longest Match Rule and the Equal-Length Tie-Breaker Rule.
The Longest Match Rule (Maximum Specificity)
The fundamental law of CUCM digit analysis states: the closest match, meaning the pattern that matches the fewest possible digit strings, always wins, regardless of the order of partitions in the Calling Search Space. Cisco calls this the closest-match rule; it is often taught as the longest-match rule.
For example, suppose a Calling Search Space contains two partitions in this exact order:
Corporate_PT(listed first)Branch_PT(listed second)
Assume the following patterns exist in these partitions:
Corporate_PTcontains the wildcard pattern2XXX(matches any 4-digit number starting with 2).Branch_PTcontains the exact pattern2001(matches only 2001).
When a caller dials 2001, both patterns match. However, 2001 in Branch_PT matches exactly one string, whereas 2XXX in Corporate_PT matches 1,000 strings (2000 through 2999). Even though Corporate_PT is listed first in the caller's CSS, CUCM selects 2001 in Branch_PT because specificity overrides partition ordering.
Equal-Length Matching Rule (CSS Order as Tie-Breaker)
When two or more matching patterns possess the exact same length and specificity, CUCM cannot distinguish between them based on digits alone. Under this condition, CUCM applies the partition order within the Calling Search Space as the deterministic tie-breaker:
- The pattern residing in the partition listed earlier (higher priority) in the CSS wins.
- The pattern residing in a subsequent partition is ignored.
Digit Analysis Decision Matrix
| Dialed String | Pattern in Partition A (1st in CSS) | Pattern in Partition B (2nd in CSS) | Selected Pattern | Governing Rule |
|---|---|---|---|---|
4100 | 4XXX | 4100 | 4100 (in B) | Longest Match: Exact pattern 4100 has higher specificity than 4XXX, overriding CSS order. |
4250 | 4[2-5]XX | 42XX | 42XX (in B) | Closest Match: 42XX matches 100 strings while 4[2-5]XX matches 400, so 42XX wins even though its partition is listed second. |
5000 | 5XXX | 5XXX | 5XXX (in A) | CSS Priority: Identical patterns of equal length and specificity; Partition A appears first in CSS. |
914085550199 | 9.1[2-9]XX[2-9]XXXXXX | 9.! | 9.1[2-9]XX[2-9]XXXXXX (in A) | Longest Match: Fixed 12-digit NANP pattern has higher specificity than variable-length repeat wildcard !. |
3. Line CSS and Device CSS Concatenation
In CUCM, Calling Search Spaces can be applied at two distinct configuration tiers on every IP phone:
- Line CSS: Assigned directly to the Directory Number (DN) under the line configuration.
- Device CSS: Assigned to the physical endpoint under the phone device configuration.
The Concatenation Rule
When an endpoint originates a call, CUCM combines both configurations into a single Effective Calling Search Space. The concatenation follows a strict, non-configurable architectural order:
Partitions assigned to the Line CSS are placed at the beginning of the search space, followed immediately by the partitions assigned to the Device CSS. If a partition is listed in both the Line CSS and the Device CSS, CUCM drops the duplicate entry, keeping only the first occurrence from the Line CSS.
Line CSS: [ Internal_PT, Local_PT ]
Device CSS: [ LongDistance_PT, International_PT ]
---------------------------------------------------------------------------
Effective: [ Internal_PT, Local_PT, LongDistance_PT, International_PT ]
Shared Line and Shared Device Architectural Use Cases
Concatenating Line and Device CSS enables powerful policy enforcement across shared lines and shared physical hardware:
- Shared Device Policy (Lobby / Common Area Phones): An enterprise deploys phones in public lobbies and conference rooms. The organization wants to restrict these devices to internal and local emergency calls only, regardless of who dials. By leaving the Line CSS empty (or restricted) and assigning a restrictive Device CSS containing only
Internal_PTandEmergency_PT, any line on that device is physically barred from placing toll or international calls. - Shared Line Across Distinct Devices: Directory Number
3001(assigned to an executive) is shared between two physical phones: Phone A on the executive's desk and Phone B in a public conference room.- DN
3001has a Line CSS containingInternal_PTandExecutive_Toll_PT. - Phone A has a Device CSS containing
International_PT. - Phone B has a Device CSS containing
Restricted_PT. - Result: Calling from Phone A enables internal, toll, and international calls. Calling from Phone B allows internal and toll calls (inherited from the executive Line CSS), but international dialing is blocked because Phone B's Device CSS lacks
International_PT.
- DN
Line vs. Device CSS Precedence Summary
| Design Component | Configuration Scope | Concatenation Position | Primary Architectural Purpose |
|---|---|---|---|
| Line CSS | Directory Number (DN) | Beginning of search list | Identifies who is calling (user privileges, class of service, executive access). |
| Device CSS | Phone (device) configuration | End of search list | Identifies where the call originates (site location, physical restrictions, local gateway access). |
| Effective CSS | Dynamic runtime engine | Line partitions + Device partitions | Deterministic search list evaluated by CUCM Digit Analysis. |
4. The Null Partition (<None>) and Security Boundaries
The Null Partition (represented as <None> in CUCM administration) is a default system partition with unique properties:
- Universal Accessibility: Any calling entity can reach patterns in the Null Partition, even if the calling entity has its Line CSS and Device CSS set to
<None>. - Evaluation Order: Digit analysis searches the Null Partition last. CUCM checks all explicitly listed partitions in the Effective CSS first. Only if no matching pattern is found in any CSS partition does digit analysis inspect the Null Partition.
- Toll Fraud Hazards: If an administrator creates an outbound Route Pattern (such as
9.@or9.1[2-9]XX[2-9]XXXXXX) or an unauthenticated SIP trunk and leaves the partition set to<None>, any device in the enterprise—including unauthenticated public phones, auto-attendant transfer legs, and external callers reaching an open transfer prompt—can dial outbound toll numbers. Best practice mandates placing all dialable patterns into dedicated, explicitly named partitions.
5. Time-of-Day (ToD) Routing Architecture
Time-of-Day (ToD) routing dynamically alters call routing behavior based on the date, day of week, and time of day. In CUCM, ToD routing is not configured on route patterns or directory numbers directly; instead, Time Schedules are assigned to Partitions.
Components of Time-of-Day Routing
ToD routing relies on two distinct configuration elements under Call Routing > Class of Control:
- Time Period: Defines a discrete time window, such as
08:00 to 17:00, active onMonday, Tuesday, Wednesday, Thursday, Friday. Time periods can also specify fixed calendar dates (e.g., New Year's Day holiday:January 1 to January 1). - Time Schedule: A logical container that groups one or more Time Periods. For example,
Normal_Business_Schedulemight contain two Time Periods:Weekday_Hours(Mon-Fri 08:00-17:00) andSaturday_Hours(Sat 09:00-13:00).
Dynamic Partition Activation
When a Time Schedule is associated with a Partition, that partition's availability to the Digit Analysis engine becomes dynamic:
- In-Schedule: During defined time periods, the partition is Active. CUCM includes the partition in digit analysis evaluation.
- Out-of-Schedule: Outside defined time periods, the partition becomes Inactive (Dormant). The Digit Analysis engine completely bypasses the partition, behaving as if the partition does not exist in the caller's CSS.
[Incoming Call to 5000 (Main Support Line)]
|
v
[Check Caller's CSS]
|
v
+-----------------------+ Active (Mon-Fri 08:00-17:00)
| Support_Day_PT | ---------------------------------> Rings Support Hunt Pilot
| (Linked to Schedule) |
+-----------------------+
| Inactive (After Hours)
v
+-----------------------+
| Support_Night_PT | ---------------------------------> Routes to Unity Connection
| (No Time Schedule) |
+-----------------------+
Real-World Implementation Pattern: Day / Night Call Routing
To route an organization's main number (5000) to live receptionist queues during the day and to voicemail after hours:
- Create partition
Main_Day_PTand attach theBusiness_Hours_TSTime Schedule. - Create partition
Main_Night_PTwith no Time Schedule (permanently active). - Assign DN
5000inMain_Day_PTpointing to the Receptionist Hunt Pilot. - Assign DN
5000inMain_Night_PTwith Call Forward All configured to the Cisco Unity Connection voicemail pilot. - In the incoming CSS (on the PSTN gateway or inbound SIP trunk), configure partition priority:
- 1st:
Main_Day_PT - 2nd:
Main_Night_PT
- 1st:
During business hours, both partitions match pattern 5000. Because both patterns have identical length and specificity, the tie-breaker rule applies: Main_Day_PT wins because it is listed first in the CSS. After hours, Main_Day_PT becomes dormant and invisible; digit analysis falls through to Main_Night_PT, seamlessly routing callers to voicemail without requiring manual attendant switches.
A Cisco IP Phone is configured with a Line Calling Search Space (CSS) containing the partition Internal_PT and a Device CSS containing the partitions Local_PT and LongDistance_PT. An administrator creates a translation pattern 9.1[2-9]XX[2-9]XXXXXX in Local_PT and another pattern 9.1[2-9]XX[2-9]XXXXXX in Internal_PT. When a user dials an external 11-digit number from this phone, which pattern is matched and why?
The pattern in Internal_PT, because the Line CSS partitions come first in the combined CSS and break the tie between equally specific matches.
The call fails with a fast-busy reorder tone because CUCM does not support identical patterns across concatenated partitions.
The translation pattern in Local_PT is matched because Device CSS partitions override Line CSS partitions for external call destinations.
CUCM performs round-robin load balancing between the two identical patterns across Internal_PT and Local_PT.
An engineer configures a Calling Search Space with the partition order Executive_PT, followed by Internal_PT. The Executive_PT partition contains the directory pattern 2XXX, while the Internal_PT partition contains the exact directory pattern 2001. A user assigned this Calling Search Space dials 2001. Which pattern does CUCM digit analysis select and which rule governs this outcome?
The pattern 2XXX in Executive_PT is selected because Executive_PT appears first in the Calling Search Space list.
The call triggers an interdigit timeout (T.302) of 15 seconds before failing because of overlapping wildcard ambiguity.
2001 in Internal_PT, because the closest (most specific) match wins regardless of partition order in the CSS.
Both patterns are evaluated simultaneously, initiating dual ringing on the endpoints assigned to 2XXX and 2001.
An administrator implements Time-of-Day (ToD) routing for a customer support line. The partition Support_Day_PT is associated with a Time Schedule active Monday through Friday from 08:00 to 17:00, containing Directory Number 5500 pointing to an agent hunt pilot. A second partition, Support_Night_PT, contains Directory Number 5500 pointing to an after-hours voicemail box, without an assigned Time Schedule. The calling phone has a CSS with Support_Day_PT listed first, followed by Support_Night_PT. What occurs when a caller dials 5500 at 19:30 on a Tuesday?
CUCM queues the call in memory until 08:00 the following morning when the daytime time schedule reactivates.
The after-hours voicemail, because Support_Day_PT is inactive outside its schedule, so digit analysis matches 5500 in Support_Night_PT.
The call is rejected with an unallocated number message because Directory Number 5500 cannot exist in multiple partitions simultaneously.
The call rings the agent hunt pilot because Support_Day_PT is listed first in the calling phone's CSS and retains permanent priority.
Sections you finish are checked off in the contents.