10.3 Webex Video Mesh & Hybrid Data Security
Key Takeaways
Webex Video Mesh deploys on-premises software media nodes (VMNs) on Cisco UCS or VMware ESXi virtualized infrastructure, keeping local participant media streams inside the corporate LAN to conserve WAN and Internet bandwidth.
In a Video Mesh deployment, media streams between local on-premises participants are mixed and switched locally, establishing a single media cascade link to the Webex Cloud only when remote participants, mobile users, or overflow capacity thresholds require it.
Video Mesh provides high availability and fault tolerance through dynamic media cascading: if an on-premises node reaches maximum port capacity or suffers a hardware outage, sessions automatically overflow or fail over to Webex Cloud media bridges without dropping the call.
Hybrid Data Security (HDS) deploys an on-premises Key Management Server (KMS) within the enterprise private datacenter, ensuring that customer master encryption keys and content encryption keys remain solely under customer custody.
In an HDS deployment, Webex Cloud microservices store exclusively encrypted blobs for persistent messages, files, and whiteboards; cloud operators and external entities possess zero cryptographic capability to decrypt customer plaintext data.
10.3 Webex Video Mesh & Hybrid Data Security
While cloud collaboration offers massive scalability, centralized management, and continuous feature delivery, large enterprises frequently confront two critical obstacles: Internet WAN bandwidth saturation caused by hundreds of concurrent high-definition video streams traversing corporate gateways, and stringent regulatory compliance mandates regarding data privacy and cryptographic key custody. Cisco addresses these operational and security challenges through two advanced hybrid architectures: Webex Video Mesh and Webex Hybrid Data Security (HDS).
1. Webex Video Mesh Architecture & Bandwidth Optimization
In a standard Webex deployment without Video Mesh, every endpoint—whether a Webex App desktop client, mobile device, or room video system—transmits and receives its audio, video, and content sharing streams directly to and from Webex Cloud media data centers. In a corporate headquarters where 50 or 100 participants join the same company-wide all-hands meeting or training session, this direct-to-cloud model places immense strain on perimeter Internet links.
The Bandwidth Problem
Consider a corporate campus where 50 participants join a 1080p high-definition video meeting:
- Each participant streams high-definition video requiring approximately 2.5 Mbps downstream and 2.5 Mbps upstream.
If multiple concurrent meetings occur simultaneously, enterprise Internet egress pipes become saturated, introducing packet loss, jitter, and call degradation across all corporate cloud applications.
The Video Mesh Solution
Webex Video Mesh resolves this bottleneck by deploying software media node instances—termed Video Mesh Nodes (VMNs)—directly inside the enterprise private network (on Cisco UCS C-Series servers or VMware ESXi virtual appliances):
+---------------------------------------------------------------------------------------------------------+
| CISCO WEBEX CLOUD |
| +------------------------------------+ +--------------------------------------------+ |
| | Webex Signaling & Identity Broker | | Webex Cloud Media Bridge Cluster |
| +------------------------------------+ +---------------------+----------------------+ |
+------------------------------------------------------------------------------|--------------------------+
|
| Encrypted Cascade Link
| (Multiplexed Audio / Video / Content)
| Destination UDP Port 5004 / TCP 443
+------------------------------------------------------------------------------|--------------------------+
| ENTERPRISE HEADQUARTERS LAN v |
| +---------------------+----------------------+ |
| | On-Premises Webex Video Mesh Node (VMN) | |
| | - Local Audio & Video Mixing/Switching | |
| | - Containerized Media Engine on UCS / ESXi | |
| +--+--------------------+-----------------+--+ |
| | | | |
| Local Media Streams (LAN Only) | | | |
| SRTP / SRTCP (UDP Port 5004) v v v |
| +------+----+ +------+----+ +------+----+ |
| | Cisco Room| | Webex App | | Cisco Desk| |
| | Kit Pro | | PC Client | | Pro | |
| +-----------+ +-----------+ +-----------+ |
+---------------------------------------------------------------------------------------------------------+
- Local Media Switching: When on-premises endpoints join a Webex meeting, signaling continues to traverse outbound to Webex Cloud, but the endpoints negotiate their Real-time Transport Protocol (SRTP) media streams directly with the local on-premises Video Mesh Node across the multi-gigabit corporate LAN.
- Bandwidth Savings: The local VMN mixes and switches the streams locally. If all 50 participants are in the same building and no external participants are present, zero media bandwidth traverses the Internet gateway. If external participants join, the VMN establishes a single, aggregated cascade link to the Webex Cloud media cluster, sharply reducing internet bandwidth.
2. Dynamic Media Cascading & High Availability
Video Mesh is engineered with an intelligent, multi-tier cascading mechanism that guarantees call continuity under all network and capacity conditions.
Cascading Scenarios
+---------------------------------------------------------------------------------------------------------+
| VIDEO MESH DYNAMIC CASCADING BEHAVIORS |
+---------------------------------------------------------------------------------------------------------+
Scenario 1: Mixed Internal & External Participants
[Local Endpoint 1] --+
[Local Endpoint 2] --+--> (On-Prem VMN) <====== [ Single Secure Cascade Link ] ======> (Webex Cloud)
[Local Endpoint 3] --+ ^
|
[Remote Mobile User] -------------+
Scenario 2: Node Port Capacity Overflow
[Endpoints 1 to 100] ---> (On-Prem VMN - 100% Port Capacity Exhausted)
[Endpoint 101] ---------------- [ Dynamic Overflow Cascade ] ------------------------> (Webex Cloud)
Scenario 3: Local Node Hardware Failure / Network Outage
[Endpoints 1 to 50] - - - X (On-Prem VMN Crashes / Power Loss)
[Endpoints 1 to 50] ===== [ Sub-Second ICE / STUN Failover ] ==========================> (Webex Cloud)
- Mixed Internal and External Participants: When on-premises users collaborate with remote teleworkers, external partners, or mobile Webex App clients, the local VMN establishes an encrypted, multiplexed cascade link to the nearest Webex Cloud media server. Local users send media to the VMN; remote users send media to the cloud. Only the active speaker video, mixed audio, and presentation content traverse the cascade link between the VMN and the cloud.
- Node Port Capacity Overflow: Each Video Mesh Node profile supports a rated capacity based on allocated compute resources:
- Capacity depends on the node's OVA profile and on the mix of video, audio, and SIP calls. When a local VMN reaches 100% capacity, the next on-premises user attempting to join is dynamically redirected to a secondary VMN in the local cluster, or gracefully overflows to the Webex Cloud media bridge without call failure or administrative intervention.
- Node Failure & Transparent Cloud Failover: If an active VMN suffers a hardware crash, power outage, or hypervisor host failure, endpoints detect RTP timeout via Interactive Connectivity Establishment (ICE) keepalives. Endpoints immediately renegotiate media transport directly to Webex Cloud media servers in a fraction of a second, ensuring meetings continue uninterrupted without dropping participants.
3. Video Mesh Sizing, Hardware Specs & Port Requirements
Video Mesh Nodes deploy as virtual appliances packaged as Open Virtualization Archives (OVA) running under VMware ESXi or as bare-metal containerized appliances on Cisco UCS hardware.
Platform Guidance
Video Mesh nodes are deployed from Cisco's Video Mesh OVA on VMware ESXi, either on a Cisco Meeting Server 1000 appliance or on specification-based servers such as Cisco UCS C220. The OVA profile fixes each node's vCPU and memory, and real capacity depends on that profile and on the call mix, so size clusters with Cisco's current deployment guide rather than fixed per-node numbers. Deploying more than one node per cluster lets a node failure shift calls to another node, with the cloud as the final overflow.
Network Port Requirements for Video Mesh
Perimeter firewalls must accommodate the following transport paths:
- Management and signaling (outbound): HTTPS on TCP 443 from the node to Webex; cascade signaling also uses TCP 444.
- Cascade media (outbound): UDP 5004 and 9000 to Webex cloud media, plus the UDP 50000-53000 range used by current releases; TCP 5004 is a fallback that can reduce quality.
- Client media (internal): Webex App and Webex devices send media to the node on UDP 5004, and endpoints registered to Unified CM reach the node with SIP on TCP 5060/5061.
- QoS: The node marks audio EF and video AF41.
4. Webex Hybrid Data Security (HDS) Architecture
Enterprise organizations operating in heavily regulated sectors—including financial services, defense, healthcare, and state government—must adhere to strict data sovereignty and encryption key custody mandates (e.g., HIPAA, GDPR, FINRA Rule 4511, and PCI-DSS). Under standard Webex cloud security, data is end-to-end encrypted, but the Key Management Service (KMS) resides in the Webex Cloud, secured by cloud Hardware Security Modules (HSMs). For organizations requiring absolute, exclusive physical custody over their cryptographic keys, Cisco provides Webex Hybrid Data Security (HDS).
Core Tenets of Hybrid Data Security
- Exclusive On-Premises Key Custody: HDS nodes run as virtual machines in the customer's data center. They host the key management service (KMS) along with indexing and eDiscovery services, and they store their data in a customer-managed database (Microsoft SQL Server or PostgreSQL). Cisco's HDS setup tool generates the configuration ISO that the nodes use.
- Zero-Knowledge Cloud Architecture: Webex Cloud data centers store only encrypted ciphertext blobs for persistent messages, files, whiteboards, search index tokens, and metadata. Cloud microservices possess zero cryptographic ability to decrypt user content.
- Instant Enterprise Revocation: Because the keys reside exclusively on customer-controlled KMS nodes, an enterprise can instantly revoke access to specific keys, projects, or spaces. Deleting or rotating a master key on the on-premises KMS renders all associated cloud-stored data permanently unreadable, guaranteeing true data sovereignty.
5. HDS End-to-End Cryptographic Flow
The cryptographic interaction between user endpoints, on-premises HDS KMS nodes, and the Webex Cloud follows a rigorous, multi-step sequence:
+---------------------------------------------------------------------------------------------------------+
| ENTERPRISE PRIVATE DATA CENTER |
| +------------------------------------+ +--------------------------------------------+ |
| | Enterprise Key Management Server | | On-Premises Active Directory / IdP |
| | (HDS node virtual machines) | | (User Authentication & Certificate Trust) |
| +-----------------+------------------+ +--------------------------------------------+ |
+---------------------|-----------------------------------------------------------------------------------+
| 2. Authenticates & Requests Key via HTTPS (Mutual TLS)
| 3. Issues Content Encryption Key (CEK)
|
+---------------------|-----------------------------------------------------------------------------------+
| v |
| [Webex App Client] |
| - 1. User composes message / attaches confidential document |
| - 4. Encrypts payload locally using AES-256-GCM |
| - 5. Transmits ENCRYPTED CIPHERTEXT BLOB outbound (TCP 443) |
+---------------------+-----------------------------------------------------------------------------------+
|
v
+---------------------------------------------------------------------------------------------------------+
| CISCO WEBEX CLOUD |
| +------------------------------------+ +--------------------------------------------+ |
| | Webex Messaging Cloud Storage | | Webex Search Indexer Engine |
| | - Stores Encrypted Ciphertext Blob | | - Indexes Only Blinded Cryptographic Hashes|
| | - CANNOT DECRYPT PLAINTEXT | | - NO ACCESS TO PLAINTEXT CONTENT |
| +-----------------+------------------+ +--------------------------------------------+ |
+---------------------|-----------------------------------------------------------------------------------+
|
| 6. Delivers Encrypted Blob
v
+---------------------------------------------------------------------------------------------------------+
| [Receiving Webex App Client] |
| - 7. Receives encrypted ciphertext blob from Webex Cloud |
| - 8. Connects directly to On-Premises HDS KMS over HTTPS to retrieve CEK |
| - 9. Decrypts payload locally on device for end-user display |
+---------------------------------------------------------------------------------------------------------+
Step-by-Step Encryption Flow
- Content Creation: User A composes a message or attaches a confidential file in a Webex messaging space.
- Key Request: User A's Webex client sends an authenticated mutual TLS request to the enterprise's on-premises HDS KMS node.
- Key Generation: The HDS KMS verifies User A's identity token and generates a unique Content Encryption Key (CEK) protected under the customer's master encryption key.
- Local Payload Encryption: The client encrypts the message payload or file locally using AES-256-GCM (Galois/Counter Mode).
- Encrypted Cloud Upload: The client uploads the encrypted ciphertext blob across outbound TCP port 443 to Webex Cloud storage.
- Blind Indexing: Cloud search indexers index only cryptographically "blinded" search tokens; cloud operators and automated bots cannot inspect the plaintext contents of messages or documents.
- Recipient Delivery: User B's client receives the encrypted ciphertext blob from the Webex Cloud.
- Decryption Authorization: User B's client authenticates directly to the enterprise's on-premises HDS KMS node to obtain the matching CEK.
- Local Plaintext Rendering: The receiving client decrypts the payload locally in memory, presenting the plaintext message to User B.
6. Architectural Comparison: Video Mesh vs. Hybrid Data Security
Collaboration engineers must distinguish between the operational domains, protocols, and security boundaries of Video Mesh and Hybrid Data Security:
| Attribute | Webex Video Mesh | Webex Hybrid Data Security (HDS) |
|---|---|---|
| Primary Objective | Bandwidth conservation and local media optimization | Cryptographic key sovereignty and regulatory compliance |
| Handled Data Type | Real-time audio, video, and screen-sharing media (RTP) | Cryptographic keys for persistent messages, files, and whiteboards |
| On-Premises Node | Video Mesh Node (VMN) media appliance | HDS node VMs (KMS, indexing, eDiscovery) with a customer database |
| Core Transport Protocols | SRTP / SRTCP over UDP 5004 / TCP 443 | HTTPS / REST over TCP 443 (Mutual TLS) |
| Cloud Interaction | Cascades multiplexed media streams to Webex Cloud | Cloud never sees keys; stores only encrypted ciphertext blobs |
| Failover Mechanism | Dynamic overflow and transparent failover to Webex Cloud | Local HDS KMS clustering; if all KMS nodes fail, decryption halts |
An enterprise collaboration engineer observes that when 60 employees in a single branch office join a company-wide Webex meeting, the branch's 100 Mbps Internet connection becomes completely saturated. If the branch deploys an on-premises Webex Video Mesh Node, how is the media traffic optimized?
Local endpoints send media to the Video Mesh node over the LAN, and the node sends one cascaded stream to the Webex cloud.
The Video Mesh Node forces all 60 clients to use peer-to-peer WebRTC connections across the Internet.
The Video Mesh Node converts all 60 video streams into audio-only SIP channels to preserve WAN bandwidth.
The Video Mesh Node caches the video streams locally and replays them to the participants with a 30-second buffering delay.
A financial institution with stringent regulatory compliance policies requires that master encryption keys for all Webex messaging content and shared files remain under the exclusive physical and cryptographic custody of the enterprise. Which Webex hybrid architecture must be deployed to satisfy this requirement?
Hybrid Data Security, with KMS nodes running in the customer's own data center.
Cisco Expressway-E deployed in a triple-homed DMZ with mutual TLS SIP trunk encryption.
Cisco Directory Connector with Active Directory Certificate Services (AD CS) integration.
Webex Cloud-Connected UC with dedicated hardware security modules (HSM) located in Cisco cloud datacenters.
During an all-hands meeting hosted on an on-premises Webex Video Mesh Node, the physical host server hosting the Video Mesh virtual machine experiences a catastrophic power supply failure. What is the operational behavior experienced by the active meeting participants?
Call control automatically redirects participants to the local PSTN gateway via ISDN PRI fallback.
The endpoints enter an unrecoverable audio loop until the on-premises Video Mesh Node is manually rebooted by an administrator.
The entire meeting terminates immediately and the host must schedule a new meeting link in Webex Control Hub.
Endpoints detect the lost local path and move their media to Webex cloud media nodes, and the meeting continues.
Sections you finish are checked off in the contents.