Voice Security for Cisco
Protection for: Call Manager (CUCM), CUBE, Webex Contact Center, Webex Calling
Quick Links
- Cisco & Mutare, an Enduring Partnership
- Resilient Voice Firewall with Multiple Filtering Layers
- Verified Interoperability with Cisco UC, CC & Cloud
- Voice Security Resilience: Cisco + Mutare
- Architecture Components: Cisco
- Architecture Components: Mutare
- Architecture: On-Premise / Cisco CUBE with Voice Firewall
- Architecture: Cloud / Cisco CUBE with Voice Firewall
- Architecture: Cloud / Cisco Webex Contact Center with Voice Firewall
Cisco & Mutare, an Enduring Partnership
Mutare has been a Cisco ecosystem development partner for nearly a decade, a close and mutually supportive relationship between the world’s largest digital communications and IT networking technology conglomerate and the world’s most innovative enterprise telecom software solutions developer.
As a select provider of voicemail-to-email with text transcription for the Cisco Unified Communications Manager (CUCM) platform, Mutare’s continued contribution to the Cisco portfolio has expanded well beyond enhanced unified communications. Today, through its award-winning Voice Traffic Filter voice firewall platform, Mutare has assumed a critical role in confronting the growing problem of unwanted nuisance and nefarious calls infiltrating Cisco customers’ enterprise and contact center voice systems.
The Mutare Voice Firewall removes the scourge of spam, robocalls, spoof calls, scammers, social engineers and voice phishers (vishers) that are undermining employee productivity, network performance, and organizational security. When added to any organization’s IT or contact center infrastructure, the Voice Firewall detects, and blocks or deflects, the vast majority of those unwanted and threatening calls before they have a chance to ring through, disrupt, or defraud an employee or contact center agent.
Resilient Voice Firewall with Multiple Filtering Layers
The Voice Firewall (Mutare Voice Traffic Filter) provides unprecedented control over the security and integrity of voice calls flowing into and out of the organization through a unique combination of proprietary voice data analysis capabilities built into multiple layers of filtering technology. Depending on the preferences set by the organization, calls may be screened through any or all the following filtering layers:
Proprietary Dynamic Database
Meta-analysis of incoming calls that integrates continuously updated data from multiple number verification resources identifying known spam, scam and robocalls.
Custom Rules
Highly flexible, organization-specific rules that direct call filtering actions for specific incoming/outgoing calls or call types.
Threat Radar
Leveraging a combination of localized machine-based learning algorithms and organization-specific call flows, the Threat Radar filtering layer identifies unusual call patterns or behaviors outside of the norm that indicate potential fraud or misuse.
STIR/SHAKEN
This screening integrates carrier-provided STIR/SHAKEN caller verification and attestation scores (when available) into the filter’s overall call trust analysis.
Voice CAPTCHA
Extra layer of vetting for calls of ambiguous trust. Voice CAPTCHA challenges callers to enter random digits before the call is passed through, essentially separating live callers from bots.
Verified Interoperability with Cisco UC, CC & Cloud
As a trusted Cisco developer partner, Mutare has worked closely with Cisco engineers to assure seamless interoperability of its solutions with the Cisco technology stack. Voice Traffic Filter is currently certified for integration with the following Cisco UC and CC cloud and on-premise systems:
Cisco Call Manager / Cisco Unified Communications Manager (CUCM)
Call Manager / CUCM (with or without Cisco Unity Connection voicemail) is Cisco’s core on-premise collaboration platform that provides centralized call control and session management for voice, video, messaging, and mobility applications within Cisco’s unified communications infrastructure. Mutare’s Voice Traffic Filter can be part of a fully behind-the-firewall Call Manager / CUCM deployment or hosted in the cloud for a lighter hardware footprint.
Cisco Unity Border Element (CUBE)
Voice Traffic Filter is certified for seamless interoperability with the Cisco Unified Border Elements (CUBE) SBC. Mutare leverages a simple configuration of the CUBE to direct incoming traffic through the Voice Traffic Filter system for analysis. Configuration is quick and easy, with no need for special services or impact on the existing IT infrastructure.
Cisco Webex Contact Center
Mutare’s Voice Traffic Filter integrates with the cloud-based Webex Contact Center through API and is included in the Webex App Hub. Applied at the inception of the call flow, Voice Traffic Filter removes or reroutes the vast majority of unwanted nuisance and nefarious calls before they reach the IVR or ring through to an agent.
Cisco Webex Calling
Mutare’s Voice Traffic Score (VTS) extends Cisco Webex Calling with real-time call reputation intelligence that helps organizations identify, evaluate, and control inbound voice traffic before calls reach users. As a Cisco Certified Call Reputation Provider (CCRP), Mutare delivers dynamic reputation scores that enable administrators to automatically allow, challenge, or block calls based on configurable trust thresholds, strengthening Voice Security while improving the user experience.
Cisco XDR
Voice Traffic Filter includes a tool that converts captured call data and analytics results into a format that is easily integrated into the organization’s XDR/SIEM security system, including Cisco XDR. The correlation of voice data with other network data not only provides deeper intelligence into the overall performance of IT networks, but also expands early detection of emerging, complex cyber-threat campaigns that are increasingly leveraging multiple channels of intrusion.
Flexible Implementation
Voice Traffic Filter provides protection for the entire organization and can be implemented on-premise, hosted in the cloud, or in a hybrid deployment.
Voice Security Resilience: Cisco + Mutare
“Resilience” is a key component of Cisco innovation and one shared by Mutare application architects as they work together to bring stable, secure, and future-proof solutions that both support and protect the businesses they serve.
To learn more about how Mutare’s Voice Traffic Filter adds strength, resilience and security to Cisco UC and CC platforms, click Here.
Architecture Components: Cisco
Cisco Unity Border Element (CUBE)
Cisco CUBE is a Session Border Controller (SBC) that provides secure voice and video connectivity between external networks and the Cisco Unified Communications Manager (CUCM, or Call Manager) platform. In an enterprise deployment, the Cisco CUBE provides session control, security, interworking, and demarcation. Cisco CUBE also provides connectivity to cloud-based voice and video systems. It can be deployed virtually on Cisco UCS servers or integrated into a Cisco router.
Cisco Call Manager / Cisco Unified Communications Manager (CUCM)
The Cisco Call Manager / Cisco Unified Communications Manager is an on-premise collaboration platform that provides centralized call control and session management for voice, video, messaging, and mobility applications within Cisco’s unified communications (UC) infrastructure.
Interactive Voice Response (IVR)
In a contact center setting, the IVR is the automated system that uses voice or touch-pad responses to guide callers through a menu of options routing them to the appropriate agent, team, or resource.
Webex Flow Designer
A user-managed tool for the Webex Contact Center that defines how calls are routed to various sub-flows or endpoints.
Architecture Components: Mutare
The Mutare Proxy Server
This server interfaces with the Cisco CUBE or other SBCs with SIP trunking. The Mutare Proxy Server communicates with the Mutare Voice Traffic Filter server via API interface, sending call signaling information to the Voice Traffic Filter for analysis and receiving information back associated with analysis results and related actions to be applied.
The Mutare Voice Traffic Filter Server
The Mutare Voice Traffic Filter server holds the organization-specific Custom Rules, Threat Radar analysis algorithms and, through API, access to the cloud-based dynamic database. It also houses the graphical user interface, admin settings, and tenant settings. This server is where the majority of call data screening and analysis occurs.
Proprietary Dynamic Database
The Proprietary Dynamic Database is a continuously-updated amalgamation of numbers related to nuisance and nefarious call activity. Screening through the proprietary dynamic database is achieved through API connection between the Mutare Voice Traffic Filter application server and multiple worldwide database providers.
Voice CAPTCHA Server
As with any filtering system, false positives can occur. To ensure wanted calls are not dropped by mistake, users may choose to have calls of ambiguous trust sent through the Voice CAPTCHA for additional screening. The Voice CAPTCHA challenges the caller to enter a set of random digits, effectively separating human callers from bots.
Deploying Mutare Voice Firewall in Your Cisco Environment
The following are simple architecture and call flow overviews of Mutare Voice Traffic Filter (VTF) integrated with Cisco enterprise and Webex platforms. In all cases, the call screening process is fast, efficient, and entirely undetectable for both callers and call recipients.
Architecture: On-Premise / Cisco CUBE with Voice Firewall

- Incoming calls are routed via CUBE to the Mutare Proxy Server for screening.
- The Mutare Proxy server queries the Mutare Voice Traffic Filter server via API request, sending SIP signaling information to the Voice Traffic Filter for analysis. The Voice Traffic Filter draws information from the cloud-based Proprietary Dynamic Database via API interface if requested. That screening data is included in analysis results from the application’s multiple filtering technologies and communicated back to the Mutare Proxy server where user-defined actions are carried out.
- Those actions may include:
- Allow – the call is passed to the customer’s Call Manager for endpoint distribution.
- Drop – the call will be dropped with no further system interaction.
- Route – the call will be routed to a specific individual, team, or resource.
- CAPTCHA – the caller is presented with a challenge.
If the action is set for CAPTCHA, that call will be directed to the Mutare CAPTCHA server. The CAPTCHA application challenges the caller to provide a random set of digits. Callers that pass the challenge are allowed through, while those that fail may be dropped or routed to another resource.
Organizations may also add their own subset of numbers to CUBE configurations that will pass through directly to the Call Manager without screening.
Architecture: Cloud / Cisco CUBE with Voice Firewall

Call flow for cloud implementation is identical to on-premise CUBE/Voice Traffic Filter deployments. Only the location of the Mutare Proxy server, Voice Traffic Filter server, and CAPTCHA server has changed, from on-premise to cloud.
Architecture: Cloud / Cisco Webex Contact Center with Voice Firewall
Implementation for the Cisco Webex Contact Center adds the cloud-based Mutare Voice Traffic Filter as a sub-flow at the front end of the Webex Contact Center call flow. Note that administrators have full control over how the system interacts with call analysis results.

- As calls enter the customer Webex call flow, they are first directed to the Mutare-provided VTF Subflow.
- The VTF Subflow queries the cloud-based Voice Traffic Filter server via REST API/HTTPS (OAUTH) for analysis.
- Analysis results may include information drawn from the Proprietary Dynamic Database as well as Voice Traffic Filter’s organization-specific Custom Rules and Threat Radar detection systems.
- If Voice CAPTCHA has been included in the Mutare Voice Traffic Filter subflow, those results (pass, fail) are also delivered to the Voice Traffic Filter server via API interface and become part of the call analysis process.
- Calls of full trust are marked as Allowed and delivered into the normal Webex CC call flow where they pass through the IVR to their endpoint. Those flagged as suspect may be dropped, also allowed through if preferred, or routed via Flow Designer to another resource or specialty agent/security team for additional vetting depending on user configuration preferences.
The following are simple Cisco Webex Flow Designer diagrams of a Cisco Webex Contact Center call flow before integration with Mutare Voice Traffic Filter and after the addition of the VTF subflow.


