To configure an encrypted trunk between Cisco TelePresence Video Communication Server (VCS) and Cisco Unified Communications Manager (CUCM), the root CA of the VCS server certificate must be loaded in CUCM. This ensures that CUCM can validate the server certificate presented by VCS. The CUCM trunk configuration must have the destination port set to 5061 as this is the standard port for SIP over TLS. Additionally, a SIP trunk security profile must be configured with the Device Security Mode set to TLS to ensure that the communication over the trunk is encrypted.