<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MRA with multi external domain in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374637#M5301</link>
    <description>&lt;P&gt;Yeah, I think you are right about the transformation. It won't affect the authentication.&lt;/P&gt;
&lt;P&gt;Anyway, how are the users from domain2 are trying to make their login? They're using "username@domain2" or "username@domain1" ?&lt;/P&gt;
&lt;P&gt;If each one of them is using a different domain, I think that the solution is using the&lt;STRONG&gt; Directory URI&lt;/STRONG&gt; field for all of users. Is this field currently contains some information or is it blank for all of the users?&lt;/P&gt;
&lt;P&gt;If it's blank, you can change the LDAP Directory configuration for this field to sync from the "mail" attribute from Active Directory, and then it'll contain "username@domain2" or "mailuser@domain2", depending on if the username is different from the email address of the person.&lt;/P&gt;
&lt;P&gt;Because then, the IM&amp;amp;P server will try to locate users that has this Directory URI based on user's input when he's trying to login, and currently there's no match probably therefore authentication fails. (But of course, do not forget to add the domains as I said in my previous comment in the Expressway-C and IM&amp;amp;P servers)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2018 18:00:02 GMT</pubDate>
    <dc:creator>Slavik Bialik</dc:creator>
    <dc:date>2018-04-27T18:00:02Z</dc:date>
    <item>
      <title>MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374366#M5298</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;I am deploying a cisco MRA solution using EXPC and EXPE.&lt;/P&gt;
&lt;P&gt;In my case, I have one internal domain (domain0.local) and multiple external domain that have different SRV records pointing to the same public address of my EXPE.&lt;/P&gt;
&lt;P&gt;_collab-edge._tls.domain1.com&amp;nbsp; &amp;nbsp;--&amp;gt; expe.domain1.com (EPXE pulbic@)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;_collab-edge._tls.domain2.com&amp;nbsp;&amp;nbsp;--&amp;gt; expe.domain2.com&amp;nbsp; &amp;nbsp;(EPXE pulbic@)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;_collab-edge._tls.domain3.com&amp;nbsp;&amp;nbsp;--&amp;gt; expe.domain3.com&amp;nbsp;&amp;nbsp;(EPXE pulbic@)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;during the configuration,&amp;nbsp; I tried one domain, it work fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;when i add the second, both of them have different issues:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-HTTP allow list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-cant determine home UCM&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BTY, I have upgrade both EXP to 8.10.4.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is there a solution or a specific guide that coud help to resolve my problem&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 02:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374366#M5298</guid>
      <dc:creator>h.hajamor</dc:creator>
      <dc:date>2019-03-18T02:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374394#M5299</link>
      <description>&lt;P&gt;Hi, I'm having a feeling that it has something to do with the:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;VoiceServicesDomain&amp;gt;domain1&amp;lt;/VoiceServicesDomain&amp;gt;&lt;/PRE&gt;
&lt;P&gt;That is located in your jabber-config.xml file.&lt;/P&gt;
&lt;P&gt;Just out of curiosity, try to change the value of the first external domain that you put in the above XML tag, to the second domain that you're currently not being able to login with. And then try to make a login with this second domain. If it works, so I'm not sure how to solve it, because you can enter only one external domain in the VoiceServicesDomain tag. I think a possible solution for that is applying a Transformation rule on the Expressway server that'll replace all the domains to the first domain (the main one, that currently is working).&lt;/P&gt;
&lt;P&gt;If it's still not working, review the configurations, maybe you didn't add those SIP domains in the Expressway-C server, you have under configurations a settings page named "Domains" you must enter them all there.&lt;/P&gt;
&lt;P&gt;Plus, you need to enter all the relevant domains in the IM&amp;amp;P server under Domains also.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 11:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374394#M5299</guid>
      <dc:creator>Slavik Bialik</dc:creator>
      <dc:date>2018-04-27T11:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374586#M5300</link>
      <description>dear  Slavik,&lt;BR /&gt;about &amp;lt;VoiceServicesDomain&amp;gt;, I am sure that tha jabber-config.xml dosn't support multidomain,&lt;BR /&gt;I am trying to go through with the transformation method&lt;BR /&gt;but i think that the transformation is needed only for SIP routing and not jabber AUTH for MRA.&lt;BR /&gt;best regards</description>
      <pubDate>Fri, 27 Apr 2018 16:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374586#M5300</guid>
      <dc:creator>h.hajamor</dc:creator>
      <dc:date>2018-04-27T16:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374637#M5301</link>
      <description>&lt;P&gt;Yeah, I think you are right about the transformation. It won't affect the authentication.&lt;/P&gt;
&lt;P&gt;Anyway, how are the users from domain2 are trying to make their login? They're using "username@domain2" or "username@domain1" ?&lt;/P&gt;
&lt;P&gt;If each one of them is using a different domain, I think that the solution is using the&lt;STRONG&gt; Directory URI&lt;/STRONG&gt; field for all of users. Is this field currently contains some information or is it blank for all of the users?&lt;/P&gt;
&lt;P&gt;If it's blank, you can change the LDAP Directory configuration for this field to sync from the "mail" attribute from Active Directory, and then it'll contain "username@domain2" or "mailuser@domain2", depending on if the username is different from the email address of the person.&lt;/P&gt;
&lt;P&gt;Because then, the IM&amp;amp;P server will try to locate users that has this Directory URI based on user's input when he's trying to login, and currently there's no match probably therefore authentication fails. (But of course, do not forget to add the domains as I said in my previous comment in the Expressway-C and IM&amp;amp;P servers)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 18:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3374637#M5301</guid>
      <dc:creator>Slavik Bialik</dc:creator>
      <dc:date>2018-04-27T18:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3375890#M5302</link>
      <description>&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;For this to work, you have to make some serious changes and here are the reasons why&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;1. Your IM and P server if using the default presence domain structure must match the domain in your JID. Eg If your users sign in using adam@domain1.com, then your IM and P server presence domain has to be domain1.com.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Now if you have multiple users on different external domain, then&amp;nbsp;you will have issues. If you have another user on adam@domain2.com, your login will fail, because domain2.com is not configured on your IM and P server, hence it is not responsible to process requests for that domain.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;There is only one possible solution for this and that is to use flexible JID on your IM and Presence server. Now this comes with a caveat, your users "mail or msRTCSIP-primaryuseraddress" address must be mapped to the directory uri and this directory uri is what they must use to login to jabber.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;For example, when you change IM and P to use directory uri, then your users "&lt;SPAN&gt;mail or msRTCSIP-primaryuseraddress"&lt;/SPAN&gt; attributes in AD must match as follows&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;1. users on domain1: adam@domain1.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;2. users on domain2: adam@domain2.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;3. users on domain 3: adam@domain3.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;Now once this is taken care, IM and P will allow users to login using any of the matched directory URI..But you still need to sort out expressway.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;To allow expressway-e to accept the login request, you will need to then tell jabber to use the domain on the expressway-e for its service discovery. Lets assume your expressway-e is on domain1 and your cucm and IP and P servers are on internal domain. You will need to do the following:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;FONT face="lucida sans unicode,lucida sans" color="#000000"&gt;jabber: SERVICES_DOMAIN=domain1.com ( note you dont need voice_services_domain: this is only required if you are using hybrid services). Y our discovery domain is actually your services_domain&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;FONT face="lucida sans unicode,lucida sans" color="#000000"&gt;So when Jabber runs its query for collab-edge, it will look for _collab-edge._tls.domain1.com&amp;gt; resolve to expwe&amp;nbsp; eg expwe01.domain1.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;FONT face="lucida sans unicode,lucida sans" color="#000000"&gt;Now internally, expressway-C will query UDS records for domain1.com, so you need to then create a forward lookup rulezone on DNS to point all the request for domain1.com to your internal domain where your CUCM and IM and P lives&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 09:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/3375890#M5302</guid>
      <dc:creator>Ayodeji Okanlawon</dc:creator>
      <dc:date>2018-05-01T09:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4136456#M43784</link>
      <description>&lt;P&gt;Hi Ayodeji,&lt;/P&gt;&lt;P&gt;Thanks for the detailed description (+5),do you think by this method, the same user can use different domains to login, for eg: a user name john, can he login with john@domain1.com,&amp;nbsp;john@domain2.com and&amp;nbsp;john@domain3.com, there is only one directory-URI for one user-id right ?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 09:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4136456#M43784</guid>
      <dc:creator>Risat</dc:creator>
      <dc:date>2020-08-16T09:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4136462#M43785</link>
      <description>&lt;P&gt;No you can't have multiple user IDs for one user. So this won't be possible.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 09:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4136462#M43785</guid>
      <dc:creator>Ayodeji Okanlawon</dc:creator>
      <dc:date>2020-08-16T09:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: MRA with multi external domain</title>
      <link>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4403453#M45696</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am in the same situation as Hajmor.&lt;/P&gt;&lt;P&gt;On IM and P, I use the directory URI for my users. In the team, we manage several branches from different countries in our company.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to put a Jabber over MRA on the mobiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I did as Ayodeji says.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created an internal DNS zone called MRA.domain1.com (with the srv UDS and cup)&lt;BR /&gt;On the public DNS, I did the same thing and configured the Collabedge SRV on my domain MRA.domain1.com&lt;BR /&gt;My eu expressways are configured with my domain.local --&amp;gt; expe1.domain.local. Is this a problem?&lt;/P&gt;&lt;P&gt;The Jabbers on mobile will be configured and pushed via airwatch. The domain service will therefore be mra.domain1.com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I think I match what Ayodeji mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my question is, how will the users authenticate on my jabber. Because internally we use a global domain for all branches. And the local jabber you just need to put your userid to log in because the service domains are pushed through the jabber bootstrap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 08:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/mra-with-multi-external-domain/m-p/4403453#M45696</guid>
      <dc:creator>Sebastien Denoncin</dc:creator>
      <dc:date>2021-05-15T08:25:33Z</dc:date>
    </item>
  </channel>
</rss>

