02-18-2016 07:13 AM - edited 03-17-2019 05:54 PM
Hi,
We have the following deployment:
* CUCM cluter (version 11.0.1)
* CWMS (50 users without HA) version 2.6MR1
When I try to call from the meeting room to my extension and from my extension to the meeting room without encryption (with TCP ports 5060 and 5062) everything is working as expected but when I change the integration to use encryption (with TLS ports 5061 and 5063) I can dial the main number of the webex, hear the announcement ("Welcome to webex..") and then after I insert the meeting number and press the # key I get silence.
Morover, I cant dial from the webex meeting room to my extension (with no answer error).
I checked the CUCM configuration (Two SIP trunks - Application and Load balancer, SIP route pattern, Route Pattern, SIP trunk security profile, out-of-dialog CSS and reroute CSS) and everything is looking just fine.
Does anyone have an idea what is wrong with my deployment ?
Thanks a lot.
02-18-2016 10:48 AM
Hi,
If all is working fine when no TLS is used, it means your CWMS system is fine. Now, when you are switching to TLS, there are changes that need to be made to the CUCM configuration side to ensure SIP Trunk Security Profiles, TLS SIP Profile, and Destination Ports in SIP Trunks are adjusted properly.
Please, if you haven't done already, do reference the Planning Guide for instructions on TLS SIP Profile configuration and other TLS information.
If your SIP Trunks successfully register, and you can make a call to CWMS but after entering meeting # nothing happens, there might be some issue with SIP REFER and SIP Route Pattern (or Re-routing Calling Search Space configuration in SIP trunks doesn't match partitions in the SIP Route Pattern).
Unfortunately, to understand what is really going on, we would need to see SIP traces and see how the call is being setup. For this kind of issue, it would be best to open a ticket with TAC to look at the logs.
-Dejan
02-22-2016 03:55 AM
Hi Dejan,
Thanks for your reply.
If I can call to the main number of the Webex (used port 5061) and can hear the "Welcome to Webex" prompt (And I can see the lock icon) it means that the certificates imported succesfully - right ?
Additionally, I thought that maybe this is a firewall problem but I tried to connect an IP phone on the servers environment and it didn't work as well.
Thanks.
02-22-2016 05:05 AM
Hi,
On CUCM, if TLS SIP Trunks successfully register with CWMS, most likely the SSL certs are fine.
Still, without looking at the setup and logs, it is almost impossible to fully understand what exactly is failing and how to address it. Unfortunately, I believe TAC ticket is the route to follow to get a TAC engineer to investigate further.
-Dejan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide