When Encryption is enabled in CUCM then the VG224 analog ports are not getting registered.
The registration is shown as rejected in cucm.
The issue is noticed only on some gateways, however there are working Gateways which are registered properly with similar configuration.
The configuration is through SCCP and is configured correctly.
When a secured Analog profile is selected for the Analog phones then the phones will not get registered.
On Some Gateways the phones are registered when we select the encryption option in the phone security profile without any issue.
The VG224's on working and non-working are on the same release.
In CUCM traces we could see that the registration is rejected as invalid certificate name or configuration issue.
Reason code 11 and reason code 3 which is certificate name invalid/ DatabaseConfigurationError.
May 12 09:01:55 POZVLNX001 local7 3 : 38266: POZVLNX001: May 12 2014 10:01:55.489 UTC : %UC_CALLMANAGER-3-DeviceTransientConnection: %[ConnectingPort=2000][DeviceName=ANF70D02F618400][IPAddress=10.32.252.85][DeviceType=30027][Reason=11][Protocol=SCCP][IPAddrAttributes=2][UNKNOWN_PARAMNAME:LastSignalReceived=StationRegister][UNKNOWN_PARAMNAME:StationState=wait_register][AppID=Cisco CallManager][ClusterID=EURO-CUCM][NodeID=POZVLNX001]: A device attempted to register but did not complete registration
3 indicates DatabaseConfigurationError - The device is not configured in the Unified CM Administration database and auto-registration is either not supported for the device type or is not enabled. To correct this problem, configure this device in Unified CM Administration.
11 indicates InvalidX509NameInCertificate - Configured "X.509 Subject Name" doesn't match the information in the certificate from the device. Check the Security profile of the indicated device and verify that the Device Security Mode is set to either Authenticated or Encrypted. Verify that the X.509 Subject Name field has the appropriate content; it should match the Subject Name in the certificate from the peer.
We could see the same from the call manager traces.
Line 15394: 09:03:59.210 |DeviceTransientConnection - A device attempted to register but did not complete registration Connecting Port:2000 Device Name:ANF70D02F618401 Device IP Address:10.32.252.85 Device type:30027 Reason Code:11 Protocol:SCCP IPAddressAttributes:2 UNKNOWN_PARAMNAME:LastSignalReceived:StationRegister UNKNOWN_PARAMNAME:StationState:wait_register App ID:Cisco CallManager Cluster ID:EURO-CUCM Node ID:POZVLNX001|AlarmANF70D02F618401^*^ANF70D02F618401
Line 15401: 09:03:59.210 |StationD: (0036154) registrationError sent StationOutputRegisterReject|0,0,0,0.0^10.32.252.85^ANF70D02F618401
Line 15402: 09:03:59.210 |StationD: (0036154) RegisterReject text='Security Error'.|0,0,0,0.0^10.32.252.85^ANF70D02F618401
We have done the following:
1. Stop “Cisco Certificate Change Notification Service” on all the nodes and regenerate the certificate and upload it to the call manager.
2. Restart the call manager service/Node and check the issue.
This did not have any impact.
The issue is with the subject name.
So under crypto pki trustpoint” configuration of gateway we changed the change the “subject-name CN= F7:0D:02:F6:18” from xx.xx.xx.xx.xx format to xx:xx:xx:xx:xx
After which the gateway is registered.
However we need to make sure the following point which is important.
The device pool under the VG224 and the analog port should be same if not the ports may register or may not register; even though the ports are registered the calls would fail.
Other point which is important to be noted when configuring a PLAR when VG224 is registered to CUCM then it is recommended to use PLAR configuration on the gateway side rather than the CUCM side.
The impact of this is, when the called party disconnects the call then the status of the analog phone still remains off –hook which causes the gateway to send the off-hook status to CUCM and thus resulting the call again.
Good day, We are planning to upgrade unity connection from 9.1 to 12.5 currently Unity 9.1 is hosted on esxi version is 6.0 We wish to upgrade esxi to version 6.5we know UC 9.1 is not compatible with esxi 6.5, however if we should upgrade t...
Hi There, We are trying to install CUCM PUB 12.5 and we are struck on the black blank screen from past two hours. we can wee RAM is being utilized 100% and CPU is around 20%. Is this normal? If yes, how long we have to wait until this black screen is...
A customer has a Jabber Directory Integration with LDAP. From the Jabber search, he should be able to search users by various other LDAP Attributes. The feature generally works (e.g. he can search for a City, and it will show him all users that have the C...
HelloIn the macro framework, is there a way I can register to the HttpClientResult response after I send an HTTP get request?In putty, affter sending a xcommand HttpClient get, I get this:*r HttpClientGetResult Body: example I would like to get that ...
I'm struggling to understand why the From in our outbound INVITE to our primary ITSP is using the IP address of our secondary ITSP, instead of the IP address of our CUBEs sending interface. INVITE from Jabber to CUBE is fine:Received:INVITE sip:80781...