02-09-2015 05:21 AM - edited 03-17-2019 01:53 AM
Hi Experts,
I am in process of configuring and testing Expressway MRA for two CUCM Cluster with same domain.
and login tests with jabber.
A couple of jabber IDs cannot log-in to IM&P
I wanto to make sure whether the configuration of each devices for MRA is correct or not
Do you think which configuration are needed to work MRA for two CUCM and IM&P Clusters?
[Expressway]
1. basic configuration such as NTP, DNS and so on.
2. enable MRA feature
3. add two IM&P clusters
4. add two CM Clusters
5. add customer domin
6. Traversal zone between expressway-e and expressway-c
[CUCM]
1. Enable Intercluster lookup service on two cucm clusters
2. Home cluster check box on two cucm clusters.
Solved! Go to Solution.
02-12-2015 04:58 AM
No I am not refeering to the cluster fully qualified domain. In 10.X it is called default domain..Please check it here
I have looked at tomcat logs and I can see a successfully login for the test user. I am keen on getting this sorted for you ( I am even ready to open a tac case if need be) but I want to check all the relevant things first..
If your domain is configured correctly.Please use RTMT to collect the following logs for the time frame that you do another test.
Cisco Client Profile Agent (CPA)
Cisco XCP Connection Manager
Cisco XCP Router
Cisco XCP Authentication Service
I will also need Expwe and C logs. To collect this please go to expwe server and navigate to
Maintenance > Diagnostics > Diagnostic logging
Network log level and Interworking log level both set to Debug
B2BUA log level set to Debug
PS: Does this affect all users on cluster A? Can users in Cluster B login? Have you tested with another user in cluster A?
02-12-2015 10:02 PM
Yes, I will confirm the domain is correct. and I will attach the captured file.
I was login test around 14:37 and collected logs on RTMT. while I collected logs on RTMT, warning was displayed as an attached file.
PS Question)
- Does this affect all users on cluster A? Can users in Cluster B login? Have you tested with another user in cluster A?
: At first test, a couple of user in Cluster A can login and all user in Cluster B can login. But all user in Cluster A and Cluster B cannot login at the moment.
and I send exp-c and exp-e logs to your e-mail. please check it up.
02-13-2015 02:47 AM
I have looked at the logs in detailed and the failure is due the SASL (Simple Authentication and Security Layer ) error.
++++++++++++
2015-02-13T14:37:40+09:00 isje XCP_CM[8601]: UTCTime="2015-02-13 05:37:40,15" ThreadID="140509293991680" Module="cm-1.isje-XXXXX-co-kr" Level="WARN " CodeLocation="cm-1_jsmcp-1_xmppd-1" Detail="XMPPStream Error -- ErrorCode: 303 Details: bind-error: Invalid stream header, Errored address: X.X.X.X, Errored user jid: unknown"
2015-02-13T14:37:42+09:00 isje XCP_CM[8601]: UTCTime="2015-02-13 05:37:42,346" ThreadID="140509310777088" Module="cm-1.isje-XXXXXX-co-kr" Level="INFO " CodeLocation="SASLManager.cpp:290" Detail="Failed during SASL session with auth component"
2015-02-13T14:37:42+09:00 isje XCP_CM[8601]: UTCTime="2015-02-13 05:37:42,346" ThreadID="140509310777088" Module="cm-1.isje-XXXX-co-kr" Level="WARN " CodeLocation="cm-1_jsmcp-1_xmppd-1" Detail="XMPPStream Error -- ErrorCode: 107 Details: internal-server-error, Errored address: X.X.X.X, Errored user jid: unknown"
+++++++++++
Do you have port 5222 enabled inbound to Expwe from the internet on your firewall? This is the port used for XMPP traffic
Do you also have port 7400 enabled between Expw-C and E
02-15-2015 06:24 PM
I'd first like to convey my appreciation for long terms supports.
I will talk about port 5222 and port 7400 with firewall engineer and update them.
At this point, I have a question.
What is different between using either Cluster_A or Cluster_B and using both of them?
I am a little confusing.
02-16-2015 01:41 AM
I am not sure I understand your question. Cluster_A is different from cluster_B. You have different users in different clusters hence you need your expressway to communicate with both clusters.
02-16-2015 04:48 AM
My question is
when one cluster is added on exp-c, I am wondering whether tcp 5222 and 7400 port use or not?
02-16-2015 04:51 AM
These ports are used to communicate between expressway-c and e(port 7400) and between the internet and expressway-e (port 5222).
It doesn't matter how many cluster you add, these ports need to be opened on the firewall(s)
02-16-2015 04:54 AM
OK, I will check again with F/W engineer and update the results.
Our F/W engineer is too busy, So I could check it on today.
02-19-2015 01:58 AM
Is this solved already?
If yes, were the ports the reason of the failure?
I have exact the same message after updating to Expressway 8.5.1.
With 8.2 all was working fine, so something must have changed maybe.
EDIT: My CUCM is 10.5.1.10000-7 and IM&P is 10.5.1.10000-9.
EDIT2: I just checked the ports, they are both open. Any other suggestions?
02-22-2015 07:44 AM
I think we have the same problem and this is not sovled yet.
I am wondering whether exp 8.5 has any bugs or not.
So I am considering to open a tac case.
02-22-2015 09:56 AM
Andy,
Is your XCP router service active on Expwe. Can you send a screen shot?
02-22-2015 09:56 AM
You mean XMPP Federation?
If no, where can I take a screen shot on exp-e?
02-22-2015 10:08 AM
go to status>unified communications and send both output from expwe and expwc
02-22-2015 10:27 AM
02-22-2015 10:54 AM
Okay please restart the intercluster sync agent on your IM and P servers. If it has not started on any server then start it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide