10-04-2017 03:01 AM - edited 03-17-2019 11:17 AM
Hello
We have cisco CUCM 8.6 with many sites all over Europe. One of the sites has been experiencing intermittent drop calls and phone reset on almost all the phones. Verified the Netwrok and all seems to be good
On the phone we could see this:
15:09:12 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
15:09:16 9: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) TFTP Error
15:09:16 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
15:09:28 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
15:09:28 14: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=UCM-closed-TCP
15:10:32 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
15:10:40 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
17:10:32 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
17:10:37 9: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) TFTP Error
17:10:37 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
17:12:08 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
17:12:11 9: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) TFTP Error
17:12:11 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
18:11:55 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
18:12:02 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
18:13:06 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
18:13:12 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
18:14:16 10: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=TCP-timeout
18:14:19 9: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) TFTP Error
18:14:19 23: Name=SEP8CB64F574494 Load= 9.3(1SR4.1S) Last=Reset-Restart
one the CUCM i can see this for that time stamp
(PDH-CSV) | Cisco CallManager System Performance\QueueSignalsProcessed 1-High | Cisco CallManager System Performance\QueueSignalsProcessed 2-Normal | Cisco CallManager System Performance\QueueSignalsProcessed 3-Low | \\10.44.72.22\Cisco CallManager System Performance\QueueSignalsProcessed 4-Lowest | \\10.44.72.22\Cisco CallManager System Performance\QueueSignalsProcessed 5-Database | \\10.44.72.22\Cisco CallManager System Performance\QueueSignalsProcessed 6-Interleaved | Cisco CallManager System Performance\QueueSignalsProcessed Total |
10-02-17 15:09 | 11 | 51 | 105 | 4 | 0 | 0 | 171 |
10-02-17 15:10 | 24 | 112 | 266 | 10 | 0 | 0 | 412 |
10-02-17 15:10 | 5 | 3 | 0 | 0 | 0 | 0 | 8 |
10-02-17 15:10 | 6 | 12 | 0 | 0 | 0 | 0 | 18 |
10-02-17 15:10 | 3715 | 1947 | 7614 | 8 | 0 | 0 | 13284 |
10-02-17 15:11 | 15 | 82 | 75 | 3 | 0 | 0 | 175 |
10-02-17 15:11 | 17 | 45 | 98 | 3 | 0 | 0 | 163 |
10-02-17 15:11 | 1 | 2 | 0 | 0 | 0 | 0 | 3 |
10-02-17 15:11 | 6 | 17 | 11 | 2 | 0 | 0 | 36 |
10-02-17 15:12 | 1 | 7 | 0 | 0 | 0 | 0 | 8 |
10-02-17 17:12 | 8 | 35 | 1 | 0 | 0 | 0 | 44 |
10-02-17 17:12 | 9 | 24 | 0 | 0 | 0 | 0 | 33 |
10-02-17 17:12 | 1104 | 1155 | 2264 | 2 | 0 | 0 | 4525 |
10-02-17 17:13 | 6 | 24 | 0 | 0 | 0 | 0 | 30 |
10-02-17 17:13 | 21 | 265 | 11 | 0 | 0 | 0 | 297 |
10-02-17 18:12 | 10 | 71 | 66 | 2 | 0 | 0 | 149 |
10-02-17 18:12 | 11 | 23 | 0 | 0 | 0 | 0 | 34 |
10-02-17 18:13 | 30 | 123 | 241 | 11 | 0 | 1 | 406 |
10-02-17 18:13 | 3594 | 3653 | 7283 | 4 | 0 | 0 | 14534 |
10-02-17 18:13 | 22 | 87 | 609 | 6 | 0 | 0 | 724 |
10-02-17 18:13 | 7 | 41 | 39 | 1 | 0 | 0 | 88 |
10-02-17 18:14 | 17 | 95 | 180 | 5 | 0 | 0 | 297 |
10-02-17 18:14 | 15 | 67 | 148 | 3 | 0 | 0 |
233
|
Please help me with this. TAC will not support as the version is EOL/EOS, let me know if you need more logs
Thanks you very much
Shameer
10-04-2017 03:56 AM
Hi Shameer,
It is most likeley a network issue. To prove it or otherwise you need a parallel set of packet captures from the IP phone and CUCM to which it is registered ( about 3 minutes leading up to the reset ). This will allow you to see if any TCP keepalives/acks or other signaling is dropped between them in either direction.
Manish
- Do rate useful posts -
10-04-2017 04:03 AM
Hi Mansh
Thanks for the prompt response, I verified the network but couldn't see anything alarming
also the reset is intermittent. We did a cluster re-boot on sunday. before the reboot we could see this happening every hour. after the re-boot it happend only 3 times yesterday 3pm, 5pm and 6pm and today just one time around 8am. I can get the console logs from the phone and the CUCM for todays incident. will that help. or we need wireshark capture on the phone. wireshark is going to be difficult as we cannot predict the time
Thanks
Shameer
10-04-2017 05:16 AM
Hello
Attached CUCM/ Phone console logs for the following event:
08:41:21 10: Name=SEP001B53B9308A Load= SCCP41.8-2-2SR4S Last=TCP-timeout
08:41:59 31: Name=SEP001B53B9308A Load= SCCP41.8-2-2SR4S File Auth Fail: SCCP41.9-3-1SR4-1S
08:41:59 25: Name=SEP001B53B9308A Load= SCCP41.8-2-2SR4S Last=Initialized
Other MACs: SEP8CB64F574494, SEP8CB64F573E5A
Many Thanks
10-23-2018 04:16 AM
Thanks
We had to rebootthe swithc and delete the ITL again to get the phone back online and stable
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide