03-09-2015 10:55 AM - edited 03-18-2019 04:09 AM
Hi. I'm working with out telco team to send sip voice calls from our VTC endpoints to an Avaya Session Manager.
I believe I have all the zones and search rules in order on the VCS side to forward the call to the SM. I am able to confirm with the telco team that the call reaches the SM but they receive the error "Cannot determine realm".
On the VCS side, I see the below output. Is the problem on the VCS or SM side? Do I need to create a trust with the SM? Thx. - F
Solved! Go to Solution.
03-09-2015 03:54 PM
An other option is to see if you get it up with 5060/udp or 5060/tcp, that might make it easier to trace. But yea, I prefer encryption as well.
Often its that you have define some kind of trust for a specific connection which might include src or dst domain, ip, port, ...
good success ;-)
Please remember to rate helpful responses and identify
03-09-2015 12:22 PM
Best is to do a trace on the VCS or the Avaya system (seems to be TLS so not so easy to look at a pcap).
Sounds pretty much that its the Avaya.
Realm is often used in authentication. I am not aware that the VCS can initiate or answer
a authentication request for a neighbor zone. Just fishing a bit in the blind, but maybe you
need to add some trust of the domain or ip of the VCS to your avaya server to allow such
kind of sip trunk.
Please remember to rate helpful responses and identify
03-09-2015 02:01 PM
Yes. I think you are onto something. TLS port 5061 needs to be open and probably in both directions. We were able to confirm that traffic was being sent to the SM but there was no entity set up for our VCS on the AVAYA SM on port 5061. It was only set up for 5060. When that entity rule was configured, our neighbor zone on the VCS failed to connect to the Avaya SM. We suspect that the Avaya SM does not have a rule sourcing from TLS 5061 to our VCS. I'll circle back with the network team. THx
03-09-2015 03:54 PM
An other option is to see if you get it up with 5060/udp or 5060/tcp, that might make it easier to trace. But yea, I prefer encryption as well.
Often its that you have define some kind of trust for a specific connection which might include src or dst domain, ip, port, ...
good success ;-)
Please remember to rate helpful responses and identify
03-30-2015 01:38 PM
TLS was a challenge and we were under a tight timeline. So instead we used SIP port 5060. We were able to connect to the Avaya Session Manager for signal communication and the border controller for media. The call works well from the endpoint but we will have to put more effort in for a proper TLS handshake. FYI.
04-02-2015 10:44 AM
Forgot to mention that we had to set up a custom zone and use filters.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide