cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5018
Views
20
Helpful
8
Replies

EXPWYC Traversal Zone TLS negotiation Failed

YAARUB F. MILAD
Level 1
Level 1
Hello,
 
I have an issue with EPWYC Traversal Zone once I configured it and saved I got the following issue:
 
 
SIP: Failed to connect to (IP<x.x.x.x>):7001 : Connect failed
 
what could be the reason for this. where to look ?
 
Thanks all
8 Replies 8

YAARUB F. MILAD
Level 1
Level 1

I am using dual interfaces on EXPWYE and E's FQDN isn't reachable by C

You can try the following.

1 First try and confirm network reachability to the Lan facing ethernet interface of the Exp-e. You can use the Ping, traceroute tools also try pinging the hostname of the expressway-e(This should help you check you have the correct DNS records) it should resolve to the internal IP.

2 You should look in the 1st DMZ , the Cisco Expressway guide provides ports that are required to be open or mapped(http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-1/Cisco-Expressway-Basic-Configuration-Deployment-Guide-X8-1.pdf). Kindly make sure yours are.

3 If the above are fine you should make sure you have configured the Traversal Zone on the EXP-E to also use the same port as you did on the EXP-C.

4 You can look at status - logs - network logs to see network data.

I have solved the issue and it was due to inappropriate Cert template

This is mean that i can`t create zone before creating cert ?

You can create a UC Traversal Zone before you get a certificate, but the it won't become active without a valid certificate on the Expressway-C that matches the subject name that you enter in the zone you created on the Expressway-E.

Thanks friend , I have other question , How can expressway E know FQDN of expressway C although i put external domain on expressway E , how connectivity through internal dns occur ?

Expressway E knows about the FQDN of the Expressway C when u enter the same while creating Traversal/UC Traversal Zone on the same. 

Expressway E doesn't initiate any connection however accepts the connection from Expressway C based on the port number configured on the UC Traversal and Traversal Zone , thus it learns about the IP address of Expressway C.  

 

 

Big thanks :)