12-06-2014 11:21 PM - edited 03-18-2019 03:44 AM
Dear Experts;
I am facing an issue while creating traversal zone in my VCS-E and VCS-C;
trying to configure remote expressway; Please find the attachment for the configuration. could you guys please support me to understand it better.
Please find the overview of the configuration which i have done;
Since I am not using TLS verified mode is set to ON, so didnt uploaded the CUCM and IM&P tomcat certificates.
uploaded the singed certificate to both VCS-C and E;
configured the traverzone;
type : Unified Communications Traversal
port : 7020 (7001 used for another traversal zone with type: traversal server; which is working fine)
h323 set to be off
when I save the configuration in both VCS-E and VCS-C the status is showing faile with reason code system not reachable.
using peer address as host name which i can ping from server to server.
so kindly support me to configure it proper if i miss something.
Regards,
Shalid
12-07-2014 02:42 AM
Addition to above , i am getting port conflict error in VCS-C
There is a port conflict on Unified CM 10.XX.XX.XX between neighbor zone CUCM Neighbor and Unified Communications (both are using port 5060);
i have another zone neighbor zone which use the same port 5060 for B2B video calls. Do I need to change the port number in VCS and SIP trunk in cucm?
12-21-2014 12:21 AM
Finally my MRA configuration works well..
Please find below steps which i had taken to complete the configuration.
Domain | Service | Protocol | Priority | Weight | Port | Target host |
sample.com | collab-edge | Tls | 10 | 10 | 8443 | tp-vcse.sample.com |
sample.com | sips | Tcp | 10 | 10 | 5061 | tp-vcse.sample.com |
Domain | Service | Protocol | Priority | Weight | Port | Target host |
sample.com | cisco-uds | tcp | 10 | 10 | 8443 | 10.200.1XX.XX |
sample.com | cuplogin | tcp | 10 | 10 | 8443 | 10.200.1XX.XX |
Validation from System Team
3. The Phone Security Profiles in UCM that are configured for TLS and are used for devices requiring remote access must have a name in the form of an FQDN that includes the enterprise domain. (this is because those names must be present in the list of Subject Alternate Names in the Expressway –C’s server certificate.
Expressway:
Expressway –C
Express E
Set Unified Communication mode to Mobile Remote Access in both VCS –C and VCS E
In expressway- E, TURN services are set OFF.
Configure Unified CM and IM&P on the Expressway- C;
Installation of suitable security certificate on the Expressway-C and the Expressway-E
Since I am not using TLS verified mode is set to OFF , so not uploading the CUCM and IM&P tomcat certificates.
Configuring traversal Zone in Expressway
Configured traversal zone for Cisco unified communication type in VCS-E and VCS-C as below;
Issue Faced during configuration:
i.In cisco call manager change the listening port from the SIP security profile used for VCS trunk from cisco call manager.
ii.SystemSecuritySIP Trunk Security Profile
Change the corresponding value in VCS-C
Any changes in the configuration of network related information may either required a system restart or re-configure the related configuration such as traversal zone …(I had face this issue and solved by this method only.)
Phone Configuration in CUCM:
Android / Iphone:
from the end user page subscribe the user service profile
Home Cluster : should be checked
Enable User for Unified CM IM and Presence : should be enabled.
Device should be associated with user.
Configure phone as below:
Login from Jabber:
No you Ready to make first VoIP call from internet using jabber.
12-23-2014 11:53 AM
So, what did you have to change to get rid of the System Unreachable?
I see the steps for your full config below, but I'm trying to figure out why, if I follow the documentation I get System Unreachable.
I have not put certificates on the devices as I was going to go with the self signed certs for now.
How did you resolve that issue?
12-24-2014 03:15 AM
Hi,
I guess that you are facing system unreachable iin traversal zone,
1. check about the ports are opened between VCS-E and VCS-C ; Please refer page# 22 in http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/config_guide/X8-1/Mobile-Remote-Access-via-VCS-Deployment-Guide-X8-1-1.pdf
2. check the credential configured in VCS-E and VCS-C traversal zone.
if everything is correct, Please recreate the same ; it will work. I had faced same issue initially the problem with port and even after everything was correctly configured i was facing the issue. then Cisco TAC advised me to re-create it again and it works well.
Let me know if you still face the issue; you can also check the dumplogs Maintenance -->Diagnostics-->Diagnostic Logging and share the logs.
Regards
Shalid.
12-24-2014 08:24 AM
Logs showed an authentication error. Turns out that you CANNOT use the self signed certs for communication between the E and C boxes.
Customer is working on getting "real" certs.
12-24-2014 08:28 AM
Not really required. You can get it signed from internal system team from their CA. This is what I have done. Generated request from each vcs server and get it signed from internal A AND uploaded to respective vcs servers.
Also did you recreated the zone?
Please keep update .
12-24-2014 09:07 AM
Yes, the zone was recreated. But the certs on the boxes were the self signed ones from installation. There is no avoiding having a CA (even a private one) involved.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide