cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
488
Views
0
Helpful
5
Replies

MRA Expressway E wants to use RMS or UCM_TelepresenceRoom license

JaySchiller
Level 1
Level 1

Hello!

I have a Expressway Cluster setup that is supposed to be ONLY for MRA.

And yet, the Expressway E Servers (and only the E Servers) keep complaining that they are out of compliance and need either a RMS License or a UCM_TelepresenceRoom license (that alternates). 

Does anyone have any idea what can cause this or how I can find out. Or even better how do I prevent it. 

Thanks!

Kind regards, 

J

5 Replies 5

Look at the call history in the Expressway E. I bet you are getting spam calls that are trying to use your Expressway for calls. One easy way to cut that down is to not allow UDP 5060 to your E. MRA uses TCP. You may also still need to apply some access lists as well.

JaySchiller
Level 1
Level 1

Hello! 

Yeah, thats what I suspected. What am I looking for in the call list? "non-traversal" calls?

TCP and UDP are both disabled. Only TLS is allowed. 

So, if this is Spam there is no way to really prevent this, right? Ok. I could use Access Lists but then the Spam invites come from a different IP, so I constantly have to maintain the access lists. That is not really an option. 

Question is, what happens to the Expressway? Is it only this annoying "Out of Compliance" message and I can just ignore it?
Or will the System stop working after a grace period?

And isn't this something that you should see on pretty much every Expressway that is accessible via the internet?

JaySchiller
Level 1
Level 1

Hi,
as written in the other post, but this is only applicable for registrations.
If someone tries to register to your expressway, a telepresence license count will be added, even if the registration isn't successfull at all.

The same for normal H.323 or SIP calls to your expressway. But this you have to prevent with call policy rules.

I'll bet those calls are using '@' your IP address. What I have done to resolve this is to use an ACL that only allows '@'userdomain.com. I usually even go a step further and require the LHS to start with a letter. Most of the spam calls are numeric only.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: