cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
458
Views
0
Helpful
2
Replies

The problem with connecting cisco jabber via expressway MRA

Alexander Rusin
Level 1
Level 1

Hello friends, help me, I've been suffering for the second week now.

I have configured the expressway c\e vX14 bundle.3.7, CUCM v14.0.1.13900, IM v 14.0.1.13900

In the mode dual domain (aaa.ru - global and aaa.local - local) 

everything works from the local network, cisco jabber connects , calls , sends messages

But from the global network, it does not want to connect
in any way, it offers to accept the certificate, it offers to enter a username and password. If you enter incorrectly, it says that the user has not been identified, if it is correct, then an error occurs that "it is impossible to establish communication with the server

Log expressway-e:

Spoiler
2025-11-19T16:04:46.459+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:46,459"
2025-11-19T16:04:46.305+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:46,305"
2025-11-19T16:04:46.210+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:46,210"
2025-11-19T16:04:46.127+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:46,127"
2025-11-19T16:04:46.030+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:46,030"
2025-11-19T16:04:45.929+03:00 traffic_server[1916]: Event="Sending HTTP error response" Status="502" Reason="connect failed" Dst-ip="178.67.197.66" Dst-port="4515" UTCTime="2025-11-19 13:04:45,929"

Log expressway-c:

 

Spoiler

2025-11-19T16:04:46.449+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM2.aaa.local:6972/global-settings.xml" Rule="https://cucm2.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:46,448"
2025-11-19T16:04:46.448+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:46,447"
2025-11-19T16:04:46.296+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:6972/global-settings.xml" Rule="https://cucm1.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:46,296"
2025-11-19T16:04:46.295+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:46,295"
2025-11-19T16:04:46.200+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM2.aaa.local:6972/SPDefault.cnf.xml" Rule="https://cucm2.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:46,200"
2025-11-19T16:04:46.199+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:46,199"
2025-11-19T16:04:46.117+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:6972/SPDefault.cnf.xml" Rule="https://cucm1.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:46,117"
2025-11-19T16:04:46.116+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:46,116"
2025-11-19T16:04:46.020+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM2.aaa.local:6972/BOTR1066.cnf.xml" Rule="https://cucm2.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:46,020"
2025-11-19T16:04:46.020+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:46,019"
2025-11-19T16:04:45.919+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:6972/BOTR1066.cnf.xml" Rule="https://cucm1.aaa.local:6972/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:45,919"
2025-11-19T16:04:45.918+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:45,918"
2025-11-19T16:04:45.754+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:8443/cucm-uds/user/jabber_test/devices" Rule="https://cucm1.aaa.local:8443/cucm-uds/user/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:45,754"
2025-11-19T16:04:45.753+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:45,753"
2025-11-19T16:04:45.480+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:8443/cucm-uds/user/jabber_test" Rule="https://cucm1.aaa.local:8443/cucm-uds/user/" Match="prefix" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:45,480"
2025-11-19T16:04:45.480+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:45,479"
2025-11-19T16:04:45.309+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:8443/ssosp/ws/public/singleSignOn" Rule="https://cucm1.aaa.local:8443/ssosp/ws/public/singleSignOn" Match="exact" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:45,309"
2025-11-19T16:04:45.308+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:45,308"
2025-11-19T16:04:44.837+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://CUCM1.aaa.local:8443/cucm-uds/servers" Rule="https://cucm1.aaa.local:8443/cucm-uds/servers" Match="exact" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:44,836"
2025-11-19T16:04:44.836+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:44,836"
2025-11-19T16:04:44.687+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://cucm1.aaa.local:8443/cucm-uds/clusterUser?email=jabber_test%40alth.ru" Rule="https://cucm1.aaa.local:8443/cucm-uds/clusterUser" Match="exact" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:44,687"
2025-11-19T16:04:44.686+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:44,686"
2025-11-19T16:04:44.538+03:00 traffic_server[2259]: Event="Request Allowed" Detail="Access allowed" Reason="In allow list" Username="jabber_test" Deployment="1" Method="GET" Request="https://cucm1.aaa.local:8443/cucm-uds/version" Rule="https://cucm1.aaa.local:8443/cucm-uds/version" Match="exact" Type="Automatically generated rule for CUCM server" UTCTime="2025-11-19 13:04:44,537"
2025-11-19T16:04:44.389+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:44,388"
2025-11-19T16:04:43.974+03:00 credentialmanager: Level="INFO" Detail="Access Token accepted" User="jabber_test" UTCTime="2025-11-19 13:04:43,973"
2025-11-19T16:04:43.331+03:00 edgeconfigprovisioning: Level="INFO" Service="OAuth/SSO" Detail="OAuth tokens acquired" RequestingUser="('username', 'jabber_test')" TokenUserId="jabber_test" Scopes="['im & presence', 'voice', 'video']" UTCTime="2025-11-19 13:04:43,330"

 

 

error_log cisoc jabber:

 

Spoiler

Certificate Validation Error
2025-11-19T14:48:16.273000

Verification of certificate failed - Expand to see details
2025-11-19 14:48:16,273 INFO [0x0000006eea542cb0] [.cisco.jabber.app.cert.CertValidation(0)] [JABBER.JABBER] [verifyCertificate] - Untrusted, error = primary error: 3 certificate: Issued to: 1.2.840.113549.1.9.1=#160d61646d696e40616c74682e7275,CN=CEE.aaa.ru,OU=IT,O=ALIOTH,L=MSK,ST=MO,C=RU;
Issued by: CN=ALIOTH-CA,DC=alioth,DC=local;
on URL: ,null
2025-11-19 14:48:16,273 INFO [0x0000006eea542cb0] [mmon/PlatformVerificationHandler.cpp(38)] [csf.cert] [handlePlatformVerificationResultSynchronously] - Verification result : FAILURE reason : [UNKNOWN]
Login Error
2025-11-19T14:48:16.502000
Service Discovery failed with error code FAILED_UCM90_CREDENTIALS_NOT_SET
Tools and Resources:
Collab Edge(MRA) Validator
SAML SSO Authentication Over the Edge
Service Discovery dupError
2025-11-19T14:48:16.502000

CUCM config retrieval result Failed - CUCM credentials are not set.
2025-11-19 14:48:16,502 WARN [0x0000006eea542cb0] [m90configflows/UcmRetrievalFlow.cpp(176)] [service-discovery] [mapUcm90ResultCodeToServiceDiscoveryResult] - CUCM Result : Failed - CUCM credentials are not set.
Certificate Validation Error
2025-11-19T14:48:27.782000

Verification of certificate failed - Expand to see details
HTTP dupError
2025-11-19T14:48:28.262000
Received HTTP response: 502 for request ID #47 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/BOTR1066.cnf.xml}
2025-11-19 14:48:28,262 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #47 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/BOTR1066.cnf.xml}
HTTP dupError
2025-11-19T14:48:28.293000
Received HTTP response: 502 for request ID #48 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/BOTR1066.cnf.xml}
2025-11-19 14:48:28,293 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #48 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/BOTR1066.cnf.xml}
HTTP dupError
2025-11-19T14:48:28.321000
Received HTTP response: 502 for request ID #49 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/SPDefault.cnf.xml}
2025-11-19 14:48:28,321 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #49 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/SPDefault.cnf.xml}
HTTP dupError
2025-11-19T14:48:28.353000
Received HTTP response: 502 for request ID #50 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/SPDefault.cnf.xml}
2025-11-19 14:48:28,353 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #50 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/SPDefault.cnf.xml}
HTTP dupError
2025-11-19T14:48:28.384000
Received HTTP response: 502 for request ID #51 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/global-settings.xml}
2025-11-19 14:48:28,384 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #51 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMS5hbGlvdGgubG9jYWwvNjk3Mg/global-settings.xml}
HTTP dupError
2025-11-19T14:48:28.414000
Received HTTP response: 502 for request ID #52 to URL: PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/global-settings.xml}
2025-11-19 14:48:28,414 INFO [0x0000006eea83ccb0] [ls/src/http/BasicHttpClientImpl.cpp(675)] [csf.httpclient] [performRequest] - *-----* HTTP response code 502 connect code 0 for request #52 to PII_CED_Exception{https://CEE.aaa.ru:8443/YWx0aC5ydS9odHRwcy9DVUNNMi5hbGlvdGgubG9jYWwvNjk3Mg/global-settings.xml}
Login Error
2025-11-19T14:48:28.419000
Service Discovery failed with error code FAILED_UCM90_CONNECTION
Tools and Resources:
Collab Edge(MRA) Validator
SAML SSO Authentication Over the Edge
2025-11-19 14:48:28,419 INFO [0x0000006eea83ccb0] [vices/impl/DiscoveryHandlerImpl.cpp(671)] [service-discovery] [evaluateServiceDiscoveryResult] - ServiceDiscoveryHandlerResult return code FAILED_UCM90_CONNECTION
Service Discovery dupError
2025-11-19T14:48:28.419000

CUCM config retrieval result Failed - CUCM connection error.
2025-11-19 14:48:28,419 WARN [0x0000006eea83ccb0] [m90configflows/UcmRetrievalFlow.cpp(188)] [service-discovery] [mapUcm90ResultCodeToServiceDiscoveryResult] - CUCM Result : Failed - CUCM connection error.

1 Accepted Solution

Accepted Solutions

Alexander Rusin
Level 1
Level 1

The problem was solved by entering a command on expressway-e

 

 

xConfiguration EdgeConfigServer VerifyOriginServer: Off

 

View solution in original post

2 Replies 2

Alexander Rusin
Level 1
Level 1

The problem was solved by entering a command on expressway-e

 

 

xConfiguration EdgeConfigServer VerifyOriginServer: Off

 

dear @Alexander Rusin 
that's very nice to see your issue is fixed..

also, for more information about this problem, i searched & founded this community posts >>

https://community.cisco.com/t5/unified-communications-infrastructure/mra-tls-between-expresswayc-and-cucm/td-p/4688606

https://community.cisco.com/t5/collaboration-applications/mra-login-over-expressway-e-is-failing/td-p/4833163


(Rate by "Helpful" or "Accept") (محمدرضا هادی_ایران) (Email: morez.hadi@gmail.com)