cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8487
Views
0
Helpful
57
Replies

SPA525G SSL VPN Stability Issues

mgallant
Level 1
Level 1

I just upgraded our UC520/32U to 8.1.0 and bought a few SPA525G's to use as our teleworker phones.  I've got the SSL piece up and running and the phones come up just as they should in the remote locations.  Everything seems to be working just fine.  BUT, the remote phones seem to be acting "flakey" every so often.  Here are some issues I've run into this week:

  • Calls dropping....phone locks...phone does the equivalent of a "restart" and then the phone is back to normal
  • Sometimes, if a phone is power cycled, it will constantly reboot and will never connect to the UC520.  I've played with this a little and have found that if I have the user unplug the phone for 5 minutes...and during that time I clear all the SSL tunnels using that username...and have them power it back up, that it will often work.  Pretty flakey.
  • Call quality is often horrible.  I'm running G729 on all phones to conserve bandwidth.  Most of the time the calls are OK, but I get complaints on call quality.  We used to be running IPSEC tunnels to all the remote users and had 7965's as remote phones and they worked perfectly, so I'm inclined to believe that it's NOT a bandwidth issue.

Has only had a lot of experience with these phones using the SSL VPN client?  I can alway fall back to doing IPSEC tunnels for most of the users, but that just doesn't seem smart.

Last piece of info...phones are running the load that came with 8.1.0 which is 7.4.6.

Any help will be greatly appreciated!

Thanks in advance!!

Matt

57 Replies 57

Hey Ryan,

Sounds like another feature that just doesn't work and shouldn't be pushed mainstream.  I don't have the time to mess with TAC nor do I ever want one of them in my production system.  I guess I'll just have to wait until it's fixed.

Message was edited by: Alberto Montilla

mgallant
Level 1
Level 1

I have fallen back to IPSEC tunnels at all four locations.  I'm going to have my users report any issues to me immediately and we'll see if there are any other problems.  Hopefully it's just a crappy version of the SSL client in the phones and they can fix it.  Otherwise, they should recall the phones for anyone using it with SSL VPN and replace them with phones that work.

If anyone has any tips, let me know!!!

mgallant
Level 1
Level 1

I also had to rollback to 7.4.6 because with 7.4.7, the softbuttons always show up blank...I had to go into CME and do a restart on the ephone to get the buttons to show up...not good...

I have the same issue with a customer.  If you do a soft reset on the phone the button labels come back, or you need to remember

which key is which, since the labels are blank but the keys still work. I found 7.4.6 to be too unstable for remote vpn. At least

with 7.4.7 vpn is stable.  Clearing the phone to factory defaults, recreating the cnf files (per phone or for model) does not fix it. Doing a soft reset via the cme apps services will get the labels back, rather annoying and not really a work around we want to train the customer to do.

I was hoping 7.4.7 would help with my stability, but I dropped the first call I took after around

10 minutes.  So much for that.  If the small biz division actually takes the time to look into this and see that it's a

common issue, maybe they'll fix it and I'll try it again.  For now, though, I've fallen back to IPSEC tunnels for most of my heavy users and my occasional users can try the SSL tunnel.  I'm not going to purchase and manage any more 871's, so I guess they'll just have to deal with it until Cisco addresses these issues.

I would have kept 7.4.7, but even with the IPSEC tunnels the button labels were missing.  I fell back to 7.4.6 and the phones seem to behave much better...on IPSEC tunnels, that is!  SSL VPN is still WAAAAAAAY too buggy for me to use it right now.

Dear Matt;

Thanks for your feedback. I'll escalate your feedback to engineering, in order to take necessary actions.

Regards
Alberto

Thanks, Alberto.

These issues are obviously affecting many users so you would be making many people happy!!  :-)

I've created a cron job to reload the CME overnight so that my users can remain connected. Though this doesn't help if they accidentally reboot their phone or if they need to restart it, I would have to reload CME again which isn't feasible.

Ya, that doesn't sound like a lot of fun, Renato.  Hopefully the engineering folks will look at this and we'll have it all resolved shortly.

On another note, I've been running w/out ANY issues using 7.4.6 over IPSEC tunnels.  No call quality issues.  No dropped calls.  NOTHING!  Looks like the SSL piece really needs some work!

I've running on 7.4.7 with the ssl vpn and no issues with the vpn (knock on wood).  We have been banging on the phones and have not had any calls fail. The issue that remains is with the labels on the soft keys, but the phone reset via the cme menu's fixes that and so far it looks like that only needs to be done once. Hopefully engineering can address this soon!!!

I wish it were that easy for us! I went to 7.4.7 and it wasn't any better. Two of the four phones were in a reboot loop until they were unplugged and plugged back in. My phone didn't have that problem, and the tunnel appeared to come up fine. However, my first call on 7.4.7 was dropped, the phone restarted, and the VPN came back up...no labels on the soft keys. One of the other phones still had horrible call quality, too. And again, these are all running as solid as local phones now that the IPSEC tunnels are carrying the voice. I even tried to break it by putting everyone back on G711u rather than G729, but they're still rockin' on along!!

Todd, what software pack are you running and on which UC system?

I've running software pack 8.1(0)

The box did panic and reloaded on saturday when I went and cleared the ssl vpn users.

Cisco IOS Software, UC500 Software (UC500-ADVIPSERVICESK9-M), Version 15.1(2)T2, RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2010 by Cisco Systems, Inc.

Compiled Sat 23-Oct-10 08:04 by prod_rel_team

ROM: System Bootstrap, Version 12.4(24r)SB, RELEASE SOFTWARE (fc1)

UC_540 uptime is 2 days, 4 hours, 2 minutes

System returned to ROM by error - a SegV exception, PC 0x839D499C at 12:49:10 EST Sat Feb 26 2011

System restarted at 12:50:15 EST Sat Feb 26 2011

System image file is "flash:uc500-advipservicesk9-mz.151-2.T2"

Last reload type: Normal Reload

Yikes! THAT'S not good!!! At least it happened over the weekend! Hope that was outside of normal business hours!!

Matt,

What are you using to create the IPSEC tunnels?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: