Branch Office VOIPs do not register.

Hi:
I've been breaking my head on this for a few weeks and nothing seems to be working.
I have three PIX 515e, one at each office.
ALL VOIPs are Polycom 300IP phones.
We have a main office (called PB) with 15 VOIP phones.
We have a branch office (called JAX) with 2 VOIP phones.
We have a branch office (called JADE) with 2 VOIP phones.
All site VOIPs must register with a hosted PBX outside of all three offices (called TN).
All 15 VOIPs at PB are registering and working with TN.
Only one of two VOIPs at JAX is registering with TN.
No VOIPs at JADE are registering with TN.
VPN Tunnels are up and functioning between PB and JAX and PB and JADE. Able to ping both ways and users in both branch sites are able to map folders to our servers.
I have opened UDP 5060 (SIP) on all interfaces. It seems there is initial conversation between TN and JAX and JADE but receiving following errors at both branches.
Pre-allocate SIP for secondary channel blah blah blah and followed immediately with a
Teardown UDP connection blah blah blah
I have attached configs for all three PIX 515e boxes (edited for security).
Could somebody take a gander at this and help me out. I'm at a complete loss.
Thank you so much in advance and have a great day!

Thank you for the feedback and suggestion GTG! I went ahead and posted it on the "security" bb and I'm going to look into SIP inspection.
Can you please MOVE this thread to the Security section and delete the duplicate post you've created?
Here's the link to your duplicate post:  https://supportforums.cisco.com/thread/2260989

Similar Messages

  • Asha 503 voip accounts not registering on 3G & not...

    Hi all.
    I had some trouble to find the proper Forum area for this issue. I hope this is the right place.
    Here is the description of the issue:
        [1]Before inserting any SIM into Asha 503:
        [1.1]Through Wi-Fi, mobile registers and makes voip calls, both using encryption and not using encryption;
        [2]After inserting Operator SIM Card (Vodafone)
        [2.1]Accounts (both using and not using encryption) do not register via 3G (even though the sim card allows that - I use same card in other devices);
        [2.2]WiFi connection doesn't register encrypted accounts any more. Tried removing SIM card and restart phone but looks like the "feature" got permanently damaged
    I did also try to reinstall firmware but issues remain (meaning that something is being left there from Operator SIM). Anyhow, I should be able to insert a SIM in the phone, otherwise it is not a phone right?
    Further info: Previously I have been testing an Asha 311:
        [1]Registers and calls through 3G and WiFi (both using or not using encryption);
        [2] Has an issue with Encrypted sip accounts- when looses WiFi and comes back to same WiFi network, is not able to re-register (this problem doesn't affect sip accounts which are not encrypted).
        [2.1] This problem is not related to SIM - After reinstaling firmware, the symptoms remain.
    NOTE: I quit from trying to solve this problem - that is why I bought the 503 .
    If anybody as a clue how to help solving Asha's 503 issue, I would be truly grateful and happy.
    Dinis
    PS In the past I came accross a problem in Asha 311 that was returning error when some apps were trying to access to internet and the solution was this:
    http://developer.nokia.com/Community...ries_40_pho​nes
    I am not sure if this would be the same kind of problem occurring now in the Asha 503 (however, Asha503 doesn't seem to have same kind of settings as in Ash 311)

    Out of the blue after a few restarts, Asha 503 started to work with no problems when connection is WiFi (both encrypted and not encrypted accounts)*.
    When connection is 3G it doesn't work at all (it is the same if account was created via UI or though provisioning).
    So, the updated Status is:
    Asha 503 - voip over 3G not working
    Accounts (both using and not using encryption) do not register via 3G (even though the sim card allows that - I use same card in other devices);
    Experienced only once - after testing several times turning on and off WiFi to force 3G, did not register via WiFi any of the accounts - had to restart the device. But this happened only once. Normally there are no issues registering through WiFi.
    Asha 311j - issues reregistering encrypted accounts when mobile leaves and comes back to WiFi
    Registers and calls through 3G and WiFi (both using or not using encryption);
    Has an issue with Encrypted sip accounts- when looses WiFi and comes back to same WiFi network, it is not able to re-register (this problem doesn't affect sip accounts which are not encrypted).
    This problem is not related to SIM - After reinstaling firmware, and not inserting SIM card, the symptoms remain.
    *the unique difference from this morning was that I had removed and inserted again the SIM card - after I had changed some mobile data settings via provisioning. but in the morning was not working.
    If anyone has any idea on how to properly  solve this, would help me loads.
    Cheers all

  • Branch office web-to-go is not starting

    Hi,
    I have downloaded and installed the Oracle Lite Branch Office setup from server's webtogo/setup. But the webtogo in branch office PC is not starting. The htttp://localhost/webtogo and listener are not started even after executing the executables manually.
    The PATH variable is set correctly. The branch office PC has Windows XP.
    Regards,
    Aneesh

    Hi,
    webtogo -d option is giving following error.
    E:\mobileclient\bin>webtogo -d
    log9: [LOADING wtgos.dll BOAdminToolNative]
    log9: [BOAdminToolNative wtgos Loaded Successfully]
    log9: MODE_BRANCH CONNECT_STRING =jdbc:polite@:1160:
    log1: Translated JDK:'Cp1252' to IANA: 'WINDOWS-1252'
    log1: Mount point jdbc:polite@:1160:WEBTOGO oracle.lite.web.ifs.OMFS@145d068
    log9: java.sql.SQLException: [ODBC 08001] unable to connect to data source
    log9: at oracle.lite.poljdbc.LiteEmbJDBCConnection.jniDriverConnect(Native Met
    hod)
    log9: at oracle.lite.poljdbc.LiteEmbJDBCConnection.connect(Unknown Source)
    log9: at oracle.lite.poljdbc.LiteType2JDBCFactory.createConnection(Unknown Sou
    rce)
    log9: at oracle.lite.poljdbc.POLJDBCConnection.<init>(Unknown Source)
    log9: at oracle.lite.poljdbc.OracleConnection.<init>(Unknown Source)
    log9: at oracle.lite.poljdbc.POLJDBCDriver.connect(Unknown Source)
    log9: at java.sql.DriverManager.getConnection(Unknown Source)
    log9: at java.sql.DriverManager.getConnection(Unknown Source)
    log9: at oracle.lite.web.JupConnection.<init>(Unknown Source)
    log9: at oracle.lite.web.JupConfig.createConnection(Unknown Source)
    log9: at oracle.lite.web.JupConfig.getConnection(Unknown Source)
    log9: at oracle.lite.web.JupConfig.getStatement(Unknown Source)
    log9: at oracle.lite.web.JupServer.loadMimes(Unknown Source)
    log9: at oracle.lite.web.JupConfig.reload(Unknown Source)
    log9: at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    log9: at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    log9: at oracle.lite.web.JupServer.initialize(Unknown Source)
    log9: at oracle.lite.web.JupServer.listen(Unknown Source)
    log9: at oracle.lite.web.JupServer.main(Unknown Source)
    log-1: ============== Server Exception - Begin ==================
    java.sql.SQLException: [ODBC 08001] unable to connect to data source
    at oracle.lite.poljdbc.LiteEmbJDBCConnection.jniDriverConnect(Native Met
    hod)
    at oracle.lite.poljdbc.LiteEmbJDBCConnection.connect(Unknown Source)
    at oracle.lite.poljdbc.LiteType2JDBCFactory.createConnection(Unknown Sou
    rce)
    at oracle.lite.poljdbc.POLJDBCConnection.<init>(Unknown Source)
    at oracle.lite.poljdbc.OracleConnection.<init>(Unknown Source)
    at oracle.lite.poljdbc.POLJDBCDriver.connect(Unknown Source)
    at java.sql.DriverManager.getConnection(Unknown Source)
    at java.sql.DriverManager.getConnection(Unknown Source)
    at oracle.lite.web.JupConnection.<init>(Unknown Source)
    at oracle.lite.web.JupConfig.createConnection(Unknown Source)
    at oracle.lite.web.JupConfig.getConnection(Unknown Source)
    at oracle.lite.web.FileHandlerUtil.<init>(Unknown Source)
    at oracle.mobile.job.Scheduler.<init>(Unknown Source)
    at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    at oracle.lite.web.JupConfig.initializeRM(Unknown Source)
    at oracle.lite.web.JupServer.initialize(Unknown Source)
    at oracle.lite.web.JupServer.listen(Unknown Source)
    at oracle.lite.web.JupServer.main(Unknown Source)
    ================== Server Exception - End ====================
    Noticed that listener is not getting started,
    E:\mobileclient\bin>olsv2040 /start
    OliteService reports the following error:
    OliteService failed, Error Code: (0x5), Message: Access is denied.
    Internal message: StartService failed in CmdStartService function.
    Forgot to mention earlier,
    During installation of branch office client, I recieved following Warnings,
    1. Operating system message: Password doesnot meet minimum security requirements. Check the password length, complexity and history.
    2. No mapping between accounts and security ID was done.
    Thanks,
    Regards,
    Aneesh

  • Branch Office will not host Microsoft services/servers - Sites and Subnets

    Hi,
    The scenario is the following:
    1 Domain. Windows 2012 R2.
    6 sites. 1 DC per site. 3 subnets per site.
    5 sitelinks.
    The sites diagram is the following:
    The branch office "SITE04" will not host any Microsoft service/server/PC. Network routing/flow scheme will not change (branch office SITE04 reamins routing traffic to/from SITE05 and SITE06).
    The questions are:
    Does the existing SITE04 subnets must be deleted?
    Does the existing SITE04 site must be deleted?
    Does the existing SITE04-SITE05 and SITE04-SITE06 site links must be deleted?
    if yes to any of the above questions?
    How to redesign the subnets/sites/site links?
    Thanks in advance!

    Thanks MrX for your response.
    The SITE04 branch office will not host Microsoft-based PCs/Servers/Services. SITE04 will be used for network traffic routing purposes and will host servers from another platform.
    Why to mantain SITE04 subnets?
    Thanks in advance!
    In this case, maintaining the subnets would be optional.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • How many AP supported in each branch office-Flex7500

                       Hi,
    From the document, it said only 50 AP supported in each branch for 7500. My case is the HQ has about 100 AP and other BO has less than 10 for each. I am planning to deploy 7500 in the DC and all the AP are in flexconnect mode. But since the limitation of the AP number for each branch office, I can not deploy 7500 in DC to manage the HQ office AP at all. Any idea?
    <A href="http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml#wbnd" mcehref="http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml#wbnd">http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml#wbnd
    Data
    640 kbps
    300 ms
    50
    1000
    Data + Voice
    1.44 Mbps
    100 ms
    50
    1000
    <BR type="_moz" mozdirty></P>

    That is for FlexConnect groups. You can have as many FlexConnect APs as you want. You would just have to use multiple FlexConnect Groups if you require using FlexConnect Groups. This is really only used if your using 802.1x and have multiple radius servers.
    Sent from Cisco Technical Support iPhone App

  • Class Not Registered error upon using MS Office Report

    Hello,
    Using LabVIEW 2010, I've just installed the Microsoft RGT trial from NI, along with the Office 2010 trial from Microsoft. Upon trying to drag the MS Office Report VI to my block diagram, the configuration dialog appears but immediately an error dialog shows up over top, with a Class Not Registered error. Attached is the screenshot. If I close the error and try to configure the VI for a basic Excel report, I get a file-not-found error in reference to the Excel template, which I have verified is indeed at the target path and opens with my version of Excel just fine. Any ideas how to get past this error?
    Attachments:
    error.JPG ‏42 KB

    Hello,
    It sounds like you have to reinstall the RGT. Have a look at this documentation.
    http://digital.ni.com/public.nsf/allkb/B7F980D169474D568625760E0055D55E
    Eric
    Eric Liauw
    AE Specialist - Automated Test | CLD | CTD
    National Instruments

  • The 'Microsoft.ACE.OLEDB.12.0' provider is not registered on the local machine (Windows Server 2008 R2 (64) vs MS Office 2007)

    We just have switched our local server from 32-bit to 64-bit machine and now we have Windows Server 2008 R2 Service
    Pack 1 with MS Office 2007. On server we are running an application in ASP.Net 3.5 using visual studio
    2008. All users have 32-bit windows 7 and MS Office 2007.
    when user tries to import data from Excel to Database (SQL Server 2005), error comes as
    "microsoft.ace.oledb.12.0 provider is not registered on local machine".
    I have tried a solution by installing Access Database Engine 2007 Office System Driver on the Server, but the error
    was same. Now what should I do to resolve this problem??? Should we install Office 2010 64-bit on the Server or is there any other solution???

    Hi,
    Thanks for your posting.
    the file can be made in excel 2007, try to install:2007 Office System Driver: Data Connectivity Components
    http://www.microsoft.com/en-us/download/details.aspx?id=23734
    Regards.
    Vivian Wang
    TechNet Community Support

  • Windows 8.1 laptop not connecting to domain in branch office

    We have a problem with a laptop. 
    It is installed in our Head office (The Netherlands), just like all other laptops by using an image.
    Tested and working on the domain.
    The user had to go to one of our branch offices (China) and when he connected there, the laptop just won't connect to the domain.
    When he plugged in the laptop, it keeps trying to connect it's directaccess.
    Other laptops (same image) immediately recognize the domain network, but this laptop just won't.
    I am able to ping everything on the local network (MPLS connection), from HQ to all Branch offices but not access them.
    I've tried changing the DNS settings, but without any result.
    Any suggestions?

    Hi,
    According to this tool's description, I think it should be helpful to check system current enviroment, such as network, certificates, etc. problem. Actually according to your description, I doubt it probably network enviroment of ISP problem, but we should
    find a way to verify our suspect. Then this tool would be convenient, it also would generate a trace log and it would be helpful with troubleshooting.
    The DirectAccess Client Troubleshooting Tool is a graphical application, based on the .NET Framework, which checks the health of a DirectAccess client by running various tests.  Built-in health tests: The following tests are currently implemented:
    Network interfaces Network location (NLS and NRPT DNS) IP connectivity (6to4, Teredo, IPHTTPS, entry point in a multisite setup, DNS) Windows Firewall (applied profile, Firewall outbound rules) Certificates (EKU Client Authentication, trust chain for AIA and
    CRL) IPsec infrastructure tunnel (Domain SysVol share) IPsec intranet tunnel (PING and HTTP probes) Additional features Run post-check script (PowerShell, VBScript, BAT or CMD file)
    Roger Lu
    TechNet Community Support

  • Clients Not seeing DHCP server at branch office or not accepting ip offers (NO LOG REPORTS KIND OF IN THE DARK)

    Hi there i am having an issue that has popped up recently i have a DC at a branch office that is connected to the main office DC via a Persistent Demand Dial connection in RRAS. Everything was working properly according to me until i found out that the Network
    Admin who manages the branch office network failed to notify me that client machines weren't getting IP addresses from the DHCP server. This server was recently installed and wasn't fully implemented till about a week ago when i configured the Demand Dial
    connection in RRAS up until that point it just had a regular old VPN connection to the main office while we worked out the kinks with a few things. the things ive tried so far to get DHCP working are as followed
    1.Rebooted the branch office server (MULTIPLE TIMES)
    2. Uninstalled the DHCP Role and re-installed it....To my surprise 1 client managed to get a ip on its lan adapter after DHCP was re-installed but nothing else
    3. Disconnected the connection between the main office DC and the Branch office DC as i figured the main office DC DHCP server might be interfering with the branch office DC DHCP Server but nothing happened 
    4. Unauthorized and Reauthorized the main office DHCP server and the branch office DHCP server nothing changed
    5. sifted through multiple log files on both servers and found noting in fact DHCP logs are empty on both servers
    6. restored backups of the DHCP servers from when they were working
    7. came here cause im out of ideas and im pulling my hair out
    here are the current statistics from the problem server
    Start Time: 7/12/2014 2:02:10PM
    Up Time: 1Hours, 18 Minutes, 41 Seconds
    Discovers: 90
    Offers: 90
    Requests: 2
    Acks: 13
    Nacks: 0
    Declines: 0
    Releases: 0
    Total Scopes: 1
    Total Addresses 253
    In Use 2 (0%)
    Available: 251 (99%)
    Id like to add that RRAS was getting IP addresses from the problem server up until the point i uninstalled the role and re-installed it
    heres is a ipconfig /all from the problem server
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : MNB-DC
       Primary Dns Suffix  . . . . . . . : VTEACR.LOCAL
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : Yes
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : VTEACR.LOCAL
    PPP adapter Remote Router:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Remote Router
       Physical Address. . . . . . . . . :
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.141.70.25(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : 10.141.70.10
       NetBIOS over Tcpip. . . . . . . . : Disabled
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
       Physical Address. . . . . . . . . : 00-16-35-AB-D3-05
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::d9e:daa4:34dd:db44%10(Preferred)
       IPv4 Address. . . . . . . . . . . : 10.141.80.102(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : fe80::226:5aff:feb7:5b3c%10
                                           10.141.80.1
       DNS Servers . . . . . . . . . . . : ::1
                                           10.141.80.102
       NetBIOS over Tcpip. . . . . . . . : Enabled
    PPP adapter RAS (Dial In) Interface:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : RAS (Dial In) Interface
       Physical Address. . . . . . . . . :
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 169.254.238.243(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                           fec0:0:0:ffff::2%1
                                           fec0:0:0:ffff::3%1
       NetBIOS over Tcpip. . . . . . . . : Disabled
    Tunnel adapter Local Area Connection* 8:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{427DF66B-3B30-40B1-B67E-B5587465C
    394}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 9:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 02-00-54-55-4E-01
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 11:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.ziricom.com
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 12:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.VTEACR.LOCAL
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 13:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.{BE201060-A9B9-404A-8361-F8FFB82F5
    6F6}
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 14:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #5
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 15:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.VTEACR.LOCAL
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 16:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #7
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Tunnel adapter Local Area Connection* 19:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : isatap.ziricom.com
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    if anymore information is needed please let me know i have full access to everything on the network so its not a problem and i am able to remotely access the branch office DC and all computer and switches at any time of the day
    Viper Technologies Computer Repair Putting The Venomus Bite Back In Your Computer We Are Located In Antigonish ,NS Canada Check Us Out HTTP://WWW.VIPERTECHNOLOGIES.TK

    Hi,
    Does this issue occur on one client or multiple?
    Please check this article:
    http://technet.microsoft.com/en-us/library/cc757164(v=ws.10).aspx#BKMK_5
    Regards.
    Vivian Wang

  • To make a new site or not? (for branch office with small number of people)

    We have a main office, with our DC (DC01) and a single site (SiteHO), and we are about to open up a new branch office in another city.  This branch office is connected to the head office via a 5 Mbps MPLS network.  The branch office will have around
    5-7 domain joined workstations, and the people there will require access to the existing file and exchange servers in the head office. 
    I was thinking about not adding a RODC in the branch office and not creating another site in AD for the branch office either.  My thinking is that since the number of users is relatively low, it doesn't warrant having a new RODC and site.  The
    traffic generated by the 5-7 user logon activities will be minimal, and the local profiles are stored on the workstations (no roaming profiles), so there shouldn't be much WAN link impact.  Obviously I would have to add the subnet from the branch office
    to the SiteHO site. 
    Can anybody think of something wrong with my reasoning?

    I think the dedicated line has a little to do with AD since its used both to authenticate the users and move the data.
    I am not sure what bandwith you get from an internet provider in your location, but for example you might get a 100Mb internet connection from an ISP. A VPN tunnel over a 100Mb internet connection I am guessing is faster then a 5Mb guaranteed MPLS link.
    The advantage of MPLS is that you can have QoS policies for voice and video traffic.
    If users move 'very large files' perhaps a local file server might be an good option. DFS replication can save a lot of bandwidth in that case. And then you would have 'local resources' in the branch and in case of wan failure the users will not be able
    to access the local file server resource. So you would need a secondary DC in that location.
    And if they are moving the files think (and check) the impact on the MPLS, because authentication requests go through that link, Exchange traffic (RPC MAPI) goes through that link so these might be affected. For example, lets say you have 2GB mailboxes.
    All Outlook users use OST files. One user's profile gets corrupted and needs to be rebuilt. The Outlook client sets up a fresh OST copy of the mailbox so now its downloading a 2GB mailbox copy over a 5Mb MPLS while some other user is moving a 'large file'.
    By local resources I am referring to file servers, printers, applications in the branch location that require AD authentication. Authentication works with both VPN and MPLS and in case the wan/vpn is down users can even log in with
    cached credentials.
    Hope it helps.
    http://mariusene.wordpress.com/

  • Interface not registered (Exception from HRESULT: 0x80040155) when calling Microsoft.Office.Interop.Outlook.MAPIFolder.get_Folders()

    Hi All,
    I have an Outlook COM addin written in C#. It is working without any issues on most client machines, but since of late it has started giving the above Exception for some clients running Outlook 2010.
    I understand that the issue is that the particular interface is not registered properly on those machines. I would like to know what in dll that interface is located and what could cause it to be missing? Can it be a component that had been deselected during
    the installation of Outlook? If so, what is that component? Or should the dll be manually registered (using REGSVR32)? Or will running a simple repair on Outlook work?
    Thanks!!

    Hello Thimila,
    What code do you use exactly?
    Try to run the problematic piece of code from VBA as a macro. Do you get the same error message? If so, you need to repair Outlook, it looks like windows registry entries were corrupted. 
    If you don't get such error in VBA it indicates that you didn't install/copy one of the required prerequisites to the end user PC (interop libraries, .net runtime and etc.). Make sure that all the required prerequisites are installed correctly. See Deploying
    an Office Solution for more information.

  • 2 Office VOIP design, and PVDM usage

    Dear colleagues,
    i have 2 , A and B sites, with same spec's "number of users 16 with IP phones, and just VOIP needed , both will connected via Internet using a FW then IPsec to other branches",
    for VOIP solution
    A:will call PSTN via 4 analog lines, so i need 4 FXO
    B:will call PSTN via VOIP provider so no FXO needed
    each branch will call other branches using VOIP h323 trunks
    my questions are,
    1- PVDM needed?? for both sites?? why PVDM needed??
    2-and if both sites will not call PSTN, directly, i.e if i used send landlines calls from the branch to my central office, i.e if i didnt use analog line nor VOIP provider to contact PSTN, IS PVDM NEEDED IN THIS CASE??
    your help is appreciated
    thanks

    Hello Ahmed,
    Hope I'm answering all your questions
    A-hereunder example of VOIP senario and give me your commect.
    1-if phone 1 call phone2, no transcoding needed?
    No. Calls between phones controlled under the same CME will use G.711 and both phones supports G.711.
    2-if phone 1 call phone 3, transcoding needed?, if needed, what CME is responsible for transcoding?, how it done, from both drection of voice traffic?
    No. Call will be in G.729 and will work since Cisco IP phones (besides G.711 and other codecs) supports G.729. If for some reason phone 3 doesn't support G.729, then CME_b needs a transcoding resource to connect the call successfully.
    B-Unity Express used only for Voice mail?, or it has another functions?
    Supports Voicemail, Integrated Messaging, Auto Attendant, IVR and Fax.
    C-if there is a CME router without PVDM module exist, can this router contain unity express?
    Yes.
    D-when i access unity express from CME CLI, i can use below command:
    Yes. That command is used to access CUE via CLI, although you can use GUI as well.
    E-what is this service-engine 0/0?, is it the AIM module??
    Yes.
    F-from the same CME router
    1-there is PVDM2-32, and PVDM2-16, how i can choose the PVDM needed for my network?
    Depending on the requirements (i.e. connections to PSTN, conferencing, transcoding, etc) you will need to calculate the total number of PVDMs. For this you can use the Cisco DSP Calculator: http://www.cisco.com/web/applicat/dsprecal/dsp_calc.html
    2-the AIM service engine 0, is it the Unity Express??
    Yes.
    3-when i access it , i use service engine 0/0, why 0/0, it is AIM 0 only, there is no 0/0?
    The AIM is installed in slot 0, subslot 0.
    F-what is related configuration to PVDM?, i.e, is there any provisioning configuration commands?
    The most common is for conferencing and transcoding resources. Check this: http://www.cisco.com/en/US/docs/ios/12_3/vvf_c/interop/intcnf2.html
    G-when transcoding done by PVDM, it it need any configuration or done automatically?, i.e if G711 tranlated in real time to G729, is it use a specific commands in the run config, or just the existance of PVDM make the transcoding done automatically?
    You configure the resources as shown in the link above. Once you get the resources registered and configured correctly, they will be invoked by CM/CME automatically when the situation demands.
    H-is there is any config needed to provision AIM?, or just access the service engine and config the voice mail?
    You first configure IP connectivity to the module. Check this: http://www.cisco.com/en/US/docs/voice_ip_comm/unity_exp/design/design21/cuenwinf.html#wp1008330
    Next you can access it via CLI or GUI for configuration and integration to CM/CME.
    http://www.cisco.com/en/US/products/sw/voicesw/ps5520/products_configuration_example09186a008037f2a9.shtml#t11
    http://www.cisco.com/en/US/products/sw/voicesw/ps5520/products_configuration_example09186a0080289ef0.shtml
    Hope it helps. Thank you for the ratings.
    -- Adrian.

  • Branch Office CME design Verification

    Hi All,
    Please refer to the attached network diagram.
    I need to verify this can be implemented and would work.
    We have a branch office moving to a new location and they intend to keep their existing CME (for business reasons),  provided by their local service provider with ISDN line for calls to the PSTN. This is managed by the service provider and we have no access to it. However we would like to grant them connectivity to the existing corporate voice network via an IP VPN connection, which shall be put in place soon. This will enable  the branch make site to site calls within the corporate network
    With a SIP trunk between the internal and external CME, I intend to make all the phones register with the Call Manager, however on the call manager , set a route pattern for calls going out to the PSTN from this branch back to the internal CME and this will then be matched by a SIP dial peer  directing the call to the external CME out to the PSTN.
    My worry is with the delay  that might be introduced when making a PSTN call as the internal CME has to first contact the call manager in order to know where to send the call.
    So my questions are as follows,
    1. Is this solution feasible especially in terms of delay? If not,
    2. Are there any other ways to achieve the same scenario
    Thanks,
    Yomi

    Are the phones at the branch office going to register to the Internal CME? If so, all configuration for outbound dialing will be done on the Internal CME, not on UCM. ie. dial-peer on the Internal CME for outbound dialing. For phone connectivity back to UCM, you will have a SIP trunk between UCM and internal CME and that is perfectly acceptable. You "might" see some quality degradation but that is to be expected from Internet based WAN connectivity. If your RTT delay is greater than 150ms, then you might see some quality issues.

  • Branch office setup with L3 switch and router with IOS security

    Hello,
    I am in the process of putting together a small branch office network and I am in need of some design advise. The network will support about 10-15 workstations/phones, 3-4 printers, and 4-5 servers. In addition we will eventually have up to 25-30 remote users connecting to the servers via remote access VPN, and there will also be 2-3 site-to-site IPSec tunnels to reach other branches.
    I have a 2911 (security bundle) router and 3560 IP Base L3 switch to work with. I have attached a basic diagram of my topology. My initial design plan for the network was to setup separate VLANs for workstation, phone, printer, and server traffic. The 3560 would then be setup with SVIs to perform routing between VLANs. The port between the router and switch would be setup as a routed port, and static routes would be applied on the switch and router as necessary. The thought behind this was that I'd be utilizing the switch backplane for VLAN routing instead instead of doing router-on-a-stick.
    Since there is no firewall between the switch and router my plan was to setup IOS firewalling on the router. From what I am reading ZBF is my best option for this. What I was hoping for was a way to set custom policies for each VLAN, but it seems that zones are applied per interface. Since the interface between the router and switch is a routed interface, not a trunk/subinterface(s), it doesn't seem like there would be a way for me to use ZBF to control traffic on different VLANs. From what I am gathering I would have to group all of my internal network into one zone, or I would have to scrap L3 switching all together and do router-on-a-stick if I want to be able to set separate policies for each VLAN. Am I correct in my thinking here?
    I guess what I am getting at is that I really don't want to do router-on-a-stick if I have a nice switch backplane to do all of the internal routing. At the same time I obviously need some kind of firewalling done on the router, and since different VLANs have different security requirements the firewalling needs to be fairly granular.
    If I am indeed correct in the above thinking what would be the best solution for my scenario? That is, how can I setup this network so that I am utilizing the switch to do L3 routing while also leveraging the firewall capabilities of IOS security?
    Any input would be appreciated.
    Thanks,
    Austin

    Thanks for the input.
    1. I agree, since I have only three to four printers, they need not be in a separate VLAN. I simply was compartmentalizing VLANs by function when I initially came up with the design.
    2. Here's a little more info on the phone situation. The phones are VoIP. The IP PBX is on premise, but they are currently on a completely separate ISP/network. The goal in the future is to converge the data and voice networks and setup PBR/route maps to route voice traffic out the voice ISP and data traffic out the other ISP. This leads up to #3. 
    3. The reason a router was purchased over a firewall was that ASA's cannot handle routing and dual ISPs very well. PBR is not supported at all on an ASA, and dual ISPs can only be setup in an active/standby state. Also, an ASA Sec+ does not have near the VPN capabilities that the 2911 security does. The ASA Sec+ would support only 25 concurrent IPSec connections while the 2911 security is capable of doing an upwards of 200 IPSec connections.
    Your point about moving the SVI's to a firewall to perform filtering between VLANs makes sense, however, wouldn't this be the same thing as creating subinterfaces on a router? In both cases you are moving routing from the switch backplane to the firewall/routing device, which is what I am trying to avoid.  

  • Help on set up branch office with 2921 H323 gateway

    I setup a new branch office with 2921 H323 gateway and cucm in HQ.  When I call a number in remote office, I get dead silence and busy tone.  However, user can hear ring at the remote location and able to answer the phone.  I was able to talk to him.  Any place I need to check? 
    Question #2, should cucm in HQ handle all calls between HQ and remote office?  I tried to call from my VoIP phone to remote office VoIP phone and monitored remote office GW running "debug voip ccapi inout".  I saw messages like gateway is handling calls.  Is this normal?  
    I'm fairly new to VoIP environment, still trying to learn.  Thanks. Let me know if you need anything to troubleshoot this. 

    I think that's where I'm confused.  I'd like to have CUCM to handle every calls for remote sites.  when I searched for the number I'm dialing for remote office, there is a route pattern that covers this number and it points to gateway.  This route pattern covers all of their local numbers including our remote office numbers.  For example, I have 9.1201456XXXX point to H323 GW.  That I got it.  However, I want the numbers belong to our office like 1111 don't go to GW for call processing.  Do I make sense?  I want only their local call to remote office go through GW not our internal call between our offices.  I'm sorry if I don't make much sense.  Thanks for your help. 

Maybe you are looking for