Cisco DX650 CUCM registration over VPN

Hi
i've installed a CUCM 9.1.2 cluster with Cisco 8945s, Cisco 9971s all running SIP Protocol.    We have introduced the Cisco DX650 into the voice network, and all features are working normal on the Local LAN.   We are now testing the DX650 for a remote worker.   the Problem i'm seeing is that the DX650 will VPN into the network, email, Jabber, Calendar, Internet all work fine and is on the network via VPN.   the one issue is that the DX650 will not register with Call Manager.  we have allowed all the necessary ports through the firewall.   i've tested with Cisco IP Communicator and it registers fine for the remote worker, but the DX650 will not register. 
What can I do to troubleshoot this or see where it's getting hung up at?  I want to see logs which shows the DX650 making an attempt or not.   
Any ideas?? 

I am setting up my first Dx650 across the VPN and I am having the same problem. I used the exact same Anyconnect path and account I use for my iPhone Jabber instance but the DX will not register. If I move it into the PtoP VPN network, it registers just fine. But when on an open internet with Anyconnect, the phone won't register.
What do I look at?
Sent from Cisco Technical Support iPhone App

Similar Messages

  • Cisco jabber for mac over fortigate vpn problem

    Hi all,
    We have installed the cisco jabber for mac successfully.Jabber client able to register locally successfully.
    Calling and other features working properly. Jabber IM also working fine.
    But when we try over vpn its shows error."services are missing".All the ports are open on fortigate firewall.

    If you have detailed diagnostics from the Jabber Mac client, this would provide some more context to why it's displaying those errors.  (Help > Detailed Logging enabled) (Help > Report a problem)
    Another thing to check for would be DNS resolution of the configured servers when the Mac is VPN'd in.  If Jabber cannot resolve the DNS name, it will not know where to connect to.
    If the diagnostics are pointing towards a connectivity problem, but the firewall says it's wide open, then taking a packet capture on the Mac where Jabber is trying to register may illustrate what's going on at the network layer.

  • Jabber call to voice mail fails with fast busy over VPN

    I have an issue that I ran into with CIPC phones over a VPN.  If a CIPC phone called over a VPN and started ringing a phone the call would fail with fast busy at the time the call would be forwarded to voicemail.  I found the issue was when remote the CIPC phone would negotiate the g.729 codec, when forwarded to a voicemail pilot over a SIP trunk set to g.711 the call would fail due to codec missmatch when no transcoders are present.
    So now I am running into what I believe to be the same issue with Jabber, when on premise the calls to voice mail work just fine, but when remote they fail.  I can directly call the voicemail pilot without error, but if calling a phone the call gets fast busy at the point we are forwarded to voicemail.  Even though all my regions are set to talk to all other regions on G.711 and the voicemail SIP trunk is set to G.711, I believe with the new features in CUCM9 that a lower speed codec has been negotiated since the we are going over the VPN, or Jabber has done this as it knows it's over VPN (not sure).  WIth CIPC I could go into the settings and turn off the Optimize for Bandwidth check box and the call would negotiate G.711.  With Jabber I can't find anything that would tell my Jabber client to stay on G.711 and I can only imagine this is a codec missmatch as the following are true.
    1. CIPC and Jabber share the same line
    2. VPN established and CIPC optimised for low bandwidth un-checked
    3. Over the same VPN the CIPC phone can leave a voicemail
    4. Over the same VPN the Jabber client gets fast busy once forwarded to voicemail
    5. Voicemail environment is Exchange-UM over SIP trunk
    6. SIP trunk is assigned a Device Pool, that is assigned to a region that all other regions communicate G.711 to
    7. On CIPC if optimised for low bandwidth is checked I get the exact same issue as I get with the Jabber client (fast busy when forwarded to voicemail)
    Would anyone know what I can do in CUCM 9 to fix this issue, as said no issue when all devices are on premise.  Wondering if there is a service parameter or a way to change the codec selection so the Jabber client attempts to always negotiate G.711.  The correct answer would be to get some PVDM DSP resources and kick up a transcoder in my resource group, and that may be what I talk them into doing if I have no other options.                  

    We have been getting the exact same thing for almost a year now... since switching to FiOS Digital Voice in May of last year!  Every time I call in to report it they 'escalate' the issue but it never gets resolved.  The problem seems to be in the initial connection.  Most of the time it works fine but, several times a month, after I call to get messages and it starts to play the new message it goes dead and I get the busy signal.  I get the same message when I call back:  “I’m sorry – that account is in use at this time.  Please try again later!”  I have even called in with my cell phone and get the same message!  I HAVE EVEN used the Internet to see if I could get my messages and, when I hit Play, I get a pop-up saying: “Your Voice Mail box is currently in being accessed; please try again later.  If the problem continues, please contact our Customer Support Center at 1-888-553-1555. We apologize for any inconvenience.”  This is obviously a software bug that Verizon has no clue on how to troubleshoot OR fix!!!  I wonder how many people have the problem and just don’t bother reporting it because of the hassle?  When it first started happening they destroyed my entire mailbox and I had to re-enter the complete mailbox setup again – 3 times!!!  NEVER let them talk you into that!!!  It’s their problem and they need to fix it!!!!!!!  I wish I could go back to the ‘normal’ voicemail we originally had… they want hundred$ to switch back because I’d be breaking my #$@%^&* contract!  Good luck if you have Verizon………

  • SoftPhone over VPN audio issue

    Having a "one-way" audio issue when IPC connects over VPN to any Main Office IP Phones (7960). Remote IPC (softphone) shows "0 Received" Packets, but the IP Phone shows them as being sent.
    This does NOT happen if IPC contacts another IPC on a PC at Main Site, or any kind of phone at the other branch offices.
    Have looked at all of the audio settings on the VPN IPC unit, they are correct.
    Any ideas?

    Try to sniff the Ethernet traffic during call setup at the CallManager. When Callmanager sends Call Control messages to remote party, it could send wrong IP address or UDP port as an RTP parameters.
    Another components could block the traffic are firewalls. How do you have your VPN tunnel built? Do you use Cisco VPN Client? What terminates your VPN traffic at the central location? PIX, VPN3000 or Router? Traffic may go one way without a change, and some protocol FixUp may be triggered for this traffic on the way back. If you have access to firewall logs, check if you have any traffic dropped.
    Good luck,
    Mike
    http://www.headsetadapter.com

  • IP phone CP7911G over VPN

    Hi,
    is there voice problem with CP7911G over VPN? I have a CP7911G that works fine on my network, but when i call another extension on VPN, i hear some noise during the call.

    Tomcat port needs to be manually modified per following instructions:
    1. Change the http port in server.xml file in \conf
    value="org.apache.tomcat.service.http.HttpConnectionHandler"/>
    value="8088"/> <---------- Change this to 80
    2. Restart Tomcat from Windows Service Control Manager
    3. Change the Cisco IP Phone Services URL's Port to 80 or remove the port from the url.
    For instance,
    http://:8088/ipphone/jsp/sciphonexml/IPAgentInitial.jsp
    to
    http:///ipphone/jsp/sciphonexml/IPAgentInitial.jsp
    4. Change the URL authentication parameter is applicable. This required IPPhone to be reset via the power cord.
    For instance,
    http://:8088/ipphone/jsp/sciphonexml/IPAgentAuthenticate.jsp
    to
    http:///ipphone/jsp/sciphonexml/IPAgentAuthenticate.jsp

  • Discover Switch and router over VPN

    i am in contact with a company having many branches connecting over VPN tunnel and with different IP range in each branch
    how can i configure the LMs to discover my switch and my router over VPN

    LMS 3.0.1 and higher can use non-CDP discovery methods which should be able to find your remotely connected VPN devices.  You could use the Ping Sweep or Route Table modules to accomplish what you want.
    See https://supportforums.cisco.com/docs/DOC-9005 for more details.

  • SX20 CUCM registration rejected

    Hello guys.
    I have an issue with integration SX20 TC 7.1 with CUCM 9.0
    CUCM registration rejected.
    Provisioning CUCM checked.
    There is error in application_log of SX20:
    Sep 17 21:35:30.411 a8 appl[1583]: 7219.85 PROV I: [requestItem] Requesting http://XXX.XXX.XXX.XX:6970/CTLSEPe4c722676b41.tlv, state=ProvItemCTL (CTL requested)
    Sep 17 21:35:30.433 a8 appl[1583]: 7219.87 PROV I: [requestItem] Requesting http://XXX.XXX.XXX.XXX:6970/ITLSEPe4c722676b41.tlv, state=ProvItemITL (ITL requested)
    Sep 17 21:35:30.444 a8 appl[1583]: 7219.88 PROV I: [requestItem] Requesting http://XXX.XXX.XXX.XXX:6970/SEPe4c722676b41.cnf.xml.sgn, state=ProvItemConfig (config requested (either full or mini))
    Sep 17 21:35:30.452 a8 appl[1583]: 7219.89 PROV ERROR: [handleFailedProvRequest] http req URL=http://XXX.XXX.XXX.XXX:6970/SEPe4c722676b41.cnf.xml.sgn req status=failed: HTTP code=404
    On the SX20 I can see a message from troubleshooting tab:
    ERROR: Provisioning Status
    Provisioning failed: Provisioning is in an error state.
    What can be a reason, any ideas?

    Hello,
    Do you read http://www.cisco.com/c/dam/en/us/td/docs/telepresence/endpoint/codec-c-series/tc6/administration_guide/administering_endpoints_running_tc6_on_ucm90.pdf  ?
    Last version: http://www.cisco.com/c/dam/en/us/td/docs/telepresence/endpoint/codec-c-series/tc7/administration-guide/administering-endpoints-running-tc72-on-ucm1051.pdf
    br Oleksandr 

  • Materialized Views over VPN

    I have a Database on Oracle 10g R1 on Windows 2003 server. I have created materialized view logs on this database with
    "CREATE MATERIALIZED VIEW LOG ON <BASE_TABLE> TABLESPACE <tablespace>
    NOCACHE
    LOGGING
    NOPARALLEL WITH ROWID, PRIMARY KEY EXCLUDING NEW VALUES;"
    I have created materialized view on my Desktop database (Oracle Express Edition).
    I can generate the materialized view on XE from these mvlogs
    I created the database link
    CREATE PUBLIC DATABASE LINK DBLNK CONNECT TO <central_user> IDENTIFIED BY <central_user_passwd> USING '<central_db_sid>';
    The script to create the materialized view on XE is
    CREATE MATERIALIZED VIEW <MVIEW_NAME>
    NOCACHE
    LOGGING
    NOCOMPRESS
    NOPARALLEL
    BUILD IMMEDIATE
    REFRESH FAST ON DEMAND
    WITH PRIMARY KEY
    AS
    SELECT *
    FROM <base table>@DB_LINK ;
    1.) When I create the materailized view on LAN, it is working.
    2.) But when I try to create the same on Oracle XE over VPN, so that I do not have to connect to main database On VPN, it just hangs.
    3.) I am using Cisco VPN connection.
    4.) I am able to access the tables as "select * from <table>@dblnk", so the database link is working, but I cannot create the materialized view.
    5.) Please note that the Global names are not set on any of the databases.
    6.) I checked the v%session_wait, and I get WAIT_CLASS as NETWORK.
    7.) But I do not get any session while this Create script is fired on VPN on the Central Database in v$session.
    8.) But when I do “select * from <table>@dblnk" I get this connection in v$session on the central database.
    9.) The Global Names setting is FALSE at the main database and the XE end also.
    --> If the database link is working, and on LAN with same setting of the XE databases it is working, it should work on VPN also, right?
    --> I am able to tnsping to the main 10g R1 database on Windows 2003 server. I am able to log in to the database, access the tables and do everything,
    but not able to create the materialized view on my XE database over the VPN.
    So the most important question is
    A.) Can the Materialized views be created over VPN?
    B.) Is there some problem with the Global Names settings in database?

    What do you mean by "complex query"? Oracle defines a complex query as one that cannot be fast refreshable, so that you could not get a delta. Many queries that people would describe as complex, however, are not technically complex in an Oracle replication context or can be made non-complex.
    Justin

  • How can i use an existing vpn connection without using the option "Send all traffic over vpn connection"?

    I have been trying to get my computer (os x.7) to astablish a remote desktop connection to my work computer via a vpn tunnel. In fact I have just discovered that it works fine if i select to "send all traffic over vpn connection" from the options in the advanced setup of the vpn.
    If the option is selected microsofts "Remote desktop connection for mac" works just fine. However without selecting the option it is not taking advantage of the tunnel but tries to connect as if the tunnel would not exist.
    Now the question is how do I get program to use the vpn tunnel without checking the above option?
    Thanks for any hints and pointers.

    Then can her computer be authorized to both accounts?
    Absolutely. You can authorize any given computer to up to five iTunes Store accounts.
    If purchases are made on her account, to a computer authorized to my account, can I put those songs on my iPod?
    If you connect your iPod to her computer, yes. Tracks download only to the computer from which they're purchased, regardless of which iTunes Store account is used for the purchase. Or you could copy the tracks from her computer to yours and then authorize your computer to her iTunes Store account. But that's sort of defeating the original purpose, it would seem to me.
    is it better to buy music through Amazon downloads and/or actually purchasing CDs to avoid the security features iTunes puts on its music?
    That's certainly an option. If it's an entire album I want, I buy CDs. That way I can import them at the quality I want and to whichever of my systems I want. Amazon or one of the other download stores that offer tracks as MP3 are also an option, though for me download stores are best when you just want a couple of tracks off a given CD.

  • DNS over VPN

    Hi community,
    I am having some trouble with dns over vpn. On server side of VPN the dns is working 100% i.e servername.domain.com resolves to local IP address correctly from within network. However, when i connect into network over VPN the dns does not work correctly - it resolves servername correctly but not servername.domain.com. I can overcome this by setting VPN above my Ethernet adaptor in service order but then all my traffic gets routed over VPN connection (which i don't want) - even if I try adding network routing defn on VPN server. I probably need to do something on the VPN client (Snow leopard 10.6.1)?
    Please help!

    Rather than dnsmasq and openwrt, I'd look at the DNS server here.
    My guess here would be that the DNS configuration is invalid, or the domain name incorrect, or such.
    For a simple split-brain, you'll have one forward zone with your local Mac OS X Server box as the DNS server, and one (created for you) reverse DNS zone. And you'll be using a unique domain name or (far better) a publicly-registered DNS domain. But this smells like a DNS error.
    Post the +dig -x+ of the IP address on your LAN, and the +dig host+ and +dig host.example.com+ of the domain name on your LAN. And given this DNS information is either public or is behind a firewall and thus accessible only via VPN, please post the real data rather than masked data.

  • VOIP over VPN need clarification

    Hi,
    Recently I have implemented Site-to-Site VPN between ASA and sonic wall firewall.
    Problem: I can able to make call from ASA side(inside) Ip phone to sonic wall (inside) side Ip phone and vice versa and it’s ringing, But not able to hear voice. So I created VOIP over VPN configuration and applied appropriate service policy towards outside interface. But still I was not able to hear voice.
    Tried below mentioned t’shot steps:
    From ASA side we had two subnets (10.20.1.x/24 – Data and 10.20.2.x/24 – Voice ) and one subnet (192.168.x.x/24 ) from sonic wall side as interesting traffic ( lan to lan). When I configured site-to-site configuration on both ends my phase-1 and phase-2 came UP and can able to communicate between each other. (In interesting traffic I created two objects and bind those objects as one object-group for source i.e. ASA side lan subnet and one object for remote-Lan as destination)
    My call manager is rest behind ASA and Ip phones needs to communicate from sonic wall side to inside ASA.
    I can able to make call from ASA side(inside) Ip phone to sonic wall (inside) side Ip phone and vice versa and it’s ringing, But not able to hear voice. So I created VOIP over VPN configuration and applied appropriate service policy towards outside interface. But still I was not able to hear voice.
    So, I  done supernetting the data subnet and voice subnet into single network i.e. 10.20.x.x/16 at ASA side and applied the configuration changes (changed ACL, nonat rule, Voice QOS ACL accordingly), and I’m able to hear voice both end and I can communicate properly from ASA inside Ip phone to Sonic wall inside Ip phone and vice versa.
    My question: I’m not understanding the logic how this supernetting resolved dead voice issue.
    Pls clarify my question I’m bit confused on this.

    It's not recommended. Although VPNs guarantee a secure pipe end-to-end, they don't guarantee latency and variations in latency (Jitter).

  • CUPC Over VPN

    We resolved a VPN issue that was preventing us to be able to log in to CUPC over VPN. I am now able to log in, I can see my buddy list and their status, however the CUPC status in the bottom of the window is listed as "Offline (No Network)".
    Server Health:
    Logon Server: Not Connected - Disconnected
    Phone Config: Downloaded
    Presence: Connected
    Desk Phone: Not Connected
    Softphone: Not Active
    Voicemail: Connected
    Secure Messaging: Not Connected - Server Unreachable
    LDAP: Not Available - Server Unreachable
    What could be causing some of the servers to be connected while others are disconnected? We are running Microsoft ISA VPN.

    This is likely an ISA VPN configuration issue. CUPC creates separate connections to each system. For example, voicemail is an IMAP or secure IMAP connection, presence is a SIP connection, desk Phone is CTI, etc. All traffic is not tunneled through CUPS.
    You will need to troubleshoot the individual protocols to understand why Microsoft's VPN product is not properly transproting them. A good place to start would be attempting telnet connections from the VPN-connected machine to the locations specified in the relavent profile on CUPS. Example: Can you telnet to your LDAP server's port as defined in CUPS?

  • Voice over vpn-call not completing

    Hi folks,
    I got a problem,where with voice over vpn. So far my voip calls were running purely on shared IP internet. Today we had tried to make two side a vpn site-to-site tunnel and send traffic thru.vpn is working. (md5,des)
    The problem We faced is when i dial a number, the other side party's phone rings for 6-8 seconds and the call gets disconnected.Whether or not the called party answers the call gets disconnected after 6-8 secs. Iam not getting any ring back, while actually other side phone rings. No voice is going thru.
    my network is normalpbx--to--Cisco3800 to--Pix--to--QuintumGateway
    isdn debug shows Cause code18-no user responding.
    help me on this...

    Hi,
    can you provide configurations of the voice gateway and pix.
    Anyway my best guess is the PIX:)
    Check timers, check security policies.

  • No iTunes sync over VPN

    I would like to do an iTunes sync over VPN but this doesn't work.
    Has anyone ever done this?
    I set up VPN service on my 10.6 server and VPN works fine, I can VPN on from an outside computer to my network w/ no issue and see my network.
    When I VPN to my network on my iPad or iPhone, I get connected and the device gets an ip but I can't initiate a iTunes sync.
    Was this just not meant to be? It should.

    I'm working on trying to figure this out too.  I have a working VPN setup.  To sync itunes, I am thinking that the itunes on the remote computer must have an itunes library that points to the main itunes library on the host computer.  I think I have changed my itunes library on my remote computer to the library on the host via Preferences and the Advanced tab.  There is a place there to change the location of your itunes library.  When I click change, I can navigate to the itunes media location on the host.
    I am syncing now, and will be able to confirm the results tomorrow when I have access to the host.  Hopefully the sync won't have messed something up.  But, I am thinking this is working...

  • Jabber 9.5 phone service not registering over VPN

    TCT devices register fine over Any Connect VPN until I upgraded to 9.5!
    After upgrade IM/P and Voice Mail services connect successfully over VPN but phone service indicates it fails to get configuration from server.
    Everything works locally.  Any ideas what might have changed with 9.5 release that would impact ASA config!

    We've come across this issue also except ours is different we can't even login. Just says username or password is invalid.
    Works ok on corporate wifi
    Does not work on anyconnect over internet wifi.
    Does not work on anyconnect over 3G cellular data network.
    I can see it connects to the TFTP server pulls the XML files down connects to each CUP server in HA but both return wrong username and password.
    -- 2013-11-06 17:33:30.594 ERROR [6dee000] - [JabberWerx][log] [CupSoapCli]: login cup failed, reason: Wrong username/password
    -- 2013-11-06 17:33:30.598 ERROR [3c04618c] - [JabberWerx][log] [LoginMgr]: CLoginCup::OnLoginFailed, -1, Wrong username/password
    -- 2013-11-06 17:33:30.599 ERROR [3c04618c] - [JabberWerx][log] [assert]: /Users/jingwliu/depot/jwcpp/branches/s201301mobile/jwcpp/LoginMgr/LoginContext.cpp(940):  CacheCupServer, ASSERT(!"CacheCupServer() not implemented.") failed!
    -- 2013-11-06 17:33:30.600 INFO [3c04618c] - [JabberWerx][log] [LoginMgr]: OnStateChanged CLoginStop::OnStateChanged
    -- 2013-11-06 17:33:30.601 INFO [3c04618c] - [JabberWerx][log] [LoginMgr]: conn, canceled due to no needs. supposed:0, signning-on:0, signed-on:0
    -- 2013-11-06 17:33:30.601 ERROR [3c04618c] - [JabberWerx][log] [LoginMgr]: login, OnError, 10
    -- 2013-11-06 17:33:30.602 ERROR [3c04618c] - [JabberWerx][log] [JabberWerxCPP]: JWLoginSink::OnError, lerr:10
    -- 2013-11-06 17:33:30.602 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] ****************************************************************
    -- 2013-11-06 17:33:30.602 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] OnLoginError: LERR_CUP_AUTH: <10>. data: 0
    -- 2013-11-06 17:33:30.603 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] **************************************************************** -- 2013-11-06 17:33:30.594 ERROR [6dee000] - [JabberWerx][log] [CupSoapCli]: login cup failed, reason: Wrong username/password
    -- 2013-11-06 17:33:30.598 ERROR [3c04618c] - [JabberWerx][log] [LoginMgr]: CLoginCup::OnLoginFailed, -1, Wrong username/password
    -- 2013-11-06 17:33:30.599 ERROR [3c04618c] - [JabberWerx][log] [assert]: /Users/jingwliu/depot/jwcpp/branches/s201301mobile/jwcpp/LoginMgr/LoginContext.cpp(940):  CacheCupServer, ASSERT(!"CacheCupServer() not implemented.") failed!
    -- 2013-11-06 17:33:30.600 INFO [3c04618c] - [JabberWerx][log] [LoginMgr]: OnStateChanged CLoginStop::OnStateChanged
    -- 2013-11-06 17:33:30.601 INFO [3c04618c] - [JabberWerx][log] [LoginMgr]: conn, canceled due to no needs. supposed:0, signning-on:0, signed-on:0
    -- 2013-11-06 17:33:30.601 ERROR [3c04618c] - [JabberWerx][log] [LoginMgr]: login, OnError, 10
    -- 2013-11-06 17:33:30.602 ERROR [3c04618c] - [JabberWerx][log] [JabberWerxCPP]: JWLoginSink::OnError, lerr:10
    -- 2013-11-06 17:33:30.602 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] ****************************************************************
    -- 2013-11-06 17:33:30.602 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] OnLoginError: LERR_CUP_AUTH: <10>. data: 0
    -- 2013-11-06 17:33:30.603 INFO [3c04618c] - [csf-unified.imp.Login][OnLoginError] ****************************************************************
    I've opened a support call with our vendor.

Maybe you are looking for