Internal user to External user P2P call failed.

Hi,
Environment:-
Lync 2013 FE (collocate mediation role) - 1
Lync 2013 Edge server (Single IP FQDN)– 1
Public IP -1
Ports:
Access Edge: 5061
Web Conference: 444
A/V Edge: 443
Ports opened on External Firewall
TCP - 5061,443,444
UDP – 3478
Tested Scenario
Internal to Internal
à Call, Video and Sharing are working fine.
External to External
à Call, Video and Sharing are working fine.
Internal to External (vice versa)  à
Call, Video and Sharing is not working.
Uccapi log:-
Client Log
User-Agent: UCCAPI/15.0.4569.1503 OC/15.0.4569.1503 (Microsoft Lync)
ms-client-diagnostics: 23; reason="Call failed to establish due to a media connectivity failure when one endpoint is internal and the other is remote";CalleeMediaDebug="audio:ICEWarn=0x2a0,LocalSite=:10970,LocalMR=:57220,RemoteSite=:33680,PortRange=1025:65000,LocalMRTCPPort=51651,LocalLocation=1,RemoteLocation=2,FederationType=0,NetworkName=airtel,Interfaces=0x18,BaseInterface=0x8,BaseAddress=:5594"
Content-Length: 0
Whether need to open 50000 – 59999 range ports in external firewall?
Can you please help on this problem ?
Regards,
Manikandan

Hi,
Please check if there is any error message on Edge Server Event Viewer.
Please double check if all needed DNS records added in external DNS Server (especial for Edge web service and A/V service).
More details:
https://technet.microsoft.com/en-us/library/gg412787.aspx
Also check the Edge external interface certificate, make sure all SAN including.
Best Regards,
Eason Huang
Eason Huang
TechNet Community Support

Similar Messages

  • Lync user calls a Skype user and call fails

    Dear Expert,
    Please help to confirm the message below about Lync user and Skype, is it correct or not?
    3) Lync user calls a Skype user and call fails
    This is an issue that will be fixed in the next service update. Try calling again.
    http://www.supertintin.com/blog/record-skype-calls/troubleshoot-skype-lync-connectivity
    Thank you

    No, it isn't correct info. Because integration between skype and Lync work successfully in call and IM
    Also you can refer below link
    http://blogs.technet.com/b/lync/archive/2013/05/23/lync-skype-connectivity-available-today.aspx
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • Skype to skype calls failing

    I can not make any skype calls on any type of plataform i use (windows 8, mac and android) in all of them i have uninstalled and reinstalled the latest versions and i still can't make any calls i have checked my internet and audio/video settings and everything seems fine but i keep getting the internal error message on mac and call failed one on windows i need help urgently since is theway i comunicate with my family.
    Attachments:
    Screenshot (1).png ‏41 KB

    On both Mac Yosemite and Android 4.4.4 on my cell, I get either "Call failed" or "Call error." Using Skype 7.7 on a new Mac Mini and 5.3 on the cell. WiFi connection is FIOS. I cannot find any reason for this except application failure. Pretty outrageous in these modern times. It is consuming much time to resolve and, as you know, time is of the essence.

  • Endeca : multi invoice pay throwing correct error for internal user but it is failing to throw the same error for external user

    Hi,
    1) Internal User expected exception:
    Exception: Payments,apply credits,disputes and print are not supported when multiple customer/currency transactions are selected
    2) External User is throwing below error instead of throwing above exception.
    Error
      You are trying to access a page that is no longer active.
      The referring page may have come from a previous session. Please select Home
       to proceed.
    found this MACCHECK from fnd logs of external user payment.
    MACCHECK: . Parameter failing validation is :mode. The parameter mode with value MultiPay could not be recognized as part of Server's response on the previous request.  Incoming URL is : /OA_HTML/OA.jsp?page=/oracle/apps/ar/irec/endeca/webui/EndecaDummyPG . Current URL is : /OA_HTML/OA.jsp?page=/oracle/apps/ar/irec/endeca/webui/OIREndecaCustHomePG&akRegionApplicationId=222&_ti=1125493452&oapc=10&retainAM=Y&addBreadCrumb=N&oas=6-LL4ndIUFLX-2zjQAQD6A.. . Referer URL is : https://<hostname>:4443/endeca/web/ar/customer?doAsUserLanguageId=en_US&languageId=en_US . HTTP Request Method is : POST
    can someone please help.
    Thanks,
    RRS

    Well, I compared my classpath between my windows batch file and the
    makefile (that comes with the samples installation) on Solaris and realized
    that I am using different sets of jars.
    So, I removed the extra jars from the makefile to narrow down the
    problem. If I remove the /opt/SUNWam/lib/servlet.jar from the makefile,
    I can reproduce this problem on the Solaris box as well.
    When I include this servlet.jar on my windows machine the program works!
    Only jars I have in my classpath are amclientsdk.jar and servlet.jar which
    I have copied from my installation (/opt/SUNWam/lib) on the Solaris box.
    Just the same way, by copying the am_services.jar, saaj-api.jar, and jaxm-api.jar,
    from the Solarix box to the windows machine,
    I am also able to pull the assertions from the Access Manager.
    I installed Sun Java Enterprise System 2005Q1 on a Solaris 10 machine.
    During the installation, I configured to install the Access Manager
    in Sun Application Server.
    Why do I need to have different set of jars on the windows machine
    for the Access Manager client SDK ?
    Could you please point me to a download link where I could download
    the correct Windows Access Manager Client SDK for
    Sun Java System Access Manager 6.0 (Sun JES 2005Q1)?
    Thanks.

  • The NLS operation failed because the registry key Control Panel\International\User Profile cannot be opened. Error code is 2. Error message: The system cannot find the file specified.

    H,
    Since upgrading Windows server 2008 R2 to Server 2012 Standard edition, we get this repetitious critical error in the event log:
    Event 1001
    Op Code NLS initialization
    The NLS operation failed because the registry key Control Panel\International\User Profile cannot be opened. Error code is 2. Error message: The system cannot find the file specified.
    We originally found that the regional date settings after changing them in regional settings (DD/MM/YYYY) and they did not inherit properly from the upgrade but they are ok now. 
    I've looked at HKCU\.Default\Control Panel\International and nothing looks obviously wrong. Country codes, time & date formats are correct.
    How do we ascertain the  cause of this error and the specific registry key that might be problematic?

    Hi,
    This could be caused by firewall rules or security softwares.
    http://www.tomshardware.com/forum/242579-44-hkcu-control-panel-international-opened
    And in addition, the fix is worth a try.
    Nothing happens when you double-click "Region" in Control Panel 
    http://support.microsoft.com/kb/2958845
    Please Note: Since the first web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

  • How to authenticate external and internal users on different AD

    What is the recommended way to authenticate external users as well as internal employees in a customer facing application?
    We have external users in an Active Directory in the DMZ and our employees in our internal DMZ.  Unfortunately we don't have an identity management system in place and wondering if there is a way we could authenticate user against two active directories without creating a trust between them.
    We are implementing EP7.0
    Thanks in Advance.

    You can also use user partitioning. A feature of the UME which allows for having different user persistence options for different users. What you could do in this case have the external user stored in the local db or an LDAP for the external users and the internal users stored in an internal LDAP directory. For more details about <a href="http://help.sap.com/saphelp_nw2004s/helpdata/en/e0/b60b404b2b1e07e10000000a1550b0/frameset.htm">user partitioning</a>, please see the docs.
    regards,
    Patrick

  • Message tracking log of internal users who are all sent the mails to external domain

    Hi ,
    How can i get the message tracking log from internal users to external users?
    We need the report of internal users who are all sent the mails to the external domain
    Regards,
    Sankar M
    Sankar M http://messagingdevelopment.blogspot.in/

    Sankar, your outbound send connector has an address space of *. So when you run "Get-SendConnector", you will see something like the following:
    Identity                                AddressSpaces                          
    Enabled
    Unix System Connection                  {SMTP:*.domfreebusy.contractor.hunti... True
    Outgoing SMTP Connector                
    {SMTP:*;10}                             True
    Mailbox Journaling Connector            {SMTP:pdwastap01.huntington.com;1}      True
    The middle one with the {SMTP:*;10} in my case (you may have a different number than 10 in yours) is my outbound connector. So yours will show an address space of {SMTP:*;<some number, 10 is the default>}. HTH ...

  • Redirect external user (internet) & internal user (intranet)

    Hi, we are developing a public portal services in which we have two kind of user: a) public user that access through internet to the portal. b) internal user that access inside a domain to the portal.
    We want to know How we can know which is the external and which is the internal in order to assign a portal desktop.
    I have seen in the forms the following options:
    1.-> IISPROXY
    2.-> SPNEGO
    3.-> APACHE & SAPDISPATCHER
    1.-> It seems that we the last release of the portal is obsolete
    2.-> It seems that SPNEGO is for internal use only (intranet).
    3.-> I have not documentation about.
    I would be very grateful if someone give a solution and documentation or links about it.
    Thanks in advanced.
    Regards.

    Hi Optima,
      You can use a appIntegrator to distinguish intranet/ extranet users..
      Have a look at "HowToUseAppIntegrator_en.pdf" from service market place.
    This weblog should give you some idea about appintegrator: Step-By-Step Guide to implement Application Integrator
    Regards,
    SK.

  • ACS v5.1 - Can internal users be disabled after x failed attempts?

    I have noticed under authentication settings for internal user accounts there is no setting to disable the account after x number of failed attempts (ACS v5.1). This is such a fundamental requirement for user accounts that I am wondering whether I have missed something. (They include this option on Administration accounts)
    Does anyone know if can this be set somewhere else or is Cisco going to implement it in a later version?
    Many Thanks

    Hello jrabinow ,
    Thanks  a lot for the reply .
    We already have our AD setup to lock account of users who failed 3 consecutive windows login attempts .
    However when network administrators fail to login  after 3 consecutive attempts into a network device, they can still login into a network device if they provide their correct AD credentials .
    Is there any specific configuration that needs to be done on the AD to be aware of the failed login attempts on the network devices and count it the same as a failed windows login attempt ?!
    Kind Regards ,
    Moussa

  • External users can communicate web server, Internal users can't communicate

    Hi All,
    This Babu, I have Cisco - 1941 and ASA 5510, ISP was terminated on Router point ot point connectivity(10.10.10.0/30). Router isdie ip is Public ip
    (49.49.49.1/28), firewall inside ip is 49.49.49.2 and i have done nating in firewall with private ip 192.168.1.0/24.
    we have web server, this is also connected in Intranet, this internal ip was 192.168.1.13 nat with publi ip 49.49.49.13.
    In this scenario all external users can communicate with web server ie www.example.com. but internal users can't communicate with www.example.com
    All internal user able to ping the web server with 192.168.1.13 successfully and get the internet also.
    Please help me, what is the problem...

    Hi Jereen,
    my user tried the following :
    - went to http://oraclepartnernetwork.oracle.com/
    - at top of the page, click on the "Register / Sign In" link.
    - entered user name [email protected], and password (he tried also with a reset system generated password)
    - got "Invalid Login" Error
    so it seems the issue is not with beehive online, but with SSO to start with...
    my other sun.com users have the same issue. Could it be a restriction on Sun.com domain ?
    I understand now my issue is not with beehive online, so don't hesitate to redirect me to the appropriate support team if necessary.
    Thanks a lot for all your help
    christian

  • Converting QuickSilver G4 internal HD to External  with multiply users

    Was using a PC MAc G4 QS as a server loaded up the extra slots with internals ran it thru a small ethernet hub Worked pretty well until a couple of days the original HD with operating system is shot. G4 owes me nothing served me well But it would save me alot of production time relinking if I could get the secondary internal into an external multi user set up
    Any recomendations.

    I think you'll need to use the select, drag, drop, verify and delete method of moving files from your internal HD to the external HD.
    If you intend to move your Photo Library to the EHD be sure it's formatted OS X Extended (journaled) with ownership set to be ignored. 

  • Oracle on NT (Logmnr and Internal User fail)

    Hi,
    My Environment is NT. I got two questions First, I have problem to use "Log Viewer"
    DBMS_LOGMNR_D to create the dictionary file.
    In the statement, I should have file name and file directory to generate the dictionary file. The problem is the file directoy format of NT and Unix is different, so I changed the file directory to the right format for NT. However, I tried several kinds of format. None of them works. So, does anyone knows the right format for "logmnrd" for NT?
    Second, my test environment can not be logged in as internal user , system and sys. I am sure the password is correct, but at the time I connectted by them. I got the error message indicating me that "Insufficient Privilege". I don't know why? So the only way for me the shutdown the database is through the NT services.
    Does any one know how to solve this?
    Thanks in advance.
    chechun

    Hi,
    My Environment is NT. I got two questions First, I have problem to use "Log Viewer"
    DBMS_LOGMNR_D to create the dictionary file.
    In the statement, I should have file name and file directory to generate the dictionary file. The problem is the file directoy format of NT and Unix is different, so I changed the file directory to the right format for NT. However, I tried several kinds of format. None of them works. So, does anyone knows the right format for "logmnrd" for NT?
    Second, my test environment can not be logged in as internal user , system and sys. I am sure the password is correct, but at the time I connectted by them. I got the error message indicating me that "Insufficient Privilege". I don't know why? So the only way for me the shutdown the database is through the NT services.
    Does any one know how to solve this?
    Thanks in advance.
    chechun

  • Internal user gets trafic from public AV Edge interface

    please can you help me to understand the following scenario:
    a call between two internal users causes traffic from the public AV interface of the Edge server and the internal clients.
    I know that the Edge server will be used to get the public IP address of the users router (to send data over NAT).
    But is there another scenario where data will be send from the public or to the public AV interface of the Edge server when the user is internal?
    Thanks for your help 

    Hi Augustin Ziegler,
    Do you have users who are using the mobile client?
    Any internally connected 2013 mobile clients will leverage the external UCWA URL which in a properly configured environment should cause the client to resolve and connect to a reverse proxy service.  The actual data path can vary here depending on the
    network configuration.  The connection could be directed out a corporate firewall to the Internet and back in through a different firewall to the reverse proxy server connecting back into the external web service on the Lync Front End server. Or this
    traffic could be purposely directed to the internal interface of a reverse proxy server listening for the same traffic as on the external interface, which would shorten the trip distance but still be routed to the external web services.  Either way the
    registration traffic and all connectivity between the 2013 mobile client and the Lync Front End server is hairpinned in some fashion.
    All connectivity between internal mobile clients and the Edge server will follow the same logic, meaning that these clients will connect to the
    external interface of the Edge Server just as if they were external clients.  It does
    not mean that all media is hairpinned though.  All Lync clients will still attempt direct connections so in the event of internal peer calls or when joining conference calls on the Lync AVMCU media will still be able to be routed directly as long
    as that traffic path is not filtered in a way to prevent this from happening.  In cases where the Edge Server must step-in to assist in relaying the media then the internal mobile clients will be taking the long way around to the external Edge interface.
    Best regards,
    Eric

  • Routing internal users through UAG

    We have published SharePoint on the UAG and want all internal users to access SharePoint through the UAG, as if they were connecting from outside our network. This is working. The problem is that we are trying to publish Office Web Apps
    for SharePoint and it is not working internally or externally. We followed the TechNet article "Publishing Office Web Apps Server Using a Reverse Proxy Server." Is this a supported configuration (to route all internal traffic through UAG
    as if the connection was external to the network)? 

    Thanks for your reply. The underlying setup is the following and this should clarify things a bit:
    UAG is load balancing SharePoint farm.
    Internal DNS is the same as the Public DNS to access SharePoint. (For example sp.domain.com)
    At this point Office Web Apps works normally for both internal and external users.
    Since we want users to experience the same login steps, the following was done:
    A DNS record was created internally, so that sp.domain.com resolves to the public IP of the UAG. This way everyone is going through the UAG for access regardless if they are internal or external users. This is when we started having issues. It seems that
    there is a loop somewhere when office web apps tries to send the document back to SharePoint.

  • BSP - UserId and Password for Internal Users - Anonymous for other users

    Hello,
    We developed an application via BSP's. This application can be accessed by two kind of users.
    1. External Users, with should access the page without using a userId and password.
    2. Internal Users, they will have more authorisation and need to specify their userId and Password.
    How can we accomplish this? I tried internal aliases, but can't get it to work properly.
    In the first service 'zbsp' I didn't specify a userId and password in sicf.
    Then I created an internal alias 'zbsp' referring to this 'zbsp'. In this alias I specified a userId and Password, but the system still asks for a userId and Password. (and after logging in the system gives the following error: The application name in URL .../bc/bsp/sap/zbsp2/uat_report.htm is invalid.)
    What did I do wrong? Or are there other ways to accomplish this?
    Greetings,
    Bart

    Take a look at the following mesaages that discussed the whole SSO and SSO2 ticket logins.
    As for a way to handle the two different login types. Well first and formost - active the SSO Tickets on your system.  Set your BSP up for that.
    Then create a new starting page with an alias to the pöublic section for BSP's in your system. On this page make two links.
    For your external users - one that redirects to your BSP passing the user and password in the url for the "read only external user" - that's the sap-user=name here&sap-password=passwordhere.
    For your internal people give them simply the link to the BSP which when they click it will see no user name and password and redirect them to the BSP login.
    Make sure you setup the BSP login according to SAP note 517860 and follow the instructions from http://help.sap.com/saphelp_nw04/helpdata/en/1d/13c73cee4fb55be10000000a114084/frameset.htm using the supplied SYSTEM_PUBLIC)
    It's a bit basic but it works, we do it
    Oh and setting up the system for the SSO (transaction sso2) is very very simple!!

Maybe you are looking for