Lync 2013 federation and mobile push 504 error

Hello,
In our company we have deployed Lync 2013 Standard with last CU
1. Front End - External web serwis and mobile sing by wildcard certyfikate trusted in Internet, and Internal webserwis sing by our Internal CA not trusted in internet
In Topology is registred: LyncFE.company.local
Default SIP domain is company.com
2. Edge Server  - All in one server sing by our Internal CA not trusted in internet with Subject Alternative Names: sip.company.local, sip.company.com, LyncEDGE.company.com
In Topology is registred: LyncEDGE.company.local
3. Reversed Proxyand NAT and firewall setup our firewall with Port Translating
LyncEDGE.comapny.local have asigned by NAT public IP Adres 10.10.10.10
LyncFE.company.local have asingned by NAT public adres IP 10.10.10.11
Incoming traffic for 10.10.10.10 and 10.10.10.11 Lync ports TCP/UDP from documentation
Outgoing traffic for 10.10.10.10 (LyncEDGE) on TCP 5061 need for federation
4. DNS setup
We have split domain and DNS like this:
Company.local (Internal DNS) and Company.com (External DNS)
DNS Records in our External DNS:
LyncEDGE.company.com record A 10.10.10.10
LyncFE.company.com record A 10.10.10.11
sip.comapny.com TLS --> LyncEDGE.copmany.com
_sipfederationtls._tcp.company.com -> LyncEDGE.copmany.com
_sipinternaltls._tcp.company.com --> -> LyncEDGE.copmany.com
lyncdiscover.company.com --> 10.10.10.10
In this setup works for now: Lync Audio Video, Mobile access. And now we trying setup Federation and Push notyfication and when we testing we get 504 form serwer.
Test-CsFederatedPartner -TargetFqdn lyncedge.company.local (This is the name of our LyncEDGE server in topology)-Domain microsoft.com
Test-CsFederatedPartner : A 504 (Server time-out) response was received from
the network and the operation failed. See the exception details for more
information.
At line:1 char:1
+ Test-CsFederatedPartner -TargetFqdn lyncedge.pep.local -Domain microsoft.com
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : OperationStopped: (:) [Test-CsFederatedPartner],
    FailureResponseException
    + FullyQualifiedErrorId : WorkflowNotCompleted,Microsoft.Rtc.Management.Sy
   ntheticTransactions.TestFederatedPartnerCmdlet
My lyncedge.company.com was add by Microsoft as Federation for Skype
telnet form Front End server to LyncEDGE.company.local on port 5061 works
Firewall show outbond traffic form LyncEDGE.company.com (10.10.10.10) to Microsoft site
But still i cant get working federation and push notyfication for mobile some one can advise where problem can be? I think problem is with our certyficate setup on EDGE server that is sing by our Internal CA not trusted in Internet.

Hi, I exchanged root certyfikates with my partner. And now he can see my status, call Video, send IM to my all account but I can't do nothink I get 504, on my logs I see below:
I tested
telnet sip.partnerdomian.pl 5061 -- OK
telnet sip.partnerdomian.pl 443-- ok
nslookup _sipfederationtls._tcp.partnerdomian.pl --> sip.partnerdomian.pl port 5061
All is ok but still timeout, where look for problem on my site or partner site. He have 3 IP LAN adreses on Edge NAT on one public
TL_INFO(TF_PROTOCOL) [0]0548.1970::12/30/2014-20:51:59.558.0006bc75 (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265))[441892531] $$begin_record
Trace-Correlation-Id: 441892531
Instance-Id: 2B8A
Direction: outgoing;source="internal edge";destination="external edge"
Peer: 195.0.0.1:15224
Message-Type: response
Start-Line: SIP/2.0 504 Server time-out
From: "Michał Machniak"<sip:[email protected]>;tag=2f81462440;epid=2ca2532739
To: <sip:[email protected]>;tag=FA942E991CA5A3E9E440BCB9A3FDDF44
Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
CSeq: 1 SUBSCRIBE
Via: SIP/2.0/TLS 172.19.19.23:59211;received=195.8.106.114;ms-received-port=15224;ms-received-cid=11600
Content-Length: 0
ms-diagnostics: 1034;reason="Previous hop federated peer did not report diagnostic information";Domain="partnerdomain.pl";PeerServer="sip.partnerdomain.pl";source="MyEdge.domain.pl"
ms-edge-proxy-message-trust: ms-source-type=DirectPartner;ms-ep-fqdn=LyncEDGE.domain.local;ms-source-network=federation;ms-source-verified-user=unverified
$$end_record
TL_INFO(TF_DIAG) [0]0548.1970::12/30/2014-20:51:59.558.0006bc14 (SIPStack,SIPAdminLog::WriteDiagnosticEvent:SIPAdminLog.cpp(802))[441892531] $$begin_record
Severity: information
Text: Response successfully routed
SIP-Start-Line: SIP/2.0 504 Server time-out
SIP-Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
SIP-CSeq: 1 SUBSCRIBE
Peer: 195.0.0.1:15224
Data: destination="[email protected]"
$$end_record
TL_INFO(TF_PROTOCOL) [0]0548.1970::12/30/2014-20:51:59.558.0006b949 (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265))[441892531] $$begin_record
Trace-Correlation-Id: 441892531
Instance-Id: 2B8A
Direction: incoming;source="internal edge";destination="external edge"
Peer: LyncFE.domain.local:5061
Message-Type: response
Start-Line: SIP/2.0 504 Server time-out
From: "Michał Machniak"<sip:[email protected]>;tag=2f81462440;epid=2ca2532739
To: <sip:[email protected]>;tag=FA942E991CA5A3E9E440BCB9A3FDDF44
Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
CSeq: 1 SUBSCRIBE
Via: SIP/2.0/TLS 172.19.23.80:49973;branch=z9hG4bKC86F300B.DA568731A4B1BC2F;branched=FALSE;ms-received-port=49973;ms-received-cid=894D00
Via: SIP/2.0/TLS 172.19.19.23:59211;received=195.0.0.1;ms-received-port=15224;ms-received-cid=11600
Content-Length: 0
ms-diagnostics: 1034;reason="Previous hop federated peer did not report diagnostic information";Domain="partnerdomin.pl";PeerServer="sip.partnerdomain.pl";source="MyEdge.domain.pl"
ms-edge-proxy-message-trust: ms-source-type=DirectPartner;ms-ep-fqdn=LyncEDGE.domain.local;ms-source-verified-user=unverified;ms-source-network=federation;ms-local-fcp=yes
$$end_record
TL_INFO(TF_PROTOCOL) [0]0548.1970::12/30/2014-20:51:59.558.0006b769 (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265))[441892531]
$$begin_record
Trace-Correlation-Id: 441892531
Instance-Id: 2B89
Direction: outgoing;source="external edge";destination="internal edge"
Peer: LyncFE.domain.local:65236
Message-Type: response
Start-Line: SIP/2.0 504 Server time-out
From: "Michał Machniak"<sip:[email protected]>;tag=2f81462440;epid=2ca2532739
To: <sip:[email protected]>;tag=FA942E991CA5A3E9E440BCB9A3FDDF44
Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
CSeq: 1 SUBSCRIBE
Via: SIP/2.0/TLS 172.19.23.75:65236;branch=z9hG4bK9FFA2BA6.757019415D97CC30;branched=FALSE;ms-received-port=65236;ms-received-cid=1400
Via: SIP/2.0/TLS 172.19.23.80:49973;branch=z9hG4bKC86F300B.DA568731A4B1BC2F;branched=FALSE;ms-received-port=49973;ms-received-cid=894D00
Via: SIP/2.0/TLS 172.19.19.23:59211;received=195.8.106.114;ms-received-port=15224;ms-received-cid=11600
Content-Length: 0
ms-diagnostics: 1034;reason="Previous hop federated peer did not report diagnostic information";Domain="partnerdomian.pl";PeerServer="sip.partnerdomian.pl";source="MyEdge.domain.pl"
ms-edge-proxy-message-trust: ms-source-type=DirectPartner;ms-ep-fqdn=LyncEDGE.domain.local;ms-source-verified-user=unverified;ms-source-network=federation;ms-local-fcp=yes
$$end_record
TL_INFO(TF_DIAG) [0]0548.1970::12/30/2014-20:51:59.558.0006b704 (SIPStack,SIPAdminLog::WriteDiagnosticEvent:SIPAdminLog.cpp(802))[441892531] $$begin_record
Severity: information
Text: Response successfully routed
SIP-Start-Line: SIP/2.0 504 Server time-out
SIP-Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
SIP-CSeq: 1 SUBSCRIBE
Peer: LyncFE.domain.local:65236
$$end_record
TL_INFO(TF_DIAG) [0]0548.1970::12/30/2014-20:51:59.558.0006b57a (SIPStack,SIPAdminLog::WriteDiagnosticEvent:SIPAdminLog.cpp(802))[441892531] $$begin_record
Severity: information
Text: The message has an Allowed Partner Server domain
SIP-Start-Line: SIP/2.0 504 Server time-out
SIP-Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
SIP-CSeq: 1 SUBSCRIBE
Peer: sip.partnerdomain.pl:5061
Data: domain="partnerdomian.pl"
$$end_record
TL_INFO(TF_PROTOCOL) [0]0548.1970::12/30/2014-20:51:59.558.0006b35e (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(265))[441892531] $$begin_record
Trace-Correlation-Id: 441892531
Instance-Id: 2B89
Direction: incoming;source="external edge";destination="internal edge"
Peer: sip.opteam.pl:5061
Message-Type: response
Start-Line: SIP/2.0 504 Server time-out
From: "Michał Machniak"<sip:[email protected]>;tag=2f81462440;epid=2ca2532739
To: <sip:[email protected]>;tag=FA942E991CA5A3E9E440BCB9A3FDDF44
Call-ID: 3a1f78a7ab334baea7c31819fcbbb197
CSeq: 1 SUBSCRIBE
Via: SIP/2.0/TLS 172.19.20.25:56348;branch=z9hG4bK62EA2C6E.CBA9E35BA4B1BC2F;branched=FALSE;ms-internal-info="bdfQfcjHqEGEYXjrThA5NV7b6oZKoU2jzjNeGxP_cA0_tb46nLxN-KzAAA";received=195.8.106.130;ms-received-port=56348;ms-received-cid=11AC00
Via: SIP/2.0/TLS 172.19.23.75:65236;branch=z9hG4bK9FFA2BA6.757019415D97CC30;branched=FALSE;ms-received-port=65236;ms-received-cid=1400
Via: SIP/2.0/TLS 172.19.23.80:49973;branch=z9hG4bKC86F300B.DA568731A4B1BC2F;branched=FALSE;ms-received-port=49973;ms-received-cid=894D00
Via: SIP/2.0/TLS 172.19.19.23:59211;received=195.8.106.114;ms-received-port=15224;ms-received-cid=11600
Content-Length: 0
$$end_record

Similar Messages

  • Lync 2013 client and mobile

    Dear All Hello,
    i am having one very strange issue, I setup lync 2013 certficate all thing okay. We can login into lync 2013 client to lync 2013 server without any issue using PC but same login if i try to login into mobile having anrorid or windows phone it fais and its
    pop up message we cannot sign you in please check your account info and try again. 
    We just created user using Enterprise voice optin, checked mobility is enabled. External url is configured. 
    Any body can refer if something is missing. I havenot updated any cu for lync 2013. 
    If i run Test-CsUcwaConference or Test-CsMcxP2PIM for mobiliity i get following error. I havneot done any update nor any tool as most of article are refering for lync 2010. 
     No response received for Web-Ticket service.
     Inner Exception:The content type text/html; charset=utf
     the response message does not match the content type of
     binding (text/xml; charset=utf-8). If using a custom en
     be sure that the IsContentTypeSupported method is imple
     properly. The first 1024 bytes of the response were:
     '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//E
     "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
     <html xmlns="http://www.w3.org/1999/xhtml">
     <head>
     <title>IIS 8.5 Detailed Error - 500.0 - Internal Server
     Error</title>
     <style type="text/css">
     <!--
     body{margin:0;font-size:.7em;font-family:Verdana,Arial,
     a,sans-serif;}
     code{margin:0;color:#006600;font-size:1.1em;font-weight
     .config_source code{font-size:.8em;color:#000000;}
     pre{margin:0;font-size:1.4em;word-wrap:break-word;}
     ul,ol{margin:10px 0 10px 5px;}
     ul.first,ol.first{margin-top:5px;}
     fieldset{padding:0 15px 10px 15px;word-break:break-all;
     .summary-container
     fieldset{padding-bottom:5px;margin-top:4px;}
     legend.no-expand-all{padding:2px 15px 4px 10px;margin:0
     -12px;}
     legend{color:#333333;;margin:4px 0 8px -12px;_margin-to
     font-weight:bold;font-size:1em;}
     a:link,a:visited{color:#007EFF;font-weight:bold;}
     a:hover{text-decoration:none;}
     h1{font-size:2.4em;margin:0;color:#FFF;}
     h2{font-size:1.7em;margin:0;'.
     Inner Exception:The remote server returned an error: (5
     Internal Server Error.

    Let ensure the mobile client can connect fine
    http://blogs.technet.com/b/nexthop/archive/2012/02/21/troubleshooting-external-lync-mobility-connectivity-issues-step-by-step.aspx
    Also we can use the Lync connection analyzer tool for Mobile scenario and test
    http://blogs.technet.com/b/nexthop/archive/2013/02/08/the-new-lync-connectivity-analyzer.aspx
    Please remember, if you see a post that helped you please click ;Vote As Helpful" and if it answered your question please click "Mark As Answer" Regards Edwin Anthony Joseph
    Great follow up thanks!.
    Seems i am near to solution. 
    I used web site url https://testconnectivity.microsoft.com it pass all test,
    When i use to test using tool it goes to my local fqdn and says unable to resolve. 
    An error occurred while sending the request.
    The remote name could not be resolved: 'lync1.hosting.mydomain.local'
    When i open this url  lyncdiscover_contoso.com it give both internal and extral url. 
    Which is this {"_links":{"self":{"href":"https://lync1.hosting.mydomain.local/Autodiscover/AutodiscoverService.svc/root?originalDomain=haxxess.com"},"user":{"href":"https://lync01.externaldomain.com/Autodiscover/AutodiscoverService.svc/root/oauth/user?originalDomain=external.com"},"xframe":{"href":"https://lync01.externaldomain.com/Autodiscover/XFrame/XFrame.html"}}}
    I am using lync 2013, with no tmg for publishing, internal web servie name is empty overrite and extranal is lync01.externaldomain.com 
    So as article says if i see internal url If the internal web services URL is identified, the web publishing rule is incorrect and is bridging the connection to port 443
    instead of port 4443 for the Lync external web services.
    Where do i have to change this in topology under web service. can you please guide this last phase. 

  • Confused with Lync 2013 Autodisocver and mobile app

    Hello
    i am confused about some stuff related to lync 2013 client discovery and mobility:
    1) internal client will try to resolve lyncdisocverinternal , then why on the internal CA request i can see lyncdiscover &lync disocoverextrnal?
    2)for auto discover to work from extrnal does it look for the A record "sip.mydomian.com" or its searching for lyncdisocver?
    3) does Mobility (client for ipad or Andriod) try to connect to edge server if if its located on the internal network or it can understand if its on the internal wifi to use internal and its outside the network it will use external?
    please help

    All Mobility Service traffic goes through the reverse proxy, regardless of where the origination point is—internal or external.
    The Lync Server 2013 Autodiscover Service returns all Web Services URLs for the user's home pool, including the Mobility Service (Mcx and UCWA) URLs. However, both the internal Mobility Service URL and the external Mobility Service URL are associated with
    the external Web Services FQDN.
    You can run the command Set-CsMcxConfiguration –ExposedWebURL internal.
    The parameter internal indicates whether the URL used by the Autodiscovery Service is accessible to users both inside and outside the organization firewall (External) or only accessible to users inside the firewall (Internal).
    If you set to internal, you can’t connect externally.
    For details, check
    http://technet.microsoft.com/en-us/library/hh690030.aspx
    Lisa Zheng
    TechNet Community Support

  • How to Generate 250 Users Conference using Lync 2013 Stress and Performance Tool

    How to Generate 250 Users N-way IM Conference using Lync 2013 Stress and Performance Tool.
    Please Let know the configurations to generate the XMLs. We are not able to create more than 70 users N-way IM conference though during configuration, we opted for 300 users conference for Large Conference (in custom setting).
    The tool somehow does not create the number of participants as indicated. Is there any way to troubleshoot why it's not generating the expected load.

    Hi,
    Would you please elaborate more about your Lync environment?
    Please check if you meet the following configuration requirements:
    Set the MaxMeetingSize option to 1000. (The default is 250.)
    Set the AllowLargeMeetings option to True.
    Set the EnableAppDesktopSharing option to None.
    Set the AllowUserToScheduleMeetingsWithAppSharing option to False.
    Set the AllowSharedNotes option to False.
    Set the AllowAnnotations option to False.
    Set the DisablePowerPointAnnotations option to True.
    Set the AllowMultiview option to False.
    Set the EnableMultiviewJoin option to False.
    More details:
    http://technet.microsoft.com/en-us/library/jj205074.aspx
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync 2013 Client and Outlook 2010

    Hi, I installed Lync 2013 (FE and Edge server). I am able to talk but still I need to buy suitable certificate in order to access from outside. Rest of the network is as follow. SBS 2011 with exchange 2010, clients have Office 2010.
    Problems that I noticed are:
    - If in Calelendar there is appointment, Lync client shows still available
    - Lync meeting button doesn't react when pressed.
    Is Lync 2013 client backward compatible with older office/Exchange or not ?
     

    For presence show doesn't integrate with outlook, Verify that the
    Lync Meeting Add-in for Microsoft Office is installed and enabled in Microsoft Outlook.
    For lync 2013 client compatible with office and Exchange, you can refer below link
    http://technet.microsoft.com/en-us/library/gg412817.aspx
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical

  • Lync 2013 federation with Skype error: 'Reference error id 504 (Source ID 239)

    I have setup lync 2013, configured skype federation (http://www.techtroubleshoot.com/federate-lync-server-with-skype/) and also done Lync provisioning. Skype federation worked for a few days (2weeks) and then stopped. Currently I am getting the following
    error 'Reference error id 504 (Source ID 239)'.
    Ports are open on the firewall. I however still get the error.
    KimaniBob

    Verify from following:
    you can telnet to your sip domain on port 5061 and 443 from external and resolve of nslookup to srv record of sipfederation is correct.
    Certificate on Edge Server not expire or damaged.
    This link had similar issue, you can check it.
    http://terenceluk.blogspot.com/2013/04/unable-to-send-instant-messages-or-view.html
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"

  • Lync 2013 Std and Ent Edition Edge co-existence

    Hi all,
    I'm seeing an odd issue with our current migration. We have the following:
    Site1: Lync 2013 Standard with Edge server.
    Site 2: Lync 2013 EE with 3 FEs, mirrored DBs and no Edge server deployed
    All users live on Site1 and all is ok. Site 1 contains the CMS & PChat DB's
    I'm re-using the current Edge server in Site1 as I need to retain the same URLs at the moment - the long term plan will be to build up a new Edge pool in Site2 once Site1 has been decommed.
    I'm planning to move a bunch of pilot users onto Site 2 in the next week, but I see the following issues when I move a couple of test accounts into the pool:
    Can't start a "meet now" conference
    Can't expand Disti Lists
    Can't search for contacts - addressbook never seems to download
    Can't see federated contacts
    P2P IM & AV works fine.
    Client logging from a user in the new EE pool shows the following errors when try to communicate with a federated partner:
    ms-diagnostics: 1038;reason="Failed to connect to a peer server";fqdn="standardserver.corp.domain.local:5062";ip-address="172.20.130.32";peer-type="InternalServer";winsock-code="10061";winsock-info="The
    peer actively refused the connection attempt";source="FEPool.corp.domain.local"
    My initial thoughts that its something to do with firewalling but I can ping & telnet from the old Front End and Edge over to the new FE pool (which are geographically separated and on different subnets) so I would have thought media should be able to
    flow between the 2 sites without a problem. The FE pool has a HLB sitting in front of it.
    I can also see our Exchange server ok from the new FE pool too.
    Looking for any suggestions on what else I can look at.

    Hi,
    From your description, did you mean you don’t move anything from Standard pool to Enterprise pool (just move test users to Enterprise pool to test the function)?
    Did you test internal or external of your corporation?
    Please create a new Lync account on Lync 2013 Enterprise pool to check if the issue also happen.
    Please check if CMS replication has update to the latest status with the help of following cmdlet:
    Get-CsManagementStoreReplicationStatus.
    If the status not to the latest status, you can invoke by the following cmdlet:
    Invoke-CsManagementStoreReplication
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support
    Hi Eason,
    I have 2 laptops I'm testing with 2 different accounts that were initally provisioned on the new pool, one is connected to our corp LAN, the other is on our guest wifi to simulate an external connection.
    CMS replication looks ok (servernames changed for obvious reasons!):
    UpToDate           : True
    ReplicaFqdn        : StdFrontEnd.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:49
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556
    UpToDate           : True
    ReplicaFqdn        : StdEdge.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:48
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556
    UpToDate           : True
    ReplicaFqdn        : StdTrustedAppServer.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:48
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.0
    UpToDate           : True
    ReplicaFqdn        : EntFE1.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:51
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556
    UpToDate           : True
    ReplicaFqdn        : EntFE2.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:51
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556
    UpToDate           : True
    ReplicaFqdn        : EntFE3.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:51
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556
    UpToDate           : True
    ReplicaFqdn        : EntPChat1.corp.domain.local
    LastStatusReport   : 20/08/2014 08:16:51
    LastUpdateCreation : 20/08/2014 08:16:46
    ProductVersion     : 5.0.8308.556

  • Lync 2013 federation failing for a specific domain

    Hello,
    We have recently migrated to Lync 2013 and noticed that one of the domains we federate with is unable to federate with us.
    we are getting the following error:
    Log Name:      Lync Server Source:        LS Protocol Stack  Event ID:      14428 Task Category: (1001)
    Level:         Error Keywords:      Classic User:          N/A Computer:      server.fqdn.com Description: TLS outgoing connection
    failures.
    Over the past 28 minutes, Lync Server has experienced TLS outgoing connection failures 4 time(s). The error code of the last failure is 0x80090325(SEC_E_UNTRUSTED_ROOT) while trying
    to connect to the server "sip.example.com" at address [10.10.10.10:5061], and the display name in the peer certificate is "Unavailable". Cause: Most often a problem with the peer certificate or perhaps the host name (DNS) record used to
    reach the peer server. Target principal name is incorrect means that the peer certificate does not contain the name that the local server used to connect. Certificate root not trusted error means that the peer certificate was issued by a remote CA that is
    not trusted by the local machine. Resolution: Check that the address and port matches the FQDN used to connect, and that the peer certificate contains this FQDN somewhere in its subject or SAN fields. If the FQDN refers to a DNS load balanced pool then check
    that all addresses returned by DNS refer to a server in the same pool. For untrusted root errors, ensure that the remote CA certificate chain is installed locally. If you have already installed the remote CA certificate chain, then try rebooting the local
    machine.
    Thanks

    Thanks Michael.
    That worked for one of two issues I'm seeing, I did use the same steps for the second issue but it didn't seem to work, I have imported the CA of the domain we would like to federate with to the trusted root certification authorities and the intermediate
    certification authorities per the certificate issuer's website guidelines. I did learn that the federated partner is also using OCS 2007 R2, not sure if this may have to do with this.
    Over the past 30 minutes, Lync Server has experienced TLS outgoing connection failures 1 time(s). The error code of the last failure is 0x80072746 while trying to connect to
    the server "ocs.example.com" at address [10.10.10.10:5061], and the display name in the peer certificate is "ocs.example.com". Cause: Most often a problem with the peer certificate or perhaps the host name (DNS) record used to reach the peer server. Target
    principal name is incorrect means that the peer certificate does not contain the name that the local server used to connect. Certificate root not trusted error means that the peer certificate was issued by a remote CA that is not trusted by the local machine.
    Resolution: Check that the address and port matches the FQDN used to connect, and that the peer certificate contains this FQDN somewhere in its subject or SAN fields. If the FQDN refers to a DNS load balanced pool then check that all addresses returned by
    DNS refer to a server in the same pool. For untrusted root errors, ensure that the remote CA certificate chain is installed locally. If you have already installed the remote CA certificate chain, then try rebooting the local machine.

  • MS Lync 2013 federation with Cisco CUP 8.6

    Hi all,
    I am currently trying to federate CUPS 8.6 with MS Lync 2013.
    After a lot of certificate issues we finally got a one-way IM from CUPS to Lync. I can't get Presence in either direction or send an IM from Lync to CUPS user.
    I have followed the Cisco guide for inter-domain federation within an enterprise. so no edge server or Cisco ASA involved.
    The error message I am seeing on the Lync side is:
    ms-diagnostics:
    1010;reason="Certificate trust with another server could not be established";ErrorType="Refer to HRESULT code for specific security status";tls-target="CUP-A.cupdomain.co.uk";HRESULT="0x80090326(SEC_E_ILLEGAL_MESSAGE)";source="LCT-LYNCFE01.lyncdomain.net"
    On the CUP side I can see the TLS session being dropped with this error message:
    17:22:58.945 |[Wed Apr 23 17:22:58 2014] PID(24295) sip_tls_verify_callback: TLS protocol error(ssl reason code=(null) [0]),lib=(null) [0],fun=(null) [0], errno=0
    17:22:58.945 |[Wed Apr 23 17:22:58 2014] PID(24295) sip_tcp.c(2409) SSL server accept returned SSL_ERROR_SSL
    17:22:58.945 |[Wed Apr 23 17:22:58 2014] PID(24295) sip_tls_accept: TLS protocol error(ssl reason code=no certificate returned [178]),lib=SSL routines [20],fun=SSL3_GET_CLIENT_CERTIFICATE [137], errno=0
    17:22:58.945 |Wed Apr 23 17:22:58 2014] PID(24295) sip_tcp.c(1056) sip_tcp : Hard close/destroy of tcp connid 93 sock_fd 37 flags 0
    On the cisco side I have only set a TLS Peer as the LYNCPOOL server. do I need to set up a TLS Peer for all of the Lync Servers?
    The lyncpool server has client and server enhanced key usage - do I need to reissue the certs with this for ALL servers in the lync cluster?
    It seems like TLS will neogotiate successfully using the LYNCPOOL server but not with any of the other servers. Must be missing something simple.
    Many thanks for advice.
    Regards
    Lee.

    Hi,
    Please double check the listen port of Lync Server.
    In the Lync Server Management Shell enter the following command to verify the current system configuration: Get-CSRegistrarConfiguration
    More ports requirement for Lync server you can refer to the link below:
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cups/8_6/english/integration_notes/IntegrationNote_CUP86_MicrosoftLyncServer2010_RCC.html
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • EWS not deployed anymore to Lync 2013 Desktop Clients, Mobile Clients still working fine

    Hello dear community,
    the subject of EWS in conjunction with Lync 2013 has been discussed a lot here .
    However, I could not find here any solution for my problem and I'm (almost) at my end.
    Following scenario - 1 x Lync 2013 BE server, 1 x Lync 2013 Edge server, 1 x reverse proxy (IIS ARR). This Lync 2013 deployment
    was installed about two months ago and integrated into existing IT landscape. Everything worked wonderfully - desktop and mobile clients were able to connect from inside and outside our organization, EMS was deployed to both desktop and mobile clients.
    After that there are no any configuration changes made on Lync server, and yesterday, shortly before an important presentation
    I've found, that EWS is not deployed anymore on all desktop clients. Mobile clients, however, continue to function smoothly.
    I have tried the following: restart Lync and reverse proxy servers - without success, Lync Connectivity Analyzer shows all
    green (internal and external), all relevant tests with Microsoft Remote Connectivity Analyzer were passed, also analysis using Wireshark brought nothing.
    I must to say that a week ago I installed SP3 for Exchange 2010 - can it may be because? Also appears more
    times a day the following error message in Event Viewer on the back-end server (language of operation system is German):
    Protokollname: Lync Server
    Quelle:        LS Storage Service
    Datum:         05.12.2013 19:23:14
    Ereignis-ID:   32054
    Aufgabenkategorie:(4006)
    Ebene:         Fehler
    Schlüsselwörter:Klassisch
    Benutzer:      Nicht zutreffend
    Computer:      SERVER-11.Speedpoint.local
    Beschreibung:
    EWS-AutoErmittlungsfehler im Speicherdienst.
    ExchangeAutodiscoverException: code=ErrorEwsAutodiscover, reason=GetUserSettings
    failed, smtpAddress = xxx, Autodiscover Uri=https://autodiscover.xxx.de/autodiscover/autodiscover.svc, Autodiscover WebProxy=<NULL> ---> Microsoft.Exchange.WebServices.Data.ServiceRequestException: The request failed.
    Das Stammelement ist nicht vorhanden. ---> System.Xml.XmlException: Das Stammelement ist nicht vorhanden.
       bei System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res)
       bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
       bei System.Xml.XmlCharCheckingReader.Read()
       bei Microsoft.Exchange.WebServices.Data.EwsXmlReader.Read()
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverRequest.InternalExecute()
       --- Ende der internen Ausnahmestapelüberwachung ---
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverRequest.InternalExecute()
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.InternalGetUserSettings(List`1 smtpAddresses, List`1 settings, Nullable`1 requestedVersion, Uri& autodiscoverUrl)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetSettings[TGetSettingsResponseCollection,TSettingName](List`1 identities, List`1 settings, Nullable`1 requestedVersion, GetSettingsMethod`2 getSettingsMethod, Func`1 getDomainMethod)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetUserSettings(List`1 smtpAddresses, List`1 settings)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.InternalGetSoapUserSettings(String smtpAddress, List`1 requestedSettings)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetUserSettings(String userSmtpAddress, UserSettingName[] userSettingNames)
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.SendGetUserSettingsRequest(StoreContext ctx, String smtpAddress)
       --- End of inner exception stack trace ---
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.SendGetUserSettingsRequest(StoreContext ctx, String smtpAddress)
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.GetUserEwsSettings(StoreContext ctx, String smtpAddress, CacheMode cacheMode)
    Ursache: Der AutoErmittlungs-URI war nicht richtig konfiguriert oder nicht erreichbar. Eventuell besteht ein Problem mit dem Proxy, oder andere Fehler liegen
    vor.
    Lösung:
    Überprüfen Sie die Ereignisdetails. Überprüfen Sie, ob der URI des AutoErmittlungsdiensts ordnungsgemäß konfiguriert und erreichbar ist. Prüfen Sie, ob die Proxyeinstellungen ordnungsgemäß konfiguriert sind und der Proxy erreichbar ist. Prüfen Sie die Konfiguration
    der AutoErmittlung zwischen Lync und Exchange Autodiscovery anhand des Handbuchs zur Problembehandlung. Wenn das Problem weiterhin besteht, wenden Sie sich mit den Ereignisdetails an das Supportteam Ihrer Organisation.
    Ereignis-XML:
    < Event xmlns="">
      <System>
        <Provider Name="LS Storage Service" />
        <EventID Qualifiers="53158">32054</EventID>
        <Level>2</Level>
        <Task>4006</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-12-05T18:23:14.000000000Z" />
        <EventRecordID>19949</EventRecordID>
        <Channel>Lync Server</Channel>
        <Computer>SERVER-11.Speedpoint.local</Computer>
        <Security />
      </System>
      <EventData>
        <Data>ExchangeAutodiscoverException: code=ErrorEwsAutodiscover, reason=GetUserSettings failed, smtpAddress=xxx, Autodiscover Uri=https://autodiscover.xxx.de/autodiscover/autodiscover.svc, Autodiscover WebProxy=&lt;NULL&gt; ---&gt;
    Microsoft.Exchange.WebServices.Data.ServiceRequestException: The request failed.
    Das Stammelement ist nicht vorhanden. ---&gt; System.Xml.XmlException: Das Stammelement ist nicht vorhanden.
       bei System.Xml.XmlTextReaderImpl.ThrowWithoutLineInfo(String res)
       bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
       bei System.Xml.XmlCharCheckingReader.Read()
       bei Microsoft.Exchange.WebServices.Data.EwsXmlReader.Read()
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverRequest.InternalExecute()
       --- Ende der internen Ausnahmestapelüberwachung ---
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverRequest.InternalExecute()
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.InternalGetUserSettings(List`1 smtpAddresses, List`1 settings, Nullable`1 requestedVersion, Uri&amp; autodiscoverUrl)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetSettings[TGetSettingsResponseCollection,TSettingName](List`1 identities, List`1 settings, Nullable`1 requestedVersion, GetSettingsMethod`2 getSettingsMethod, Func`1 getDomainMethod)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetUserSettings(List`1 smtpAddresses, List`1 settings)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.InternalGetSoapUserSettings(String smtpAddress, List`1 requestedSettings)
       bei Microsoft.Exchange.WebServices.Autodiscover.AutodiscoverService.GetUserSettings(String userSmtpAddress, UserSettingName[] userSettingNames)
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.SendGetUserSettingsRequest(StoreContext ctx, String smtpAddress)
       --- End of inner exception stack trace ---
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.SendGetUserSettingsRequest(StoreContext ctx, String smtpAddress)
       bei Microsoft.Rtc.Internal.Storage.Exchange.ExchangeContext.GetUserEwsSettings(StoreContext ctx, String smtpAddress, CacheMode cacheMode)
    < /Data>
      </EventData>
    < /Event>
    However Event ID
    32054
    was actually
    always there
    – even
    when everything
    worked fine -
    but with
    some another content.
    That's why I
    don't know
    if I
    should take it seriously.
    Thanks a lot in advance for your help!

    Hi MiF,
    The issue may cause by the Network Service account that the Lync Storage Service uses does not have access to the private key in used by the oAuth certificate. Please do with the following steps:
    Open MMC and add the “Certificates” Snap-in (Local Computer)
    Open Personal | Certificates and find the the Certificate being used for OAuth (use the Lync “Get-CsCertificate -Type OAuthTokenIssuer” cmdlet to find the serial number of the OAuth certificate).
    Right-click | “All Tasks” | “Manage Private Keys”
    Add Permissions for “Network Service” account (the defaults Full control and Read).
    Please also check registry key on client computer.
    If the HKCU\Software\Microsoft\ Office\15.0\Lync \[User SMTP Address]\Autodiscovery registry key does not exist on the user’s workstation, then it likely means that one of the following failures
    have occurred:
    Lync was unable to locate a valid DNS A record or SRV record for the Autodiscover site
    Certificate assigned to Autodiscover site is not trusted by the Lync workstation
    More details:
    http://www.microsoft.com/en-in/download/confirmation.aspx?id=15668
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync 2013 Mirror Database fails to install - Error: DsRoleGetPrimaryDomainInformation failed with error "6BA".

    Database primary installs just fine for Lync 2013 - however fails instantly when trying to install mirror DB to mirror SQL Server.  The account has dull domain admin, Enterprise admins, and schema admins.  Full access to the share as well.  I
    get the following error:
     InstallMirrorDatabaseCmdlet.StartMirroring
    4/7/2014 10:38:56 AM
    Failed
         └ 
    Error: DsRoleGetPrimaryDomainInformation failed with error "6BA".
    ▼ Details
    └ Type: CannotGetDomainInfoException
    └ ► Stack Trace
        └  
    at Microsoft.Rtc.Management.ADConnect.NativeHelpers.NativeHelper.GetPrimaryDomainInformation(String server)
    at Microsoft.Rtc.Management.Deployment.MirrorUtils.GetSqlServerAccount(String server, String instanceName)
    at Microsoft.Rtc.Management.Deployment.TopologyParser.PopulateDatabasesForSqlInstance(ISqlInstance sqlInstance)
    at Microsoft.Rtc.Management.Deployment.TopologyParser.FindDatabasesForMachine(IMachine machine)
    at Microsoft.Rtc.Management.Deployment.TopologyParser.FindDatabasesForFqdn()
    at Microsoft.Rtc.Management.Deployment.TopologyParser.GetDbListToMirror()
    at Microsoft.Rtc.Management.Deployment.TopologyParser.get_DbInfoList()
    at Microsoft.Rtc.Management.Deployment.InstallMirrorDatabaseCmdlet.StartMirroring()
    at Microsoft.Rtc.Management.Internal.Utilities.LogWriter.InvokeAndLog(Action action)
    4/7/2014 10:38:58 AM
    Error
     └ 
    Error: An error occurred: "Microsoft.Rtc.Management.ADConnect.CannotGetDomainInfoException" "DsRoleGetPrimaryDomainInformation failed with error "6BA"."

    The issue could be a typo in the SQL server name or that the SQL server isn't allowing remote connections. If you run the Install-csmirrordatabase command from powershell you should see more details about the error.
    Take a look at Doug Deitterick's blog: http://blogs.technet.com/b/dodeitte/archive/2013/03/05/issue-configuring-sql-mirroring-for-lync-server-2013-when-sql-witness-is-defined-but-not-available.aspx
    Please mark posts as answers/helpful if it answers your question.
    Blog
    Lync Validator - Used to assist in the validation and documentation of Lync Server 2013.

  • Lync 2013 HA and Features

    Hi,
    Im currently working with my client to upgrade their 2010 Lync environment to Lync 2013 with Enterprise voice.
    The existing environment is very basic with a 2010 FE pool with only one server (no idea why they didn't just go for Standard ?!), in addition to this there is a single edge server providing external access and federation services.
    So I have my design document pretty much their with regards to 2013 and introducing enterprise voice. Its designed for 1000 users and HA is a requirement. They only have one datacentre so DR is not an option.
    My solution consists of a single FE pool with 3 enterprise edition servers, 2 Mediation servers, 2 Edge servers and a SBC to connect to the contact centre which is staying on the old phone system for now. VOIP will be provided by an external SIP provider.
    We will be taking advantage of DNS load balancing for FE and Edge access and using a reverse proxy solution to load balance HTTP/HTTPS traffic. The customers DB team wish to deploy a 2 node SQL 2012 Cluster as opposed to mirroring so I am taking their lead
    on that.
    Ive recently been reading about pairing Lync 2013 Standard edition. Would that provide the same (or similar) resiliency to the solution I have proposed? Also for the amount of users I am talking here, do I even need to separate the mediation server role
    from the front end?
    One final question, can the backend SQL DB, monitoring and archiving DB be located on the same SQL server?
    Thanks in advance!

    Hi, agree with Cro's statement regarding the consideration for collocating the mediation server role (particularly if you have an SBC with media bypass enabled for your environment).
    Regarding the pool pairing HA vs DR scenario, I always quote myself answering that;
    http://www.gecko-studio.co.uk/dont-play-with-fire-play-with-pool-pairing-configuring-testing/
    "Pool Pairing is a disaster recovery (DR) mechanism that was introduced with Lync Server 2013. With two pools in a paired relationship, we are afforded resilience in the form of automated voice failover, and manual failover of CMS and User
    Data between those two pools in the event of a pool failure. Each pool will also act as a backup registrar for the other. But lets iron something out before we go any further – Pool Pairing is not a High Availability (HA) solution, despite how
    often you might read this in one format or another. By definition alone, the services that a highly available platform provide should remain completely unaffected in the event of any given component in that environment failing. End users are blissfully
    unaware of any problem, and are able to perform every single action as they normally would without the need for manual administrator intervention. As we’ll discuss, Pool Pairing does require manual intervention in the event of a disaster or Front
    End Pool failure, and the end users will definitely notice the outage. As such Pool Pairing falls short of the aforementioned definition, and should be classed as a DR measure rather than an HA one."
    Kind regards
    Ben
    Note: If you find a post informative, please mark it so using the arrow to the left. If it answers a question you've asked, please mark the thread as answered to aid others when they're looking for solutions to similar problems or queries.
    Lync | Skype | Blog: Gecko-Studio

  • Lync 2013 Attendant Response Group - Long Delay - Error ID 45019 LS Inbound Routing

    Hello,
    We have a customer who's using Lync Server 2013 with Response Groups and the SamRoxx Attendant Client. They are getting an error whereby calls made directly to users come through instantly, however attendants who take a call via the Response Group
    get a 10 second delay. We are seeing 
    Error ID 45019 LS Inbound Routing
    User ***@***.com provided a routing document with errors.
    Default call handling was applied instead. Merge conflict. Wait total present in both preambles.
    Problems with this user's routing documents will not be reported again for another hour.
    Cause: A new or experimental user agent my have published a routing document with errors.
    Resolution:
    Replace the user agent that published the defective configuration.
    Has anyone seen this before??
    Thanks
    Lync Tips Blog - [email protected] - If this post has been useful please click the green arrow to the left or click 'Propose as answer'

    Hi tomcotton,
    You can try steps below to troubleshoot the problem.
    1. Remove the affected Lync user from the Response Group and test whether the error persists.
    2. I’m not aware of
     the SamRoxx Attendant Client, can you use Lync 2013 client to test and check ?
    Best regards,
    Eric
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Lync 2013 Federation

    Hi,
    We are planning to Deploy Lync Server 2013 Federation with client domain.
    We have a separate domain at client location onsite (They have their own Lync environment) and Separate domain in Our offshore ODC. The Point-to-Point (Dedicated link ) enabled. So there is no DMZ. We are planning to enable lync federation with client domain.
    Can We place Edge Server in the same network where Front end Server installed? How do we go about this requirement? Please suggest.

    For configure Lync Edge, you need to have two network adapters for each Edge Server, one for the internal-facing interface and one for the external-facing interface.
    Yes, you can put internal NIC with Lync Front End
    For more details about Network interface of Lync Edge, you can check below link
    http://technet.microsoft.com/en-us/library/gg412847.aspx
    For Deploy and Configure Lync Edge
    http://technet.microsoft.com/en-us/library/gg398147.aspx
    Configuring SIP federation, XMPP federation and public instant messaging in Lync Server 2013
    http://technet.microsoft.com/en-us/library/jj205134.aspx
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • Lync 2013 Edge and routing algorithm

    Hi
    I have problem with Lync 2013 Edge server. I'm tring resolve problem but for now I 'm totally lost.
    Short description for a problem:
    What works:
    IM and presence communication to Internet and federation
    A/V conferences with remote users and federated organizations.
    File transfer to remote users and federated org.
    What doesn't work:
    Audio and video P2P connections to remote user and federated org. SIP signalization works, but media connection doesn't.
    Tracing at wireshark shows that Edge server trying establish stun connection to INTERNAL clients on EXTERNAL interface.
    Persistent route for internal subnets are added to routing table on server.
    All ports are opened on firewall between DMZ and LAN.
    I can ping and connect via RDP to stations on internal network.
    Why  A/V Edge service trying establish connection on external interface ?
    What is algorithm/mechanism for network interface selection
    Regards
    Mawik

    Hi,
    Please check if all server settings were correct (check if Global Settings had the A/V Edge server defined and assigned as the A/V Authentication Service in the pool properties).
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

Maybe you are looking for

  • How to create  some columns dynamically in the report designer depending upon the input selection

    Post Author: ekta CA Forum: Crystal Reports how  to create  some columns dynamically in the report designer depending upon the input selection  how  export  this dynamic  report in (pdf , xls,doc and rtf format) report format is as below: Element Cod

  • Automatic payment program for customer

    Hello! I have the next issue: I want to pay physically (give money from bank) to somebody (a commission). In the system, this person is defined as customer. Can I use the automatic payment program for a customer(as it is in SAP system) and send the p

  • Very Urgent : Dumps Generated in Production System, reason unknown

    We are getting ABAP Dumps every second for some reason on the production system. The error analysis message is as follows : Error analysis The data type "MCVBAPB" was reloaded from the database while the program was running. However, the system found

  • Imported Events, All One Hour Off :-(

    Just exported over 1000 events from our athletic games from Excel to Palm, so that I could save as vcal files. All the times were correct in Excel and Palm, but after importing to iCal ALL the imported events (1000+) were now one hour earlier. My iCa

  • Keynote does not see my imovie events

    I am trying to create a keynote presentation.  When I click the icon to import media it allows me to do it for photos easily.  When I click on movies it says that I have no movies.  I have gone back to imovie a dozen times and shared my clip in every