Lync 2013 Remote Access on all Lync clients from the internet not login.

Hi All,
I have a Lync 2013 setup with and Edge server as well as TMG Server.
All clients can login on the mobile devices (IPAD, Windows phone etc). However, when i try login on lync client, I get "we're having trouble connecting to the server. If this continues, please contact your support team".
What could be casing this causing this?
KimaniBob

Hi Ben,
Thansk for the reply.
I have created  the DNS records on the external and tested all, all seem fine. My Edge server has 2IPs(Internal and External) a NAT has being to the External interface of the Edge and it has being done well.
I have also ran the ecxhange connectivity, and the output is all green. (Passed)
Just as an add on. The lync client seems to establish a connection because , I prompts me to enter my credentials. If i put in wrong credentials i get an authentication error. However, if I put in the correct credentials, I get server is temporary unavailable.
Althou the the error has changed now'Lync couldn't find the server for domain.com....'
I ran the ocslogging tool and i get the following logs:
TL_INFO(TF_CONNECTION) [0]1274.0B08::12/09/2013-13:29:25.870.00000149 (SIPStack,SIPAdminLog::WriteConnectionEvent:1222.idx(446))[972797567] $$begin_record
Severity: information
Text: TLS negotiation started
Local-IP: 192.168.168.3:5061
Peer-IP: 212.49.88.99:11468
Connection-ID: 0x60400
Transport: TLS
$$end_record
TL_ERROR(TF_CONNECTION) [0]1274.0B08::12/09/2013-13:29:26.058.0000014c (SIPStack,SIPAdminLog::WriteConnectionEvent:1222.idx(452))[972797567] $$begin_record
Severity: error
Text: The connection was closed before TLS negotiation completed. Did the remote peer accept our certificate?
Local-IP: 192.168.168.3:5061
Peer-IP: 212.49.88.99:11468
Connection-ID: 0x60400
Transport: TLS
$$end_record
I also check on the TMG and found it was dropping SIP protocal (port:5061), not sure if this is the cause, and if so how do I sort it.
So far no solution.
KimaniBob

Similar Messages

  • How can I access my home security DVR from the internet?

    My Time Capsule (as a router and not a bridge) blocks me from accessing my home security DVR from the internet.  I can access it from other computers connected to my LAN but not from the internet.  I guess it's a firewall setting issue.  I can't add the home security application to the list of firewall allowed incoming connections since it's a Windows app that I cannot install on my Mac.  On the other hand, the app is installed on my old PC but I can't access the Mac firwall settings from the PC and add the security app (If that's the problem).
    My DVR is connected to a Netgear switch which is connected to the Time Capsule which is connected to a Cisco modem provided by Comcast. I thought one of the modem ports had to be opened by Comcast. That was not the issue.  After spending 2 hours on the phone with Comcast going in circles talking to 10 different overseas agents, they concluded the Netgear switch was blocking me from accessing the DVR.  I think they are wrong and that it's a Mac firewall problem.  HELP!!!  Does anyone know what could be the problem and how to solve it?

    Did you forward the required ports in the TIme Capsule? If not it won't work.. it has nothing to do with firewall unless the DVR is plugged into the Mac. If it is plugged into a switch you need to lock the IP of the DVR and find out what ports are required.. usually just port 80, ie html.. but it could be some others.
    Since Apple do not use upnp to open ports.. the TC will have to manually be provided with the ports.. Apple use PMP-NAT that is not used by the rest of the known world.. Just to ensure you stay in the camp.

  • Access to a site from the Internet not working, but is for other sites on the same SP

    Greetings,
    My environment:
    SP 2013 Enterprise w/ SP1 installed
    2 servers in the farm, 1 for SQL, 1 for SP
    Both servers are VMs running on Hyper-V, SQL is a bit underpowered when it comes to memory, SP is fine
    5 web applications running, including a MySites web app and Central Admin (I've seen where separate web apps isn't the recommended configuration any more, but, this is how it was done when setup)
    All sites run using SSL (443), same NIC, using host headers, pretty standard stuff (I think)
    Claims authentication on all but Central Admin
    Central Admin is firewalled off to all but a select few
    1 to 1 correspondence between web apps and content databases
    Other than MySites, all sites have either 1 or 2 site collections (search is in a separate site collection on 2 of the sites); MySites has many more site collections
    So, site A, site B, site C, and site M are all supposed to be available from the Internet (with SSL and authentication) and also from the internal network. For site A, C, and M, this is true, no problem. Site B however doesn't work when coming in from the
    Internet, just internally. I've received multiple reports of this from some of my users around the country, and I've been able to replicate it on my computers.
    IIS just gives a blank page, no messages, no login. Chrome does present a login box, and will log into the site and work. This is from a laptop that is a part of our domain with cached credentials, but not directly connected to our network or using
    our VPN. A non-domain laptop without cached credentials prompts me to login, as it should, and seems to work. The domain laptop will use the cached credentials to auto-authenticate to A, C, and M, but not B.
    I'm using IE 11. I've tried putting the site into Compatibility mode, no joy. I've added the site to the Trusted Sites list, no joy. I don't have IE 10 available for testing (or 9 or 8 or ... just 11 :-(  ) I've flushed the browser cache, emptied the
    cookies, etc.
    So, 3 of 4 sites work fine on the same machine, same Internet connection, same browser, same SP. I'm thinking it's something with IE, but, what? Seems like IE should be sending the same creds to all the sites, as they're all in the same Internet domain.
    Does IE or Windows cache different creds somewhere? Or is there something in SP? I could see where one person's settings could get hosed somehow, but numerous people around the country with different h/w, different Internet connections, different credentials?
    ARGH! HELP!!! Point me at something to look at, because I'm drawing a blank (and getting permanent dents in my forehead from banging it on my keyboard)...
    Thanks much,
    Steven

    It seems that the difference between the sites that will open and the one that won't is the Default Authentication provider is set to NTLM on those that open, and Negotiate (Kerberos) on the one that won't. The Authentication Provider for the Default zone
    is Claims Based Authentication on all the sites, just site B (which won't open) is set to Negotiate (Kerberos), the others are set to NTLM.
    Short term: can I change the provider to NTLM without destroying the site?
    Long term: point me in the direction for setting up Kerberos correctly on my server/farm, as from what I can tell Kerberos is the recommended path forward. I'll setup a non-production test site and get it figured out.
    Thanks much.
    Steven

  • How can I add a trusted site in Safari to access our secure Sharepoint site from the internet?

    My company has a secure sharepoint site that we access from the internet that requires our Active Directory logon. The Safari on the iPad does not allow you to add the URL as a trusted site and thus it prompts you for your username and password multiple times when navigating to various content.  The solution for full blown browsers is to just add the URL as a trusted site in your browser security settings.  Is there a work around for this or will Apple perhaps add this capability to add trusted sites to the mobile version of Safari?

    Non-Windows browsers do not have a concept of a "trusted" site. In Windows, IE and Chrome do not repeatedly prompt for credentials because they use the user's login credentials on the desktop. Other devices do not have this capability. Instead,
    you need to use something like ADFS to authenticate users.
    Trevor Seward
    Follow or contact me at...
    &nbsp&nbsp
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • Time Capsule:  Need help accessing my video surveillance DVR from the Internet.

    I am using the latest 4th Generation Time Capsule attached to a DSL Modem.  My 4 video Survilance DVR is connected to a switch then to the Time Capsule.  How or what is needed to be able to access the DVR via the internet.  I am able to access the DVR from within the home network only.  Would appreciate some guidance.
    Thanks in advance.

    Is the modem bridged?
    If not and working in router mode then the TC should be bridged.. this will never work if you have double NAT.
    Whichever box is the main router will need to forward the required ports for the camera dvr.. does the software use port 80 ie html?? That means you just forward port 80 to the IP address of the dvr. But find out the port.. the dvr instructions should tell you. Port forwarding on the TC.. ain't hard.. just google for the instructions. If the dsl modem is router, read its manual.
    You will need to lock the ip of the dvr so it doesn't shift. Do that in the router if possible but I am not sure you can on the TC. You will need to do it on the device using a static ip.
    The other thing is public IP .. do you have a static public address.. if not you will need to run dyndns. this is not available in the TC.. as most things are not available. So you will also need to check the dvr remote access instructions as it might have a dyndns client.. or you will have to use dsl modem as router even if you currently bridge it.
    Sorry this is making it complicated.
    Give some feedback and we can go from there.
    What is the main router?
    What modem is it exactly?
    What make and model is the DVR? A URL to the pdf manual will help if it gets complicated.
    What port do you use to access the DVR?
    Is there a dyndns client in the dvr?

  • Remotely accessing my Mom's Desktop via the internet?

    Hello all, If I have put this in the wrong forum please let me know.
    My mother just purchased a new iMac and she is nearly comp illiterate. I live in CA and she in IL. I was wondering is there software I can install on my iMac and hers to be able to work on her iMac remotely?
    please point me in the correct direction. Thanks.

    Hi,
    Have a read of this:
    http://docs.info.apple.com/article.html?path=iChat/4.0/en/11883.html

  • Lync 2013 client is deployed but user accounts are not migrated from OCS to Lync 2013 Server - how to open Lync meetings automatically in the Lync Web Plug-in

    We have in our enterprise the following scenario:
    1 - Lync 2013 client is installed
    2 - User accounts are not migrated to Lync 2013 Server, users are using Office Communicator as their main tool
    3 - Users receive Lync 2013 meeting requests but when try to access them, Lync 2013 client launches and shows error. Users will need to open the browser and paste the URL to the address bar but this still open
    4 - We cannot use the workaround of adding "?SL=1" to the Lync 2013 meeting URL as the user base is large and manual workaround is not accepted
    5 - Question: is there any automated way, via egistry key or GPO setting, so that users temporarily (until their accounts are migrated to Lync 2013 server) can bypass Lync 2013 client completely and automatically open all Lync 2013 meetings
    on the browser, using Lync Web Plug-in?

    Thanks for the response,
    First, I should have mentioned clearly that users have Office Communicator 2007 client and Lync 2013 client installed in their machines. Their accounts are not migrated yet to Lync 2013 server.
    Second, we are using IE9 and IE10. The issue is that users CAN join Lync 2013 meetings with their browsers but have to paste the URL manually to browser and add "?SL=1" otherwise, if they just click at the "Join Online Meeting" or "Join
    Lync Meeting" URL it launches Lync 2013 client which shows error because is not configured yet, as they are using OCS client and migrating slowly to Lync 2013 server.
    Is there a Group Policy setting or a registry key from Microsoft that can be turned on to these users machines and make will all Lync meeting requests to be opened in IE browser instead of Lync 2013 client. We need a way to ignore
    Lync 2013 client until user accounts are migrated to Lync 2013 Server. Manually typing URLs is not an option in a big organization, can't explain thousands of users of different levels what to do.
    We are regretting the decision not to separate Lync 2013 from Office 2013 package we deployed recently. If Lync 2013 is uninstalled then all Lync meeting requests are opened in browser without an issue.

  • Lync 2013. There was a problem connecting with the Exchange. Unable to load the magazine discussions.

    Lync 2013. There was a problem connecting with the Exchange. Unable to load the magazine discussions.
    Installed Lync Server Standart 2013, client PC MS Office 2013.
    As the mail system - Lotus Notes Domino Server and Lotus Notes client, respectively.
    Exchange is not installed at all.
    question:
    1 What is the message: "There was a problem connecting with Exchange. Unable to load the magazine discussions." and how it is fraught?
    2 How can I fix this message? Cleaning the C: \ Users \% UserName% \ AppData \ Local \ Microsoft \ Office \ 15.0 \ Lync \ does not help
    3 What are the disadvantages when using Lync Server Standart 2013 without Exchange? In principle, I put for Lync Exchange?
    4 What are the advantages when using Lync Server Standart 2013 with Exchange?
    5 Is it possible to work simultaneously Lync Server Standart 2013 + Exchange + Lotus Notes
    Thank you.

    1) That sounds like a strange translation.  But basically, it wants to connect to Exchange and it's complaining. 
    2) You can attempt to go to Tools->Options->Personal and set Personal Information Manager to None, and in Lync Management Shell run set-csclientpolicy
    http://technet.microsoft.com/en-us/library/gg398300.aspx with the following options:
    DisableCalendarPresence $True
    DisableEmailComparisonCheck $True
    EnableExchangeContactSync $False
    There may be more, I've never tried to completely disable Exchange features from Lync.
    3) No conferencing plugin for meeting invites, no automatic presence management based upon your calendar, no searching your Outlook contacts for new contacts, no voicemail, no conversation history,no unified contact store, and more:
    http://technet.microsoft.com/en-us/library/jj688098.aspx
    4) This is just #3 in reverse :)
    5) Depends on your goals, but the experience wouldn't be great.  You'd want to keep your contacts and calendar in Exchange and your email in Notes.  It would be confusing to your users. 
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • HT204406 I purchased the additional Icloud storage for my ipod touch.  Since it removes all my music from the touch and stores it in Icloud, I find that when I am not at my wifi location or another one,I can't access my music.Is there a solution for that?

    I purchasedhe additional Icloud storage for my ipod touch.  That removes all my music from the ipod and putsd it in Icloud.  I find that when I am away from my wifi connection, like when walking or working out, I can't access my music. Is there a solution for this?

    Download the music to your ipod when you are in a wi-fi area.
    It will be stored on your ipod.

  • Is it possible to remote-access my MacBook Pro away from home?

    Is it possible to remote-access my MacBook Pro away from home?
    What I currently have:
    Late-2011 MacBook Pro 8,2 (OSX Mavericks 10.9.5)
    2.5ghz Intel i7 quad-core
    16gb RAM, 1024gb SSD raid-0 (internal)
    Connecting to the internet through:
    Apple Time Capsule 2TB (via ethernet)
    +
    Time Warner Cable "Ultimate 100" (top speed)
    I would basically like to be able to have my MacBook Pro on *at home* and connected to the internet via ethernet to the Apple Time Capsule.. and then be able to somehow connect and log in to my MacBook Pro, either through another computer or preferably, my iPhone 5s..
    Mostly just interested in having accessibility to be able to make downloads, such as magnet links, while away from the computer.. and basically be able to come home to mostly finished or complete downloads.. Basically like how you can DVR/TiVo things from your iPhone and have it sync with your DVR/TiVo while away from home..
    Is this possible? Thank you!!

    Yes you can do this.
    I would suggest you start with TeamViewer.com (free for personal use).
    You will need to install TeamViewer on your Mac AND your iPhone.
    The Mac version will need to be configured for unattended remote access.  You should practice before you leave the home.
    There are other iPhone apps that can remotely access a Mac.  A lot depends on whether they can get past the home NAT router.  Be careful of apps that provide VNC access, but do not provide a way to get past the home router.  If you try one of these, make sure you test it away from your home WiFi network.

  • Outlook Web Access is currently unavailable. If the problem continues, contact technical support for your organization and tell them the following: No Client Access servers of the appropriate version can be accessed from the Internet

    Good Morning,
         We are getting this error 
    Outlook Web Access is currently unavailable. If the problem continues, contact technical support for your organization and tell them the following: No Client Access servers
    of the appropriate version can be accessed from the Internet
    We installed a new Exchange 2007 CAS on Windows 2008R2. Got rid of old CAS on Exchange 2007. Now seeing this error. Does anyone have an idea??

    Hi,
    If the issue persists, I recommend you install Exchange 2007 SP3 RU7 and check the result. Also, ensure that Exchange 2010 SP2 RU1 or later version is installed. Old Exchange version may lead to the CAS-to-CAS proxy incompatibility.
    What's more, here are some helpful blogs for your reference.
    Exchange 2010 SP2 RU1 and CAS-to-CAS Proxy Incompatibility
    http://blogs.technet.com/b/exchange/archive/2012/02/17/exchange-2010-sp2-ru1-and-cas-to-cas-proxy-incompatibility.aspx
    OWA Coexistence With Legacy Versions
    http://blogs.technet.com/b/sjimmie/archive/2010/07/09/owa-coexistence-with-legacy-versions.aspx
    Hope this can be helpful to you.
    Best regards,
    Amy Wang
    TechNet Community Support

  • Can i make it so that all my clients have the same wallpaper Leopard Server 10.5.8

    hi i am running leopard server 10.5.8 and i was wonderg if i can make it so that all my clients have the same wallpaper
    that they can not change

    com.apple.desktop
    i think that the name of the file as least

  • RemoteApp's not running when accessed from the internet

    Hi TP,
    Hopefully someone can help me here.
    I've installed RDWeb on the RDG server which live in our DMZ - I can access and log on to RDS from the internet with the RDG FQDN remote.external.com but I can't launch any RemoteApp's. Basically there's no RemoteApp pop up warning with all the connection
    information (Publisher, Type, Path, Name, Remote computer, Gateway server) just the RemoteApp connecting to window with no info. Seems like it can't grab this information. 
    Users can log in to RDS internally with the RDG FQDN remote.external.com and run RemoteApps with no problems.
    Thanks for your help in advanced!

    Hi,
    1. On the client PC, remove the thumbprint value entry for this server under the PublisherBypassList key.  This is located under the following path:
    HKCU\Software\Microsoft\Terminal Server Client\PublisherBypassList
    <SHA thumbprint>     REG_DWORD     0x00000xxx
    Additonally, remove the key for the server under the Servers key:
    HKCU\Software\Microsoft\Terminal Server Client\Servers\<FQDN of server>
    2. What is the precise error message you receive when you attempt to launch a RemoteApp from external?
    3. If you manually configure the Remote Desktop Client with the RD Gateway FQDN via Advanced tab--Connect from anywhere, are you able to connect from the Internet? 
    -TP

  • How do I setup my Time Capsule (3rd Generation) to be accessed from the internet while I'm traveling?

    How do I setup my Time Capsule (3rd Generation) to be accessed from the internet while I'm traveling? It is installed on my home network behind my TWC broadband router.

    Ok.. since the TWC modem is also a router.. all configuration takes place on this box.. NONE whatsoever takes place on the TC.
    There is no airport utility 7.7.3 but there is a firmware of that number for the latest AC model TC..
    Is it tall like this.
    Then it is Gen5.
    otherwise it will have a firmware.. 7.6.4 or earlier and the airport utility must be 6.3 or earlier.
    Open the Airport utility and give us a screenshot of the summary page.
    That will also help us determine that you have the TC, which version and how it is setup.
    You might want to press the edit and also give us the Internet and Network tab as they should be set correctly as well.
    I have created a DDNS through DYN.com although I am not sure how to implement this into the TC.
    You do not do anything in the TC.. set it up in the Ubee router.
    Port forward 548 to the TC in the Ubee router.
    And make sure the TC has a static IP in the Ubee router.
    Overall if you find this too hard I strongly recommend you buy a product designed for remote access .. eg WD MyCloud.. they are cheap and easy peasy to setup for remote access.. by PC or Mac and since it is built outside of Apple you not bound up in Apple limitations built into all their equipment to prevent you using it the way you want.. rather than apple want you too.. eg BTMM and iCloud being the only way apple provide for access to the TC and only when it is the main router of the network.
    You are fighting hard because Apple made this hard.. not easy.

  • Can't access the web-site in my home folder from the internet.  Need help.

    I am trying to publish a website from the Sites folder in my home directory. The website is made and I can access it from from every computer within my ethernet. But despite a couple attempts I made I can not get the website published on the internet.
    I have an Airport Express station. Two Macs and one PC are using the ethernet. As far as I can tell the Airport Express station is directly connected to the internet. I live in a brand new apartment which has Lan outlets in every room next to the electricity outlets. I have a single designated internet IP address.
    To open my computer to the internet I set the "Default Host Option" in the Airport Administrator Utility and selected the default three digits for the "Default Host option" IP address. Then I updated the Airport Express station, manually set the IP address in the Network preferences on my Mac to the "Default Host option" IP address and activated Personal Web Sharing in the Sharing preferences. By doing so I lost my internet connection. It turned out I still had the same IP address that I had before I selected Default Host Option.
    As I understand with the Default Host Option I designate one IP address within the ethernet to receive all traffic from outside. But how do you now tell the Airport Express station which computer on the ethernet will be the host for the incoming traffic carrying the Default Host Option IP address? Apparently just setting the IP address manually in the clients computer Network preferences to the "Default Host Option" IP address doesn't tell the Airport Express station to change the IP address it has assigned to this client to the Default Host Option IP address.
    In another attempt to make my website accessible on the internet I removed the Default Host Option and instead opened Public Port 80 and Private Port 80 for the IP address of the client computer in the Port Mapping tap of the Airport Administrator Utility. But again, no access to my website from the internet.
    To access the website from within the ethernet I use the following web-link, which works fine:
    http://192.xxx.x.x/~user/index.html
    The internet of course doesn't see the 193 IP address. It only sees the Public IP address. Therefore I used the Public address instead of the Private IP address to connect to my website from the internet:
    http://222.xxx.xxx.xxx/~user/index.html
    But as I said, I still can't access the website from the internet.
    I have the feeling that I conceptually don't understand something correctly. I would appreciate if somebody could help me with this problem.

    See this article:
    http://support.apple.com/kb/HT1866
    Sometimes My Music does not show up in special folders in TweakUI.
    If so, see this post:
    http://discussions.apple.com/thread.jspa?messageID=1731188&#1731188##
    If you would rather not mess with the registry you can often work round with a shift key start.
    Hold down the shift key and start iTunes, keep holding down the shift key until you are asked to choose or create a library. If you already have one, navigate to your iTunes folder and choose iTunes Library.itl. Otherwise create a new library in My music.

Maybe you are looking for