Lync Client uses wrong RTP Ports for calls from/to RGS with Agent Anonymity

We have QoS implemented and client ports for audio, video und application defined by Set-CsConferencingConfiguration. We also use firewalls in our LAN between the different VLANs for Clients, Servers and Gateways/SBC. Only RTP from the client with the defined
ports are allowed by the firewall. Media ByPass is enabled.
In all normal cases, the right ports will be used and marked by GPO with the right DSCP value. But if an agent get a call from a RGS which has agent anonymity enabled, the client uses a port in the range 1024-65535 for audio. Also if you make a call on behalf
of the RGS, the client use a random port between 1024-65535. As soon, as the source of the call is in another VLAN (e.g. a call from PSTN which comes in over a SBC in e separate VLAN), the firewall between the two VLANs block the RTP traffic.
We see the deny on the firewall log and in the SBC log we see, the reinvite for the media by pass with the IP of the agent and a not valid port. We also see, that no RTP from the client/agent will arrive the SBC and no RTP from the SBC will arrive the client/agent.
So the call will be disconnected, as soon as an agent wants accept the call.
Is there an additional setting to make sure, the Lync client always use the valid RTP port range?
This behavior exist in Lync 2010 and Lync 2013 clients.

Hi Holger,
Thanks for reply!
Sure! I set all AudioPorts on all Services, but the problem are not the ports used by the server, the problem are the ports used by the client. We set the client ports to 49152 with a count of 40. The client (2013 and also 2010) use these ports correctly in all
cases exept for call from/on behalf of an RGS with Agent Anonymity.
If we disable the RGS agent anonymity, restart the client of the agent, then the client uses also the correct source ports for RTP.
I've checked this behaviour now on 3 customer installations, our own productive installation and in our lab.
Because until now only one of our customers have firewalls between the internal VLANs, only this single customer have the issues...
Regards,
Stephan

Similar Messages

  • Can lync client use internet proxy settings to proxy edge servers, if direct access is not reachable?

    Hi everybody I am trying to Login with my lync Client out of my organization. So I am using lync as a remote user. I am in another organization, and I am using their coporate lan wired and wireless, but I cannot Login to lync in my organization.
    I see that I cannot Access my edge Server on port 443 to authenticate directly, I know that Client in this organization use Internet Proxy to browse the Internet. they have a .pac in their ie Settings.
    my question is; can lync Client use Internet Proxy Settings to reach the Destination? I mean the Access edge on port 443?
    or it can use only Client direct Access to reach the edge Servers?
    I Think that the answer is that I use tcp protocol and not http, and maybe that is the reason why I cannot use the Internet Explorer Proxy Settings to reach the Access edge Servers, different maybe is the case I Need to reach the reverse Proxy for live Meetings.
    Hope my question is clear.
    Thanks

    Proxy settings are used to tell Internet Explorer the network address of an intermediary server (known as a proxy server) that is used between the browser and the Internet on some networks.
    Lync client doesn’t use Internet Proxy Setting. You need to access the Edge service directly.
    Lisa Zheng
    TechNet Community Support

  • How to use a fixed port for remote assistance in windows 8.1 behind a nat router freebox?

    Hello,
    Before to use remote assistance in windows 8.1, i need to configure my nat router freebox.
    But remote assistance ( msra.exe ) use a dynamique port and never the same.
    How to use a fixed port for remote assistance ini windows 8.1 ?
    And why i can't use easy connect ?
    i read that the router must implement the PNRP protocol. I think it's a propriatary microsoft's protocol unknow on my router.
    Thanks

    Hello,
    Very good. It's a big range ( 255 mini from 49152 )  for a single port but if it's the only one possibility...
    You are very helpfull ( i don't know if it's a good english but you make me very happy )
    Merci beaucoup

  • When i am using my iphone 4 for calls the screen doesnt go blank so i keep cutting my calls off how can i resolve this ?

    when i am using my iphone 4 for calls the screen doesnt go blank so i keep cutting my calls off how can i resolve this ?

    Try removing your case... it might be interferring with the proximity sensor.

  • Did you know that verizon charges ¢50 for calls from the US to Canada?  Just dialing an area code like 604 (Vancouver, CA), will create charges at a rate of ¢50/minute.  Amazing that they can charge this much for a call to Canada.  I know they have it som

    Did you know that verizon charges ¢50 for calls from the US to Canada?  Just dialing an area code like 604 (Vancouver, CA), will create charges at a rate of ¢50/minute.  Amazing that they can charge this much for a call to Canada.  I know they have it somewhere in their contract/website.

    Did you know that verizon charges ¢50 for calls from the US to Canada?  Just dialing an area code like 604 (Vancouver, CA), will create charges at a rate of ¢50/minute.  Amazing that they can charge this much for a call to Canada.  I know they have it somewhere in their contract/website.

  • Query UCCX database for calls from a specific Caller ID

    Hi,
    I did some searching and could not find this answer specifically.
    I have a request from the call center supervisor to provide a report of all calls coming into the CSQ's showing all of the important data (date, time, answered, not answered, length of call, disposition, etc.) for calls from a specific caller ID for a specific date range.
    The caller ID starts with 9XX-XXX-XXXX, so of course UCCX Historical Reports will not display this number as a parameter in the Detailed Call by Call CCDR report because I am limited to the first 32,765 rows. I tried modifying the XML file but have not been successful.
    I tried doing a query through the CLI but not sure if I have the query right.
    Any insight?
    Thank you very much.

    I tried modifying the XML file for the Detailed Call CSQ Agent report
    ICD_Detailed_Call_CSQ_Agent_en_us.xml with the following:
    BEFORE:
    SELECT distinct callednumber FROM contactcalldetail
    AFTER:
    SELECT SKIP 10000 FIRST distinct 20000 callednumber FROM contactcalldetail
    Unfortunately, there are no changes in the available parameters shown:
    The number starts with a '9', so I need to skip the numbers that start with 408. Any help?

  • I want to create a distinct (default) ringtone for calls from people not in my address book?

    I want to have one default ringtone for calls from people who are not in my address book.  I would also have a distinct ( different) ringtone for those people IN my address book.

    Seastar214 wrote:
    I want to have one default ringtone for calls from people who are not in my address book.  I would also have a distinct ( different) ringtone for those people IN my address book.
    Then do that.

  • Setting up Remote Desktop Apps for access from a Mac with 2FA

    Hi
    Setting up Remote Desktop Apps for access from a Mac with 2FA.
    I have a server 2012 remote access gateway, with remote apps published(which uses single signon), behind a 2FA connection (web based) and want to know if its possible to allow macs to connect to the remote Apps behind it. i cannot permanently remove any
    of the above setup as it is a requirement.
    When i connect from a mac i can login to both the 2FA and remote access web pages and see all the apps but when i click on any app it downloads it to the mac and when i try to run it using Remote Desktop App for MAC i get an error :
    "httpendpointexception: 4, The non-proxy http connection failed to connect with the message: 500 internal Server Error."
    I have tried with 2fa turned off for testing and get the same result.Does it support 2012 TSGW server? does it support Remote desktop apps? as i cant find a definitive answer on either.
    Thanks in advance for any advice.

    Hi,
    Thank you for posting in Windows Server Forum.
    From Error description it seems to be a communication issue between your Mac and your RD gateway server. If you connect from extranet, you may need Remote Desktop Gateway or a VPN/Direct Access connection to your intranet, or forward port 3389 on your router.
    500 Internal Server Error seems to be a HTTP related error. 
    The HTTP status code in IIS 7.0, IIS 7.5, and IIS 8.0
    Also, please double check the settings if you have a RD gateway implemented in you intranet.
    http://redmondmag.com/articles/2013/12/24/rd-gateway-in-windows-server.aspx
    In Windows Server 2012 R2 RD Gateway pluggable authentication is also introduced. This allows custom authentication routines to be used with RD Gateway. For example building a two-factor solution on top of RD Gateway is now possible which allows doing token-authentication
    to the RD Gateway which works seamlessly with RD Web Access or RDP file launching.
    Please check below article for more information.
    Windows Server 2012 R2 is coming what does this add to RDS – VDI
    In addition, please provide the log file from the client for further research.
    Microsoft Remote Desktop -> About Microsoft Remote Desktop -> Send log via email
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • For find activated lync client using SCCM 2012

    Hi All,
    In my current company we have in deployed lync client. But we are not sure how many clients are activated.
    Is there any way to find which system got activated using SCCM 2012.
    Please suggest and let me know any reference.
    Thanks 

    I really don't know, but I would guess that a file or registry key would change once it's activated. Basically, I would simply compare an activated system with a not activated system and look for the difference. Once you've located that you can create
    a compliance setting to see how many system are actived, or not.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Using a different port for SMTP

    Where can I change my preference of port number for SMTP? I would like to use 366 since I think my ISP is blocking port 25.

    Your ISP blocks inbound and/or outbound 25?
    Port 25 is used for server-server communication and can't be changed.
    If your ISP blocks port 25 inbound, then your server can't receive mail from other servers, even if you change it's port.
    If your ISP blocks 25 outbound, you still need to send to a destination port 25. For outbound, the only thing you can do is relay through your ISP (either from client, or configure postfix to relay through ISP).
    When people add alternate ports for SMTP, it's for the mail client to submit mail to the server. From there, server-server is always going to have a dest port of 25.
    If you wish to add an alternate port (you said you wanted 366) for mail submission, edit /etc/postfix/master.cf
    Find this line:
    smtp inet n - n - - smtpd
    add another below it (location doesn't really matter) like this:
    366 inet n - n - - smtpd
    Then stop/start mail server and port 366 will accept smtp connections.
    FYI- the standard port for smtp submission is 587. Doesn't matter if you want to use another port (366), just make sure you're not trampling on another service which may use that port.
    Jeff

  • Using separate ethernet ports for LAN and internet

    Following scenario:
    A couple of Lion clients and a Lion server connected to a switch. Switch connected to router for internet access. All devices, clients, server and router are in the same C-Class net.
    I'd like to connect the Lion server with 2 ethernet ports to the switch, so that one port is solely used for connections to the Lion clients (aka LAN) and the other port is solely used for connections to the internet. That way heavy LAN traffic to/from the server cannot bog down internet access to the server. Any ideas how to acomplish that?
    Usually you would configure the Lion server as a router and connect the Lion clients (via a switch) to one port and the cable modem to the other, so both ports are in different subnets. But I don't want all internet traffic from the clients going through the Lion server.
    The best I've come up so far was to configure both ethernet ports with static IP addresses. The one connecting to the clients with a 255.255.255.0 netmask but no router IP given. The one for internet with a 255.255.255.255 netmask and the router IP set to my physical router IP. It seems to work, but I'm not sure, whether this is the suggested way to do such a setup.
    Maybe some manual editing of the routing table is are more solid solution?
    Any tips appreciated.
    Pete

    What you want to do can be done but maybe not the way you are trying.
    First yes, you would use two Etherner ports on the Mac, if it is a Mac Pro or XServe it has two built-in, other Mac models can do this using a USB Ethernet interface.
    Next, the way I would normally do this is to have a separate switch for the WAN router, this would make the setup look like the following
    LAN Switch ----- Server ------------ Router --- Internet
           | |                             |
           | |                            NAT    
           | +-----------------------------+
           |
           +------ Client Devices
    The router could be doing NAT via one interface, or a separate Firewall box could do the NAT.
    Another possible way would involve segmenting the lan switch by setting up a VLAN and putting one port for the Servers second Ethernet connection on to that VLAN (using public IP addresses and the a connection to the router on that VLAN, the LAN switch could then route between the two VLANs. Cheaper LAN switches do not have this ability.

  • Can't use front USB port for external Hard Drive

    I have had some problems for about the past year with the front USB port on my 2009 13in Macbook Pro 5.5.
    As you know, there are 2 USB ports on the left side on a 13inch Macbook pro.  The one closest to me (the front one) works fine when I use it with a flash drive.  But when I connect my external 7200RPM external drive to it, after about a minute, it ejects then re-recognizes the disk. 
    I video edit with FCP and use the external as one of my scratch disks. 
    At first I thought maybe it was the cord or the drive that was messed up.  But then I connected my other external drive to this port and the same thing happened.
    But when I connected it to the back USB port, everything works fine. I haven't had any trouble.  So i make sure it's connected to that port when using the external.
    Why would this be happening.  It only screws up when using a standard external drive but not flash drives or any other peripherals.
    Thanks
    Brandon

    Exactly what Ogelthorpe mentioned.
    I bought a Seagate 500GB 7200RPM and bought an external case from Staples that has a big fancy led to show HD activity.  Sometimes it works and sometimes it doesn't.
    Tested it on my PC and it works all the time so it got me stumped.  Thought it was my MB.
    Decided to try another external drive drive on my MB and everything works.  So I returned the fancy external enclosure and bought the simple $10 one.
    Now everything works fine.
    Maybe changing your external case might help you.

  • Can I use the Ethernet Port for a computer when it is also used as a wireless network with an Airport Extreme as the access point for the wireless network

    Can I use the Ethernet Port  of the A1264 Airport Express to connect to the Ethernet port of a computer that does not have wireless capability when the Airport Express is also used on a wireless network with an Airport Extreme 5th generation as the access point for the network?
    I have AE 5th gen
    looking to buy (from ebay) the AEX A1264
    Various computers, printers and hubs for the network
    Is this possible to do?

    Bob, Thanks for the info. I have read different articles that said yes, but I wanted to make sure before I commit to buy. I have an older A1084 which I could not use the Ethernet port. I know at one point I was able to when I was on 10.4. Now that I am on an Intel processor and 10.8 I am going to have to upgrade some of my Apple wireless hardware.
    Thanks Again.

  • I want to know how many minutes were used last billing cycle for calling

    my daughter has been calling out of state a lot recently.  i want to know previous statement minutes and it also mentioned that out of area calls may not show up on bill right away. so how many minutes has she actually used this billing cycle?

    If you are the account owner, you can go online and view the usage for each line on your account.  For calls, you can go back 12 months and see the history.
    If she made the calls from your home area, then there should be no delay in them showing up on the bill. The delay comes if the phone is out of the home area and roaming; sometimes the information from the roaming towers takes more time to reach Verizon  computers.  Your question wasn't clear if she was simply calling an out of state number, or if she was out of state and making calls.

  • Using Eudora or Netscape7 for non-verizon email accounts with FIOS for access

    Since Verizon does not give tech support to 3rd party email clients, and using a non-Verizon email account creates additional problems, I decided to share what I learned the very hard way....certainly with no help whatever from Verizon tech support.
    First of all, there may have been a time (a day, a month, some random nanosecond) when you had to change the port to 587 it is no longer the case.  Port 25 works just fine, and in fact 587 no longer works in most cases.  So ignore tech support's claim that all you have to do is change the port number to 587...don't do it.
    And so long as you want to use a pop account other than verizon for your incoming email you will have to use what is referred to as SMTP Relay.  Verizon tech support will tell you that Verizon no longer supports SMTP Relay, and technically speaking that is true, but Verizon SMTP Relay is not what you need anyway.  What you need is to use the SMTP Relay facility of your Email Client, in my case Eudora and (for my wife) Netscape 7.
    Now before you can actually do anything you will have to have a valid Verizon email account, even if you never plan to actually use your verizon email address.  That means before you can set up your email client you must have a verizon email address. The tech who installed my FIOS supposedly set up my computer, which meant I had internet access, but he didn't set up the verizon email address.  I wasted 2 days before this came to light...so just make sure you have one before starting.
    Netscape 7.0  has an email client my wife has used forever so I had to make it work for Verizon FIOS.  Fortunatly they have a built in SMTP Relay facility (although they never call it that).  You set up your pop (incoming) server the way you always have.  In my our email accounts are on Earthlink, so you use the earthlink POP server for your incoming email.  If you are switching from whatever you have to Verizon FIOS, you will already have that set up anyway.  But you will have to change the SMTP server address to outgoing.verizon.net    and you will have to click the box that says Use Authentication, with  User Name and Password.  You will put into the User Name your verizon email account except without the .verizon.net    And the first time you use this Client to send email it will ask your for your password (use your Verizon password) and you should check the box that says to remember this password.    This will make everything work fine.  You will see on the SMTP Server information page a box that allows you to fill in the port.  If you leave it blank it will use port 25.  If you put in another port number it has to be right, and what is the correct number keeps changing based on which verizon person you talk to.  I found that 25 works, although they say it won't, and that others don't work, although they say they will.
    To Use Eudora (as i do)  first you have to be using the latest version 7.1 because it appears to be the first one that truely supports SMTP Relay. That's a free download if you don't have it.   Then you have to use multiple personalities.  Effectively you set up one personality (go to to tools and click on personalities) which is your normal email account (ie not your verizon one).  This is used for everything with the exception of the SMTP Server interaction.  YOu then set up a second personality which is for your Verizon email account. Be aware that you can still have that account use your normal email return address so folks who receive email from you can reply to your normal email address.  You can, independantly from that set up your incoming email pop account to be either your normal one or your verizon incoming email account (I do it the later way so I can receive something actually sent to my Verizon account, although I never give that out.  But now the important thing is that you set up your SMTP server to be outgoing.verizon.net  set up User Name to be your verizon email account but without the verizon.net and click on Authentication Allowed and Use Relay Personality.  Don't click on Use submission port 587, like I said you want to use 25, but if verizon has changed that yet again no problem as you can set up the port to use independantly using the Tools/Options/Ports , and finally you go to the Tools/Options/SendingMail stuff and select the SMTP Relay Personality to be the one that is set up for the Verizon email account.  That means your client will operate using your primary personality for everything except the SMTP part and for that it will get all its parameters from the Relay Personality. 
    This all worked.

    I use Eudora a my email client and routinely receive both my Verizon and ATT emails. 
    The last email I received  from my Verizon account was at 10:30pm on August 5.  I cannot send emails from Eudora at all either.
    My Verizon DSL email account is active through Verizon-Florida at my home there.  I am currently at my Ohio home and the DSL account is with Frontier which purchased Verizon here in Ohio.
    Does anyone know what might have happened to have resulted in my emails not being sent to or from my Eudora Client?

Maybe you are looking for