Lync MX -Externally not working

We are having an issue with Lync MX externally.
Lync MX Internally(domain joined) is working fine so is Mobility (external Only-internal not required), Lync 2010/2013 clients are working fine internally and externally.
It is a small deployment 2x FE and 1 x Edge.
When we try logging on from Lync MX externally we get the spinning that never ends. By enabling logging we get :
Direction: outgoing;source="local"Peer:
edge.pool.Mydomain.com:57398Message-Type: responseStart-Line:
SIP/2.0 401 Unauthorized
Looking further into the logs like the external access edge send the SIP/2.0 401 Unauthorized
We are using public certificates on the FE. And
 Certificate Revocation List (CRL) Distribution Point (CDP) for the certificates issued to Lync server points to an HTTP resource instead of an LDAP resource as per :
http://technet.microsoft.com/en-us/library/jj823129.aspx
All servers are on CU7.
Please let me know of any suggestions you may have in further troubleshooting this issue. I believed I have covered all troubleshooting steps available, but might
of missed some.
Thanks a lot in advance.
$$begin_record
Trace-Correlation-Id: 4102754091
Instance-Id: 0037822A
Direction: outgoing;source="local"
Peer:
edgeFQDN.MyDomain.com:57398
Message-Type: response
Start-Line: SIP/2.0 401 Unauthorized
From: <sip:[email protected]>;tag=b30bd1e0cf;epid=9a2fefef5c
To: <sip: [email protected] >;tag=C1DDC329DEAF0304014EBB25D437EA2B
CSeq: 1 REGISTER
Call-ID: 11172a5257a14d85a0c7fd2adf6ed9cd
Date: Tue, 18 Dec 2012 11:52:55 GMT
(This timezone is a bit confusing, client and server are in EST -5)
WWW-Authenticate: NTLM realm="SIP Communications Service", targetname="MyFrontEnd.domain.local", version=4
WWW-Authenticate: TLS-DSK realm="SIP Communications Service", targetname="
MyFrontEnd.domain.local ", version=4, sts-uri="https://ExternalWebServicesFQDN:443/CertProv/CertProvisioningService.svc"
Via: SIP/2.0/TLS
192.x.x.x (internal Edge IP):57398;branch=z9hG4bK3B762A20.E711664720C9EC67;branched=FALSE;ms-received-port=57398;ms-received-cid=608E00
Via: SIP/2.0/TLS
10.x.x.x (Lync MX Client):59982;received=63.131.143.173;ms-received-port=3061;ms-received-cid=866600
Server: RTC/4.0
Content-Length: 0
Message-Body: –
$$end_record

Hi Shahan,
Thanks for the reply.
Please see below.
Testing connectivity to the Lync Autodiscover Web Service server for a secure connection on port 443 to obtain the root token.
Connectivity to the Lync Autodiscover Web Service test successful.
Test Steps
Attempting to test Autodiscover Web Service URL
https://lyncdiscover.mydomain.com/Autodiscover/AutodiscoverService.svc/root.
Autodiscover Web Service URL successfully tested.
Test Steps
Attempting to resolve the host name lyncdiscover.mydomain.com in DNS.
The host name resolved successfully.
Additional Details
IP addresses returned: 64.27.x.x
Testing TCP port 443 on host lyncdiscover.mydomain.com to ensure it's listening and open.
The port was opened successfully.
Testing the SSL certificate to make sure it's valid.
The certificate passed all validation requirements.
Test Steps
ExRCA is attempting to obtain the SSL certificate from remote server lyncdiscover.mydomain.com on port 443.
ExRCA successfully obtained the remote SSL certificate.
Additional Details
Remote Certificate Subject: CN=MyFrontEndPoolFQDN, OU="MyCompany, Inc.", O="MyCompany, Inc.", L=Jersey City, S=New Jersey, C=US, SERIALNUMBER=xxxxxxxxxxx, Issuer: CN=GeoTrust SSL CA, O="GeoTrust, Inc.", C=US.
Validating the certificate name.
The certificate name was validated successfully.
Additional Details
Host name lyncdiscover.mydomain.com was found in the Certificate Subject Alternative Name entry.
Testing the certificate date to confirm the certificate is valid.
Date validation passed. The certificate hasn't expired.
Additional Details
The certificate is valid. NotBefore = 4/30/2012 10:20:46 PM, NotAfter = 3/2/2013 3:19:52 AM
Testing HTTP authentication methods for URL
https://lyncdiscover.mydomain.com/Autodiscover/AutodiscoverService.svc/root/user.
HTTP authentication methods successful.
Additional Details
Web Ticket URL found as expected and confirmed anonymous access isn't allowed.
Testing HTTP content for URL
https://lyncdiscover.mydomain.com/Autodiscover/AutodiscoverService.svc/root/domain has McxService.svc.
Http Content is verified
Additional Details
Found as expected McxService.svc and confirmed anonymous access not allowed.
Kind Regards:
Galya

Similar Messages

  • Lync Meet Now not working

    Hi,
    I am using lync 2010 and users are unable to join online online meetings externally, getting 404 - File or directory not found when clicking on the meeting URL. On front end server i am getting below error when user initiates a meeting:
    A Create Conference request sent to an Mcu was rejected. It will be retried but if this error continues to occur conferencing functionality will be affected.
    Mcu: https://FrontEndFQDN:444/liveserver/datamcu/ Conference: sip:lync.test1@domain;gruu;opaque=app:conf:focus:id:9JC9TMSJ Error: otherFailure
    Cause: Overloaded or incorrectly functioning MCU.
    Resolution:
    Ensure that the Mcu is functioning correctly.
    I have checked File Share folder permissions and they are correct. Not sure if this is related but this issue came after my file share folder went down. It is now up again with correct permissions but meetings are not working.

    Hi,Ali,
    If above still doesn't work,please double check the file share permission to verify:
    1)Configure the NTFS file security on the new  folder and you  grant
    Read & Execute permissions to Everyone.
    2)verify that the Administrators group is already granted
    Full Control in NTFS security .
    3)Configure the share permissions so the administrator account is granted
    Full Control. 
    Also make sure you have restart the Web conferencing service and IIS service.
    Regards,
    Sharon
    Sharon Shen
    TechNet Community Support
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question.

  • Mac Lync 2011 and Lync 2013 - Autodiscovery not working

    We're currently setting up a Lync 2013 topology including Front End Pool and Edge Server.  I've been told that the Lync 2011 client should work with lyncdiscover and lyncdiscoverinternal as it does for IOS and Windows.
    However looking at the logs being generated by the Lync 2011 client this doesn't seem to be the case.  I'm seeing
    sipinternal, sip, sipexternal when Lync 2011 is set to AutoConfigure.  I do not have any of these configured.
    If I manually specify lyncdiscover and lyncdiscoverinternal the logs show it's starting to find the Front End Servers, but still errors.
    What am I doing wrong?

    Hi,
    Please add the following SRV records in internal DNS Server:
    _sipinternaltls._tcp.sipdomain.com
     _sipinternal._tcp.sipdomain.com
     _sip._tls.sipdmain.com
    Then flush the DNS cache on the local Mac computer, then test the issue again.
    Best Regards,
    Eason Huang
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Eason Huang
    TechNet Community Support

  • Lync A/V not working via Edge except for Federation

    I have an interesting problem.
    Internal users can do audio/video/screen sharing just fine from the internal network.
    I can do A/V and screen sharing with my federated contacts just fine from my internal network.
    When I use Lync on an external network (from home, public wifi, or even 4G), I can see presence, IM back and forth with no issues, but I can not do Audio/Video or screen sharing. I can do the whiteboard/Q&A/etc. It connects the call but I don't see or
    hear the other internal participant, and then it disconnects after exactly 10 seconds.
    The 2013 Lync Mobile app has the same issue - I can IM, but cant use audio or video.
    Does anyone know where I should start? I currently have a mixed topology with Lync 2010 and 2013 front-end servers, and a Single consolidated 2010 Edge server, with 3 external IP's addresses NAT'd to 3 public addresses. I remember that this used to work,
    but since it is not a heavily used feature, I don't know when it stopped working. It may have stopped when I installed the 2013 FE servers but i'm not positive.

     You can verify my earlier statement by looking at your ICE candidate list when your AV fails... 
     Look in snooper at the log, and search for 'candidate'... you should see a list of at least 6 entries similar to this:
    a=candidate:1 1 UDP 2140706431 192.168.1.101 39052 typ host
    a=candidate:1 2 UDP 2140705918 192.168.1.101 39053 typ host
    a=candidate:2 1 TCP-PASS 6656159 x.x.x.x 56276 typ relay raddr 192.168.1.101 rport 39041
    a=candidate:2 2 TCP-PASS 6656158 x.x.x.x 56276 typ relay raddr 192.168.1.101 rport 39041
    a=candidate:3 1 UDP 16648713 x.x.x.x 55824 typ relay raddr 192.168.1.101 rport 39050
    a=candidate:3 2 UDP 16648712 x.x.x.x 52421 typ relay raddr 192.168.1.101 rport 39051
    a=candidate:4 1 TCP-ACT 7086863 x.x.x.x 56276 typ relay raddr 192.168.1.101 rport 39041
    a=candidate:4 2 TCP-ACT 7086350 x.x.x.x 56276 typ relay raddr 192.168.1.101 rport 39041
    a=candidate:5 1 TCP-ACT 1664797951 y.y.y.y 39041 typ srflx raddr 192.168.1.101 rport 39041
    a=candidate:5 2 TCP-ACT 1664797438 y.y.y.y 39041 typ srflx raddr 192.168.1.101 rport 39041
     missing typ relay or typ srflx raddr means you're not successfully talking to your edge, and getting ports allocated, which is my suspicion. The best troubleshooting step from there is a network capture to verify whether you are getting responses
    to your TURN requests. I can't comment on the connectivity test website, as I haven't used it, but I have spent a lot of time troubleshooting edge issues in multiple environments... 
    Jon McClary
    Using the lync logging tool, which components should I log to get this output?

  • Lync Inactive Timer Not Working - Starts after 5 minutes rather than 20 minutes

    I have a client who has her Inactive timer set to 20 minutes.  I verified that the registry entry is set as such.  We have rebooted her system and cleared her Lync cache files.  She does not have a screen saver set, and her plugged
    in power setting for turning off the display is set for 30 minutes, and put the computer to sleep is Never.  Battery power options has the display turning off after 5 minutes.  Her system is plugged in and the Inactive status kicks off
    after 5 minutes and the display does not turn off.  I can not figure out why it is kicking off after 5 minutes rather than 20 minutes as it is set.  Any ideas on what else might be causing it to go inactive after 5 minutes?  Or what else I can
    try to get it to initiate the 20 minutes that it has set?

    My apologies, I didn't check the location being the 2010 forum and was hoping it might still be 2013 as we get a lot of 2013 posts in the 2010 forums.  The app doesn't currently work with 2010 which stinks.  I was thinking if it
    worked we could beef it up so it worked well for you and add some additional features.  In the end, there's no native option but it's a good idea.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications
    This forum post is based upon my personal experience and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • Roles authenticed externally not working

    i have created a role OPS$dummy which is authenticated externally..
    i have also set the initialization paramters os_roles and remote_os_roles to true
    but now when i manually try to set the role at the client side it says
    ora 01989 role ops$dummy not authorized by operating system.
    please guys can you just guide to solve this problem...

    oracle linux 5... any how got the solution... i created groups on teh server and then added the users to that... it worked..
    can this os_authent_prefix value be added to the name of the role at the beggining...

  • Lync 2013 is not working properly

    Hi,
    I have installed Lync 2013 FE server and it was working fine until yesterday. I am not able to Csenable users or couldnot open Lyncserver controlpanel. I am receiving error about unauthorized authorization failed. I restarted sql browser service,uninstall
    ms silverlight and all other options which showed online, but I am getting same error. Please  help me to find the solution this.
    Thanks.

    Hi shrigiriraj,
    On your Lync Front End Server, open IIS, expand Lync Server Internal Web Site, browse cscp to check if you can access successfully. If you can access the website successfully, the issue is more of a DNS issue.
    Best Regards,
    Lisa Zheng
    Lisa Zheng
    TechNet Community Support

  • Lync 2013 Mobility not working

    Dear All,
    I have Lync 2013 Server running in my environment. Below are the details,
    1) We have one Lync FrontEnd server as well as one Lync Edge Server installed in Egypt Site & one Lync FrontEnd server as well as one Lync Edge Server installed in Dubai Site in a Single domain.
    Users who are in Egypt site pool are able to login through Lync Mobility but unfortunately users in Dubai Site pool are unable to login through Lync mobility.
    Anyone help would be highly appreciated.
    Thanks & Regards,
    Zeeshan Butt

    Hi Zeeshan Butt,
    You can try to test in the internal network in site Dubai.
    If a user in site Dubai login with mobile externally, the user will connect to the Reverse Proxy. The autodiscover service on Egypt site will search the user information about which pool he belongs and return the right
    external Web service URL of that pool. Then the user will connect to the right pool (Site Dubai) through the Reverse Proxy belongs of Site Dubai.
    You can use Lync Connectivity Analyzer to check if the correct URL of web services have been returned from autodiscover service:
    http://blogs.technet.com/b/nexthop/archive/2013/02/08/the-new-lync-connectivity-analyzer.aspx
    Please also try to login mobile manually to have a test:
    https://<ExtPoolFQDN>/Autodiscover/autodiscoverservice.svc/Root for external access
    https://<IntPoolFQDN>/AutoDiscover/AutoDiscover.svc/Root for internal access
    Note: the ExtPoolFQDN is the External web FQDN of Site Dubai.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync Mobile App not working without WIFI

    HI,
    we have Lync 2013 deployed and everything works fine. We can do Voice Calls, Video Calls etc.
    But when we switch off the WIFI and only 3G or 4G is enabled, we can call persons, but after we accept the call, it gets terminated and we can't hear each other.
    any idea?
    EDIT: We get the error "Could not establish a connection"

    Hi repa1982,
    Since A/V is now supported over 3G/4G, or Wi-Fi the Edge Server plays a larger role in mobility deployments.  In the diagram below, you can see that the mobile client will still send signaling information via the Reverse Proxy, but it will now send media
    via the A/V Edge interface on the Edge Server:
    Click the link below for more information.
    Lync 2013 Mobility
    http://blogs.technet.com/b/dodeitte/archive/2013/02/27/lync-2013-mobility.aspx
    Best regards,
    Eric

  • External not working

    My problem is this. My boyfriend gave me his external (Western Digital, 120G). I've had it for 6+ months now. I have used it in both a pc and my macbook. It has worked fine until recently when I've tried to transfer files over from my mac to pc. I'm not sure what the problem is. I can use it on my mac, it appears on my desk top and I can open and view all the files. When I plug it into the PC (and I've tried a few different PCs) however, the flash drive icon doesn't show up at all. Not on the desk top, not under removable devices in my computer. I don't know where else to look for it. I'm assuming since it doesn't show up under my computer that it's not being recognized in the drive. Also, I do see that the format is FAT32.
    Please help!

    Sorry about the long response.
    Most likely, the external that you are using may not be compatible with your PC, although it is with a mac. You should check the product labeling to see EXACTLY what the system req'mts are and make SURE your computer complies with all of them.
    Hope it helps.

  • Drag and drop documents to Lync 2013 message not working

    I have searched the forum and can't find a reference to my specific issue.  With Lync 2010, I could drag and drop a word document or an excel spreadsheet into the message box.  The recipient would get a message to click on the document to retrieve
    it.  When I do this with Lynch 2013, all that displays in the message is an icon for a word document or an excel spreadsheet . . . the recipient does not receive an actual document that can be opened.
    How do I get Lync 2013 to allow for dragging/dropping like Lync 2010 supported?
    Thanks!

    Hi lac55,
    You can right click the icon, it will prompt you to download the file and the file will be saved under “C:\Users\xxx \Documents\My Received Files”.
    Best regards,
    Eric
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Lync 2013 Mobility not working in MultiSite Topology

    Dear All,
    I have Lync 2013 Server running in my environment. Below are the details,
    1) We have one Lync FrontEnd server as well as one Lync Edge Server installed in Egypt Site & one Lync FrontEnd server as well as one Lync Edge Server installed in Dubai Site in a Single domain.
    Users who are in Egypt site pool are able to login through Lync Mobility but unfortunately users in Dubai Site pool are unable to login through Lync mobility.
    External webservices are published on both Sites. Furthermore Dubai Site Pool users are able to login through Lync Client from external but they are unable to login through Lync Mobille Client.
    Anyone help would be highly appreciated.
    Thanks & Regards,
    ZB

    Is lws.abc.com external web url for Egypt site?
    How about lyncaepool.abc.com and communication.abc.com?
    I would like to confirm if you pasted two URLs in IE directly. Here are some tips for troubleshooting the issue.
    For multiple pools, the Autodiscover traffic can be routed to a single Front End pool as long as both pools have their external Web services published. Once a client connects to the Autodiscover service it will be returned the external web service FQDN for
    either pool, depending on which pool the user account belongs to.
    Thus, you must have external Lyncdiscover record pointed to Egypt site. Once Dubai external user connects to Egypt Autodiscover service, it will be returned the external web service for Dubai Site Pool and user connects to Dubai Site Autodiscover service(https://<Dubai
    ExtPoolFQDN>/Autodiscover/autodiscoverservice.svc/Root) and UCWA. We can check if mobile client is able to resolve Autodiscover service URL of Dubai Site by typing the URL into manual configuration of Lync mobile client.
    Here is a great blog about Lync mobility Autodiscover process.
    http://blogs.technet.com/b/nexthop/archive/2012/04/25/lync-server-2010-mobility-deep-dive-autodiscover-service.aspx
    If the issue persists, please paste the result of Lync Connectivity Analyzer for further troubleshooting.
    Kent Huang
    TechNet Community Support

  • Exchange 2010 SP3 cohabitation Exchange 2013 ecp?exchver=15 from external not work

    Hi
    i have installed an exchange 2013 cohabitation with exchange 2010 for migration. outlookanywere,ecp,owa, autodiscovery...etc are configurered
    when i try to connect to the eac or owa internaly its work, but when i try to do externaly https://mail.mydomain.com/ecp?exchver=15
    i have error 302, 301 to many redirections
    how can i fix this
    thanksin advance

    Hi,
    Generally, status 301 means that the resource (page) is moved permanently to a new location. Please refer to Sneff_Gabor's suggetsion to check the Redirect setting s for OWA and ECP in IIS manager.
    Additionally, please provide more information about your issue and collect any error logs for further troubleshooting.
    Regards,
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Winnie Liang
    TechNet Community Support

  • CFNA/CFB internal external not working

    I run CCM 4.1(3)sr2. When I configure different forwarding destinations in the CFNA/CFB fields the call gets forwarded to the internal destination regardless of where the call comes from. I dial from PSTN via cell phone but the call goes to the internal destination every time. Thoughts?

    Go to CCM Admin -> Device -> Gateway and find the gateway for incoming PSTN calls. Click the gateway and find the endpoint for these calls. Make sure that Call Classification is set to OffNet.
    Hope this helps. If so, please rate the post.
    Brandon

  • Lync 2013 /w Edge not working properly (internal/external same domain name and all "external" users"

    Hi,
    I've got some issues with a Lync 2013 setup.
    The config consists of 2 lync servers. One FE and one Edge. All seems to work except audio in meetings and Sip.
    The setup is like this (fake ip's used):
    Front End:
    Internal IP: 172.16.0.10
    External IP: x.x.185.10
    All ports open in Cisco ASA
    internal AD DNS: dialin/lync/meet/lyncdiscover to Front end internal ip. edge/lsedge/sip points to edge internal ip
    EDGE:
    Interal IP: 172.16.0.11 (no gateway configured)
    External IPS: x.x.185.11, x.x.185.12, x.x.185.13
    All external IP's are direct internet facing, no NAT (a firewall is in place).
    All external interfaces are using a wildcard certificate.
    All server are running in a remote data center, so basically no internal users. We all connect to the external interfaces. The Windows domain name (AD) is the same as our External DNS (companyname.com).
    Autodiscover works, we can logon, chat but there is no audio. The audio test failes. Also SIP is not working with a sip trunk.
    External DNS: sip/webconf/av are pointing to their external ip's. sipexternal is a cname to sip. lyncdiscover/lync/dialin/meet all point to the Frond end External ip.
    _sip._tls/_sipfederationtls.tcp/_xmpp-server.tcp all point to the sip.companyname.com ip.
    I just can't figure out what is wrong.

    @PSingh123 I'll try the logs in a minute and get back with the results.
    @PaulB_NZ Thanks for the input. In my opinion the FE does need an external IP. How else will you be able to connect if you are a remote worker?
    The Edge is (asfar as i know) needed for Enterprise voice and Federation with other (external) sip domains. It's not needed for basic (chat/video/whiteboard etc) Lync functionality for both internal and external (remote) users.
    The Edge is to communicate with services/users outside the origanisation.
    I do still think that the basic topology (FE with internal IP and Nat'ed external ip working with an Edge with internal IP and 1 external IP nat'ed to 3 DMZ ip's) is correct in this case.
    I can be wrong and in that case would like to be pointed to the correct configuration.
    75           
    Points
    Top 15
    PSingh123        
    Partner        
    Joined  Jun 2007        
    9
    PSingh123's threads
    Show activity

Maybe you are looking for

  • Very Slow Disk Access

    Recently I've had to restart my PB multiple times in order for it to start up because it just sits with the Apple logo and the circle going. I booted from a backup drive, no problem, but when I attempted to reformat the drive via Disk Utilities, it w

  • My pc sound level is very low on playback from dvd and most websites even though its at 100 percent

    the playback level on dvd and most video streams is very low.(youtube seems ok)This is my second pavillion g7 w/ windows 7 .The first had a defective fan but the sound level was ok and there was a graphic eq section for sound control with other outpu

  • Urgent help : Need to recover a database without backup and archivelogs

    Hi, We are in urgent need to recover a database without backup and archivelogs one datafile seems corrupted SQL> recover automatic database until cancel using BACKUP CONTROLFILE; ORA-00279: change 10527325422479 generated at 07/27/2011 03:13:04 neede

  • ICal keeps sending email notifications of past agenda items

    iCal keeps sending email notifications of all agenda items from the last 2 years (then I bought my laptop). After laptop start up this action is repeated every hour. How can I stop these >300 emails coming in every hour? Am not using iCloud & not sha

  • My preview mode icon doesn't work

    Just upgraded to CS3 master collection on Windows XP Very inexperienced on InDesign however. My preview mode icon does not work as it did on the CS2 version. I have to go view-screenmode-preview to see the preview mode - this is a bit of a slow way c