Hello I have three remote sites that are very similar in configuration and layout. Each site has a gateway using MGCP and SRST with a VPN connection over the internet (T1 or DSL). Periodically 2 of my 3 sites are failing and this is the message that I get in the trace and event viewer:
Error: StationEventAlert - Station alert.
TCP ProcessID: 22.214.171.1243
Device Text: 32: Name=SEP001930C8F22A Load= SCCP41.8-2-2SR3S : Invalid SCCP message! : Invali
App ID: Cisco CallManager
Cluster ID: StandAloneCluster
Node ID: 192.168.18.20
Explanation: Station device sent an alert to Cisco CallManager.
Recommended Action: Ensure that the configuration for identified device is proper..
The phones will reset soon after I receive this message. However, the gateway is fine and stays up.
TAC is stumped. Any ideas?
Mmm, do you have the SR number?
The sites directly connected to the CCM never unregister or reset?
I had a case last year in which customer was getting the same errors and was a duplex mismatch in the VPN path.
I would recommend to gather sniffer trace CCM and SDL traces from CCM to see what exactly is happening.
have you alreday tried removing tftp caching from Advance TFTP service parameters:
"Enable Caching of Constant and Bin Files at Startup" set to False
"Enable Caching of Configuration Files" set to False
"Build CNF files" set to Build All
Restart the TFTP service after making the changes.
The final answer was that the phones were loosing keepalives somewhere. Enough so that the phone would restart, the invalid SCCP message was just a byproduct.
In the end there wasn't too much that we could do about it.