Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Unable to install Subsriber for CUCM 10.0(1)

Hi,

 

I have this pretty weird situation here. I tried to install a subscriber for my Publisher from another network but failed always with the error " Is the security password correct or the Publisher is offline?" something like that. But i tried installing a subscriber in the same physical server, it works. so this eliminates the possibility of security password wrong.

Also i check the firewall logs. I saw traffic going into the publisher from the installing subscriber. I can see from the logs that the subscriber is successfully connected to publisher via ssh but still cannot install.

 

Here are how my network setup.

 

Publisher -------- Core Switch 1 ------- Firewall ------- Core Switch 2 --------  Subscriber

Building A                                         Metro Wan                                           Building B

Network A                                                                                                     Network B

10.10.x.x                                                                                                       10.26.X.X

 

I am using MetroE something like a leased line.

 

All traffic have been allowed from the firewall.

 

Update:

Screenshots

 

Best Regards,

Dennis

26 REPLIES

Are the firewall rules

Are the firewall rules incoming/outgoing?

 

New Member

incoming and also outgoing. I

incoming and also outgoing. I check the policies where it was configured as any any.

Let me put it a more details into the drawing.

Cisco Employee

How much BW between sites??I

How much BW between sites??

I'd recommend you to install it locally, then move the server if you keep facing the issue, if the servers fail to establish the replication, then it's most definitely something in your network. 

HTH

java

if this helps, please rate

www.cisco.com/go/pdi
New Member

erm... around 10 to 20 mbps

erm... around 10 to 20 mbps per site.

 

So that means i can install the subscriber locally in the same physical server and then image out the subscriber to the other physical server?

 

Best Regards,

Dennis

Hall of Fame Super Silver

You could, but moving virtual

You could, but moving virtual machine (without SAN) is very, very time consuming.  Can you get the detailed install logs? Do you have the new sub defined in configuration with matching hostname before you start the sub install? Is NTP port reachable from sub to pub? Can you monitor the firewall for activity to see what's being blocked?

Chris

VIP Purple

Hi,As said by Chris,please do

Hi,

As said by Chris,please do check for NTP reachability.

 

If NTP is unsyncronised in Pub, SUB won't get install.

there is also a bug associated to it.Please refer the link.

https://supportforums.cisco.com/discussion/12250381/cucm-10-subs

 

regds,

aman

VIP Purple

Hi Dennis, Just guess:can u

Hi Dennis,

 

Just guess:

can u run the command utils os secure status and check whether it is permissive ?

If not, can make it permissive and then, try.

regds,

aman

New Member

Ah. Ok. I will run that

Ah. Ok. I will run that tomorrow as the server is on the other site.

 

best regards,

Dennis

VIP Purple

Hi Dennis, Everybody is

Hi Dennis,

 

Everybody is suggesting troubleshooting steps.Is the issue resolved or still struggling ?

 

regds,

aman

New Member

Hi Aman, Still struggling. I

Hi Aman,

 

Still struggling. I am still wondering what went wrong. Most probably will re create the sub again and reinstall.

 

Best Regards,

Dennis

VIP Purple

Hi Dennis,, check ntp status

Hi Dennis,,

 

check ntp status as well.

can u share utils ntp status from PUB?

regds,

aman

VIP Purple

suggest opening TAC case.

suggest opening TAC case.

 

regds,

aman

New Member

From the firewall logs the

From the firewall logs the NTP is reachable. It can reach the NTP servers. From the logs i see there are no other traffic being block or deny.

 

Also in the firewall logs the sub actually successfully connects to the publisher SSH.

 

So i am still puzzled with this.

 

Best Regards,

Dennis

New Member

adding ip address server as

adding ip address server as subscriber into publisher before you install subscribers, login into web-gui cucm publisher choose Menu > add server as subscribers.

and then makesure the DNS service for the CUCM, if DNS service not activated you must change the cucm hostname with the ip address.

 

 

 

Regards, Habibi
New Member

Hmmm... I have already add

Hmmm... I have already add the IP for the subscriber in the GUI setting.

 

For the DNS there are no DNS for all the system in this setup.

so you mean is now i need to add DNS settings for my servers?

 

Best Regards,

Dennis

New Member

if there no DNS for all

if there no DNS for all system, make sure the name server as publisher in the CUCM web-gui is IP Address

from the screenshoot the publisher hostname is MSIPA482, the subscriber trying to connect the publisher with the hostname by DNS, you need to change the hostname publisher in the IP Address

Regards, Habibi
New Member

In the Pub CUCM web-gui all

In the Pub CUCM web-gui all servers are IP Address.

But I did not set DNS in the system. How does it find the DNS server?

 

regards,

Dennis

Hi Dennis.Can you please post

Hi Dennis.

Can you please post the output of a show network cluster from CUCM PUB.

 

Thanks

 

Regards

 

Carlo

Please rate all helpful posts "The more you help the more you learn"
New Member

Hi here is the output. From

Hi here is the output. From this it says it is successfully sync... but the settings cannot complete.

VIP Purple

what is utils ntp status

what is utils ntp status  from PUb?

 

regds,

aman

New Member

(No subject)

New Member

read this link, i hope this

VIP Purple

Hi Yusuf, thanks for sharing

Hi Yusuf,

 

thanks for sharing the link[+5].

As Dennis has mentioned that none of the passwords have been changed.

 

regds,

aman

New Member

Hi Aman, i am quite lost for

Hi Aman,

 i am quite lost for the moment. Haha. From all those troubleshoot we have made have shown that the sub actually successfully connected to the database, means the security password is correct.

Also the NTP can be sync. So now i really not sure what is the main cause of it now.

 

Best Regards,

Dennis

New Member

Thanks for helping. Call the

Thanks for helping. Call the TAC have them troubleshoot found out some ports are block.

Check on the firewall logs still can't find who is blocking.

At the end client says that they have UTM. Check UTM and found out that the port 22 is classified as SSH exploitation error.

Then proceed in trusting the IP address. Now my subscriber installed successfully.

Thank you everyone that helped me for this. Also sorry for the late update.

New Member

Good news, have a nice day :)

Good news, have a nice day :)

dont forget to click answered

Regards, Habibi
291
Views
5
Helpful
26
Replies