cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10976
Views
5
Helpful
12
Replies

Expressway Core cannot connect to the UCM IM&P. XMPP router: Inactive

stavropouloss
Level 1
Level 1

I'm setting up a Teleconference environment (10.5 CUCM/IMP) with some MX300 G2, SX20 and many Jabber clients. The solution is the new Expressway Core/Edge.

It seems that I can't manage to make the Expressway Core to  connect to the Unified Communications environment and specifically with my Presence and IM UCM. Everything is configured properly in the Configuration > Unified Communications section. I can see that the connection to the UCM itself is Active but not to the UCM IM&P where I see the error "XMPP router: Inactive".

Every server name can be resolved by the DNS so there's no issue with this. Expressway Core is in the same subnet (switch) with the UCM and UCM IM&P. Passwords are corretly configured. There's no encryption enable between the UCM IM&P and the Expressway Core.

Am I missing something? Do I have to do any extra configuration for the IM&P side? Can anyone help me? I'm attaching some screenshots from my environment.

Thank you, Stefanos

 

 

1 Accepted Solution

Accepted Solutions

Michael Ciulei
Level 1
Level 1

Hi stavropouloss,

     In order to that service become active you need to have the Traversal Zone between Expressway C & E active.

     To have Expressway C & E traversal zone active you need to upload on each server certificates signed by a trusted CA authority. 

   Documentation about how to generate them can be found here: http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-1/Cisco-Expressway-Certificate-Creation-and-Use-Deployment-Guide-X8-1.pdf

Cheers buddy.

 

View solution in original post

12 Replies 12

rasimyigit
Level 1
Level 1

Do you configure the Firewallports, SRV Records, create the right certificates?????

I see that tls verify is not enabled. But you need that. Also which NIC Modell on the expressway you are drive? Single NIC and DUAL Nic? NAT or not NAT? Import questions :-)

Thank you for your reply!

I didn't talk about any firewall. There's no firewall between the expway core and the ucm environment they all are in the same subnet. I think I was clear with this.

I'm specifically talking about the connection between the Expway Core  and the UCM IM&P server internally. I'm not  messing with the traversal and dmz yet (I need certificates for the TSL there).

I also don't want encryption between my core servers, so why should I use tls? I think this is not a prerequisite, nor the certificates, nor the dns srv records at this point (again I'm talking about the internal network not dmz Expway Core and the UCM IM&P) .

I don't understand the questions about the NICs and NAT. I use only the first NIC of each Expway Core and Edge. Again there's no NAT anywhere in the internal network where the UCM, UCM IM&P and Expway Core are connected.

Thank you, Stefanos

Hi Stefanos,

 

Did you solve the problem?

I have same issue with you.

the status of IM and Presence server is XMPP router: inactive.

Any idea to solve this problem?

 

regards,

Ovindo

Hi Ovindo,

We are very curious whether have you solved the issue because we are also facing the same issue. Kindly help on this.

 

 

Regards,

Sakthivel C

Hi

I would suggest to check the following thread and make sure you have not missed any required configuration as Cisco document was not that clear for few configurations. 

https://supportforums.cisco.com/discussion/12200046/mobile-remote-access-expressway-inactive-jabber

 

https://ciscocollab.wordpress.com/2014/01/29/deploying-collaboration-edge/comment-page-1/

We are also having this issue and interested if you have resolved the issue.

 

Thanks.
 

Michael Ciulei
Level 1
Level 1

Hi stavropouloss,

     In order to that service become active you need to have the Traversal Zone between Expressway C & E active.

     To have Expressway C & E traversal zone active you need to upload on each server certificates signed by a trusted CA authority. 

   Documentation about how to generate them can be found here: http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-1/Cisco-Expressway-Certificate-Creation-and-Use-Deployment-Guide-X8-1.pdf

Cheers buddy.

 

Thank you for your reply!

So as soon as I enable the traversal zone between Expway Core and Edge then the Unified Communications service will automatically be activated and connect to the XMPP of the UCM IM&P? Because this wasn't too clear in the documentation to be honest. I definitely will try it tomorrow though.

Thank you,

Stefanos

Hi,

I have the same problem as Stefanos.

Unified Communications statusEnabled
XMPP routerInactive
Provisioning serverInactive

 

My travearsal zone is active with TLS.

What can fixthis problem?

Hello Tobias Bachetta

I had this exact problem.

I can not tell which is the root cause, but after a reboot of the VCS-E server, all returned to work properly.

Now, I can use the jabber through the web publication without problems.

Good luck

Just to follow this up I've managed to configure this. Anyway as soon as the traversal zone is active the UCM services will also get active. For this you need certificates for the TLS negotiation of course. Additionally you need upload tomcat and xmpp certificates of UCMP and IMP to the expc trusted CAs list. Following exactly the document Michael provided should do the trick.

Chi Fai Leung
Level 1
Level 1

Hi Cheers buddy,

Actually, I made TLS tunnel is working fine between the Expressway-C (Traversal Client) and the Expressway-E (Traversal Server).

But the Expressway-C still fail to the IM&P "XMPP router: Inactive" (Expressway-C > Configuration > Unified Communications > IM and Presence servers)

And fail on the ... (Status > Unified Communications)

XMPP router: Inactive

Port forwarding mesh: Inactive

IM & Presence servers: failed

 

 

Any idea for that?

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: