Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ONE-X MOBILE PARTIALLY CONNECTED FROM WAN 2

Status
Not open for further replies.

BrianCosta

Systems Engineer
Oct 25, 2018
376
JO
Hi ,,,

Need Help from the following case:

IPO and Application Server Rls 11

The IPO SIP Domain : ipo.masafat.jo
The XMPP Domain: msft-ipo.masafat.jo

The SRV and A Record configured in Private and Public Domain
The Firewall/NAT firewall Configured as document
The Ports set in Manager: UDP: 5060, TCP:5080, TLS:5081
Put the Public IP on the Network Topolgy, and firewall tyoe:Unknown

through wifi, the one-x is working
from wan, fully connected when the voip mode is not always, when set the voip mode to always down to partially connected.
the customer trace the traffic on firwall told me that when application request ports after firewall there is no replay from IPO and one-x portal side.

have you any idea from where can i start to troubleshoot this issues ?

Thanks
 
Do you have a trace of when the user attempts to login on the OneX mobile app over the WAN?

Secondly, the one x mobile app is very flakey, you should look to going over to Equinox :)

Thank you

ACSS

Just another day in the life of ME
 
@Manie3: at the monitor, nothing, we will try wireshark, at the customer sophos firewall, the ports is forwarded but there is no reply from pbx side, also for first time when connect from outside its connect fully because this is not set to voip, when set the voip mode to always the one-x down partially.
about the equionx, the customer need this to be worked, i suggested already to the customer.

Thank you.

 
I would like to Explain it again:

I'm running Avaya IP Office 11. I'm trying to get One-X working with VoIP. I installed the app on my phone, and it works fine on the local network. When I go off-site, the app says "VoIP is partially connected.
Looking at the Wireshark Trace, I do not see any 5060 (SIP) attempts. Looking at the Firewall packet sniffing I do not see and 5060 SIP) attempts. I temporarily removed all port/IP restrictions from my firewall to the One-X server, but it still wasn't working.
This is my topology
172.16.40.99 is my ipo 500 box (Reolves ipo.masafat.com)
172.16.40.97 is my one x portal server (Resolves msft-ipo.masafat.jo)
I have already create fqdn on my dns server, both of those DNS entries resolve to a public IP. The public IP NAT internal One-X Portal Server IP local IP my phone use the one x server Domain name.
from off-site, Using a browser,
https://[Public- IP-ADDRESS]:8444/rest/my/im-info
https://[Public- IP-ADDRESS]:8444/rest/my/sip-info
I can access and see user information.

LAN-VOIP_pthttb.png


LAN-Network_Topology_p1omhp.png


So it seems like the Avaya system itself is blocking the external connections. Any ideas? Does anybody have any idea about it?
 
Not sure if this is the cause but Domain name shouldn't include the ipo part as that makes it an FQDN and not a domain.

| ACSS SME |
 
@pepp77 i think you are on to a winner with that.

@BrianCosta on your domain server what have you got set for the forward zone? And then in the host entry what do you have set?

Cheers

ACSS

Just another day in the life of ME
 
@pepp77 @ Manie3 : Thank you in update, and here is the DNS configuration:

- Private Side:

Untitled4_uchtz2.png


Untitled5_ynxc4z.png


Untitled6_ftb5pe.png


Untitled7_dprugs.png


- Public Side:

A Record (domain:msft-ipo.masafat.jo/IP: 94.xxx.xx.xxx)
A Record (domain:ipo.masafat.jo/IP: 94.xxx.xx.xxx)

TCP SRV Record:

1) Protocol :_tcp / Service: _sip/ port:5060/ host: ipo.masafat.jo
2) Protocol :_tcp / Service: _xmpp-client/ port:5222/ host: msft-ipo.masafat.jo

UDP SRV Record:

1) Protocol :_udp / Service: _sip/ port:5060/ host:ipo.masafat.jo
2) Protocol :_udp / Service: _xmpp-client/ port:5222/ host: msft-ipo.masafat.jo

TLS SRV Record:

1) Protocol :_tls /Service: _sip /port:5061/ host: ipo.masafat.jo

TCP_SRV_Record_huhhat.png


TLS_SRV_Record_goncvp.png


UDP_SRV_Record_cwfn0j.png


Thanks Again .
 
You don't need any of those SRV records, just the A records. The rest is provided by the app <-> One-X portal communication on initial contact (port 8444).

Externally your two DNS names should resolve to your public IP which have the correct port forwarding on your firewall to the IPO (5060,5061), and the One-X portal Server (8444, 5269, 9443, 8069, 5222 etc).

ACSS (SME)

 
Thanks All,

Solved, found that the server provider holding the public DNS forwarded the DNS to the website company. now its connected.

Thanks Alot all ...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top