Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

YA Pro/Lite Softphone and Teleworker Solution

Status
Not open for further replies.

RDECIT

Technical User
Apr 28, 2009
376
GB
We are struggling to get YA Softphones to work with Teleworker. We have tried it with 3300 MXe and a Teleworker server in a DMZ with it's own WAN IP using YA Pro, no joy.

3300 CX with a Teleworker APC Module, using YA Lite, the same problem.

In both cases it we use the YA on the LAN using the local address of the Teleworker server, the certificate passes, it can be approved and the softphone works.

If we take the YA client offsite and configure it to reference the Teleworker via and external address the certificate fails, in both the cases above. We have spent a lot of time on this and can't work out why the certificate fails. We've checked the firewall rules as per the handbook but we never get past the cert. Please Help!
 
Have you enabled YA Softphone support in the teleworker?

What release of TW have you got?

Got this working no problem a couple of times.
 
Teleworker Soultion Status is enabled on the blade and also the YA Solution Status is enabled.
Installation of Teleworker Solution V4.1.28 blade.

 
So you ticked the bx to out it in teleworker mode yes? Put in the EXTERNAL IP address?

When you got the certificate were you on the LAN or at another site? Have found that it will always try the local IP first so if you get the certificate while internal it may not work.

Other thing is have you got a Firewall or somehting that might be blocking the ports?
 
So you ticked the bx to out it in teleworker mode yes? Put in the EXTERNAL IP address? YES.

When you got the certificate were you on the LAN or at another site? Have found that it will always try the local IP first so if you get the certificate while internal it may not work. LAN - Can always get a valid cert on the LAN and approve it on the 6000 MAS Certificates Screen.

Other thing is have you got a Firewall or somehting that might be blocking the ports? YES - I have opened the ports specified in the engineering guide. However there is a section about translation of ports, but that appears to be for the CCM Softphone only.
 
on my point number 2. try from a outside site. i.e. home or public wifi.

You will need to revoke the original certificate and get a new one from the YA

 
Matt, Perhaps my original thread wasn't clear. We only get the LAN to test the setup internally. We then revoke the certificate and try to set it up from the external location.

We always get on the YA client, failed to send certificate request.
 
I've double checked our firewall and it's been configured to allow all connections to and all responses from the Teleworker Gateway IP address on the following ports:

6801 and 6802
3998 and 6880
20000 to 23000
2114, 2116, 35000 and 37000

Is this correct.
 
are you able to get to the web management interface on the TW server from external?
 
It looks like we might be onto something, although it's not listed we have now opened and re-directed port 80. The YA in Teleworker now gets the certificate and we can approve it....AT LAST!

We now have a problem with no sound.
 
Just out of interest , have you got the TW working correctly for normal phones?

Under YA Support in TW server have you got the IP addresss of all the reuired fields as the IP address of the YA server?
 
Have you tried downloading the TNA (teleworker network analyzer) and checking the ports from outside?

Dave

You can't believe anything you read... unless of course it's this.
 
Hi Rob,

I'm pretty much stuck in the same place with my deployment. No sound.

I'll post my findings if I do find something, could you do the same?

I'm talking to the service providers that take care of the fw and routers.
 
Will do. We're attacking this both for out internal system (using a sonicwall) and a clients system (using a PIX) However the solution that Matt has provided requires the PIX to have a third port for DMZ (The engineering guidlines do state that two port routers are no supported) So we have ordered a NIC card for their PIX and I will be testing tomorrow with Matts config. Fingers crossed.
 
Rob,

Do you have any physical sets configured as Teleworkers?
Do they work if you do have them?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top