Monday, October 31, 2022

UCCX Finesse login error - Authorization failed. Contact your system administrator

 When you re-generate Cisco CUCM tomcat certificate, you may get this error on finesse. 


1- Download tomcat.pem from CUCM publisher and uploaded the new CUCM tomcat certificates on the UCCX nodes as tomcat trust


2- Reload the UCCX

Monday, September 5, 2022

Expressway E and C Setup - MRA

Mobile and Remote access System Configuration

Expressway MRA use for registering your remote endpoints registering with CUCM without using VPN










Few Points

* If your are deploying over WAN, minimum recommended latency is 80ms

* Remote devices will be communicating with Edge initially using the Public IP, E Usually deploy in DMZ. C takes care of LAN side communication towards CUCM

* There will be two interface for Edge. Internal and External.

* Remote devices will be registered over Core, on CUCM you could find the registered device IP as C

* If you have redundancy, Then both C act as Active - Active


---------------------DNS Records-----------------


1 -  Create PTR DNS Record for each Xpressway C host

2 -  Create Expressway Cluster DNS for Cluster C

3 - Create PTR DNS Record for each Xpressway E host

4 -  Create Expressway Cluster DNS for Cluster E

5 -  Create SRV Records

create 2 Recors for Expressway E [ port number 8443]

service : _collab-edge

Protocol: _tls


---------------------Installation MRA with Expressway-----------------

** Install Both E and C. Following are the basic config

1- Add your NTP server on C and Expressway

2- Change your root CLI password

 Default User Name - root Default Password TANDBERG

command to change password 'passwd'

3- Add Options key on Both C and E. Once you add Expressway series key system will show as whether its Core or Edge

4- Add DNS server IP'series

5- Configure Clustering on C and E

->enter the Cluster Name and then add the peer 1 and 2 host name/IP address

->Reboot both E and C. Once it rebooted check your clustering is Active

6- Configure Unified Communication 

-> Go to Configuration-> Unified Communications -> Choose Mobile and remote access

7- Configure Domain > Add your Domain

8- Add a link between C and  CUCM 

configuration -> Unified Communications -> Unified  CM Servers -> Enter FQDN or IP or Pub

enter AXL details. Once its added CM cluster will be auto added

9- Add CA Certificate and Root Certificates 

On C go to Maintenance -> Security Certificates->  Trusted CA Certificates -> Browse and add rootCA certificate



Reinstalling CUC and UCCX Subscriber

We had UCS C220, recently UCS upgraded to C240 M4SX. All the secondary UC servers were running on 220. This new UCS racked in service provider managed DC. So the IP details were different. I have re-installed the subscriber and added to existing cluster. procedure is simple, steps given below

Note - During the installation you would require to enter the Web-security details (CN,OU etc)
use 'show web-security' to get the details from CLI. you would require to enter the OS admin password as well

UCCX Installation:
  1.  Login CCX Administration -> Go to System -> Servers -> and delete the subscriber node -> Restart the Publisher
  2. Once publisher is restarted check System -> Servers. Make sure Subscriber is removed from the cluster
  3. Start the installation, during the installation choose that this node as subscriber and enter the publisher details. Once installation completed check the cluster and DB replication. New subscriber will be part of cluster now 
CUC  Installation:
  1.  Login CUC Administration -> Go to System Settings -> Cluster -> Click Find -> Choose the Subscriber node -> Delete it -> Restart the Publisher
  2. Once publisher is restarted, make sure Subscriber is removed from the cluster
  3. Start the installation, during the installation choose that this node as subscriber and enter the publisher details. Once installation completed check the cluster and DB replication. New subscriber will be part of cluster now 

Friday, August 7, 2020

CUBE - ADD Diversion header for a specific number in FROM header

 

We had migrated all the DID's to SIP provider, however the Toll free numbers we had from Different Provider. All agents phone masked with TFN, But Since TFN from different provider SIP ITSP rejected the outbound calls agent make. To pass the TFN we need to add a Diversion header so that it will be authenticated from ITST and then call will be routed

request INVITE sip-header From modify "(.*sip:Your TFN @.*)" "\1\x0D\x0ADiversion: <sip:DID from ITSP@CUEB IP Address>"


Below Diversion header also work 

request INVITE sip-header Diversion add "Diversion: <sip:DID@CUEB IP Address>"

Monday, May 11, 2020

device Model code risdb

When you run 'show risdb query list phone'  device name will not be shown. instead it will be in enum code. complete enum code s given below

enum name
15 EMCC Base Phone
20 SCCP Phone
30 Analog Access
40 Digital Access
42 Digital Access+
43 Digital Access WS-X6608
47 Analog Access WS-X6624
50 Conference Bridge
51 Conference Bridge WS-X6608
62 H.323 Gateway
70 Music On Hold
71 Device Pilot
73 CTI Route Point
80 Voice Mail Port
90 Route List
100 Load Simulator
110 Media Termination Point
111 Media Termination Point Hardware
120 MGCP Station
121 MGCP Trunk
122 GateKeeper
125 Trunk
126 Tone Announcement Player
254 Unknown MGCP Gateway
255 Unknown
52 Cisco IOS Conference Bridge (HDV2)
53 Cisco Conference Bridge (WS-SVC-CMM)
83 Cisco IOS Software Media Termination Point (HDV2)
84 Cisco Media Server (WS-SVC-CMM-MS)
112 Cisco IOS Media Termination Point (HDV2)
113 Cisco Media Termination Point (WS-SVC-CMM)
131 SIP Trunk
132 SIP Gateway
133 WSM Trunk
85 Cisco Video Conference Bridge (IPVC-35xx)
522 BlackBerry MVS VoWifi
640 Usage Profile
598 Ascom IP-DECT Device
599 Cisco TelePresence Exchange System
36041 Cisco TelePresence Conductor
36219 Interactive Voice Response
61 H.323 Phone
72 CTI Port
134 Remote Destination Profile
30027 Analog Phone
30028 ISDN BRI Phone
2 Cisco 12 SP+
3 Cisco 12 SP
4 Cisco 12 S
1 Cisco 30 SP+
5 Cisco 30 VIP
9 Cisco 7935
6 Cisco 7910
7 Cisco 7960
8 Cisco 7940
10 Cisco VGC Phone
11 Cisco VGC Virtual Phone
48 VGC Gateway
12 Cisco ATA 186
124 7914 14-Button Line Expansion Module
336 Third-party SIP Device (Basic)
374 Third-party SIP Device (Advanced)
115 Cisco 7941
119 Cisco 7971
20000 Cisco 7905
302 Cisco 7985
307 Cisco 7911
308 Cisco 7961G-GE
309 Cisco 7941G-GE
335 Motorola CN622
348 Cisco 7931
358 Cisco Unified Personal Communicator
365 Cisco 7921
369 Cisco 7906
375 Cisco TelePresence
376 Nokia S60
30002 Cisco 7920
30006 Cisco 7970
30007 Cisco 7912
30008 Cisco 7902
30016 Cisco IP Communicator
30018 Cisco 7961
30019 Cisco 7936
30032 SCCP gateway virtual phone
30035 IP-STE
404 Cisco 7962
412 Cisco 3951
431 Cisco 7937
434 Cisco 7942
435 Cisco 7945
436 Cisco 7965
437 Cisco 7975
446 Cisco 3911
550 Cisco ATA 187
631 Third-party AS-SIP Endpoint
36049 BEKEM 36-Button Line Expansion Module
613 Cisco TelePresence Profile 52 (C60)
540 Cisco 8961
228 7915 24-Button Line Expansion Module
586 Cisco 8941
628 IMS-integrated Mobile (Basic)
36227 Cisco TelePresence MX800 Dual
493 Cisco 9971
36241 Cisco TelePresence DX70
36225 Cisco 8865
478 Cisco TelePresence 1000
562 Cisco Dual Mode for iPhone
606 Cisco TelePresence Codec C90
617 Cisco TelePresence MX200
253 SPA8800
611 Cisco TelePresence Profile 42 (C60)
620 Cisco TelePresence TX9200
582 Generic Single Screen Room System
684 Cisco 8851
497 Cisco 6961
593 Cisco Cius
584 Cisco TelePresence EX90
607 Cisco TelePresence Codec C60
621 Cisco 7821
36042 Cisco DX80
503 Cisco Unified Client Services Framework
232 CKEM 36-Button Line Expansion Module
688 Cisco TelePresence SX80
689 Cisco TelePresence MX200 G2
604 Cisco TelePresence EX60
36232 Cisco 8851NR
610 Cisco TelePresence Profile 42 (C20)
521 Transnova S3
548 Cisco 6911
558 Cisco TelePresence 400
36217 Cisco 8811
229 7916 12-Button Line Expansion Module
36216 Cisco 8821
36043 Cisco DX70
585 Cisco 8945
632 Cisco Cius SP
577 Cisco 7926
481 Cisco TelePresence 500-37
642 Carrier-integrated Mobile
633 Cisco TelePresence Profile 42 (C40)
36239 Cisco TelePresence DX80
564 Cisco 6945
583 Generic Multiple Screen Room System
626 Cisco TelePresence SX20
652 Cisco Jabber for Tablet
608 Cisco TelePresence Codec C40
623 Cisco 7861
690 Cisco TelePresence MX300 G2
616 Cisco TelePresence Profile 65 Dual (C90)
622 Cisco 7841
635 CTI Remote Device
468 Cisco Unified Mobile Communicator
614 Cisco TelePresence Profile 52 Dual (C60)
36213 Cisco 7811
681 Cisco ATA 190
505 Cisco TelePresence 1300-65
682 Cisco TelePresence SX10
86 Cisco IOS Heterogeneous Video Conference Bridge
484 Cisco 7925
615 Cisco TelePresence Profile 65 (C60)
592 Cisco 3905
634 Cisco VXC 6215
575 Cisco Dual Mode for Android
88 Cisco IOS Homogeneous Video Conference Bridge
547 Cisco 6901
520 Cisco TelePresence 1100
588 Generic Desktop Video Endpoint
479 Cisco TelePresence 3000
480 Cisco TelePresence 3200
36210 Cisco TelePresence IX5000
591 Cisco TelePresence 1300-47
627 Cisco TelePresence MX300
36224 Cisco 8845
645 Universal Device Template
36207 Cisco TelePresence MX700
619 Cisco TelePresence TX9000
580 Cisco E20
537 Cisco 9951
594 VKEM 36-Button Line Expansion Module
597 Cisco TelePresence MCU
659 Cisco 8831
648 Cisco Unified Communications for RTX
685 Cisco 8861
36208 Cisco TelePresence MX800
495 Cisco 6921
230 7916 24-Button Line Expansion Module
590 Cisco TelePresence 500-32
647 Cisco DX650
36235 Cisco Spark Remote Device
557 Cisco TelePresence 200
683 Cisco 8841
496 Cisco 6941
87 Cisco IOS Guaranteed Audio Video Conference Bridge
609 Cisco TelePresence Quick Set C20
227 7915 12-Button Line Expansion Module
596 Cisco TelePresence TX1310-65
612 Cisco TelePresence Profile 52 (C40)

Saturday, January 11, 2020

How to change Cisco CIMC Password

The procedure to change CIMC Password

1- Login CIMC GUI
2- Admin -> User Management
3- Click on the Admin Account -> Select Modify user 
4- In the pop up  window tick Chanage Password
5- Enter the new password and Save
6- You don’t need to restart any service or CIMC to effect the changes
7- You can logout and login back to check new password

Cisco UCS firmware upgrade


Recently I have upgraded UCS C240 from firmware to 4.0,



1-      Download UCS CIMC firmware from Cisco.com (Path Downloads Home >>Servers - Unified Computing>>UCS C-Series Rack-Mount Standalone Server Software>>UCS C240 M5 Rack Server Software)

2-      Login CIMC and Launch KVM (I was using Java)

3-      Activate the Virtual Devices from Virtual Media tab

4-      Map the ISO to the CD/DVD option.

5-      Then reboot the system waiting for the option to press F6

6-      select the Cisco vKVM-Mapped option (Cisco vKVM-Mapped vDVD1xx)

7-      Now the system will start copying the files and will perform some checks. This step would take 10-15 mins

8-      Host Upgrade Utility will show you list of upgrades, choose all or Specific

9-      When the upgrade completes all components will have status PASS: this would take 20-40 mins

10-   Click Exit and the server will reboot and activate the new CIMC. Wait for the server to come back up and you will see that CIMC has been upgraded

Ref below document, which talks about UCS firmware upgrade brief with screen shot.

Tuesday, December 3, 2019

CUCM DBReplication reset

When you reset dbreplication  you could check the status using 'utils dbreplication runtimestate'. you would be able to see number of of tables checked aganist the total of 706



Cluster Replication State: Replication status command started at: 2019-11-28-21-14
     Replication status command in PROGRESS. Checked 54 tables out of 706
     Last Completed Table: scratch
     No Errors or Mismatches found.


Cluster Replication State: Replication status command started at: 2019-11-28-21-14
     Replication status command in PROGRESS. Checked 118 tables out of 706
     Last Completed Table: functionrole
     No Errors or Mismatches found.

UC Data center movement

We had to shift our datacenter to another location. We had following components to shift from existing DC to new DC and business wanted to do it without any downtime and no additional cost apart from shipping the hardware.

UCS Servers
CUCM
CUC
UCCX
CUEAC
Expressway C and Expressway E
PLM

Following are the UCS and applications running on each UCS



ESXi01
C240 M4SX
ESXi02
C220-M3S
ESXi03
C220-M3S
EXPRESSWAYC01
EXPRESSWAYC02
UNITY CONNECTION 02
EXPRESSWAYE01
CUCMTFTP01
UCCX 02
CUCM01
EXPRESSWAYE02
CUCMSUB02
PLM01
CUCMSUB01

UNITY CONNECTION01
EXPRESSWAYC02

ATTENDANT CONSOLE1


UCCX01



We had multiple remote sites in the US region, so I have proposed to split it in two different DC's for geographical redundancy. We decided to ship ESXi01 initially and change the network to the new network. All the primary applications were running on ESXi01



Prerequisite


1- Update new IPs in DNS Records,

2- New TFTP IP address need to be updated on AD

3- You can clone Publishers and can use it in case any emergency. However Cisco does not support Cloning and Vmotion



This is what I did pre and post shipment of ESXI01


1- Communicated to local team that During the esxi01 movement activity, VOIP cluster would in READ ONLY mode and cannot make any changes

2- Mannual back up and total registered phone count taken. " Show Risdb query phone " would give you the total registered and unregistered details. Including firmware, phone type, IP address etc.

3- few screen shots from RTMT and CIMC console to make sure there are no major alarms

4- Before shipping changed the ESXi IP address

5-Shipped UCS device via overnight courier service

6-Connected UCS and changed CIMC ( CIMC only for UCS management, this won't impact anything)

7-started with CUCM Publiser IP change followed by Subs

8- CUCM DB didn't sync automatically so I did 'utils dbreplication reset all' then cluster REPLICATION SETUP changed to  (2) Setup Completed. Before it was showing  (3)DB Active-Dropped

9- Then CUC and PLM, CUEAC IP's changed with out issues

10- UCCX we could not change due to bug CSCve59850, I had to open a TAC case to fix this issue, TAC made changes in the root. however later changing IP address UCCX system -> server were showing as 'UNKNOWN", TAC again made changes in the intraclustercomm.ips

11- Expressway we didn't face any issues. Created a new DMZ setup and assigned new IPs and NAT IP. 

12- CUEAC  You need to change IP from Regedit and update it in TSP as well


License


We didn't changed the hostname and Domain name of servers. 


We had procured new license only for UCCX. 


CUC and CUCM license were on PLM and you don't require new license when you make network changes for CUC and CUCM


CUEAC -  Since this is running on windows license will not be void after changing IP


Major issue faced


1- Home office user's phone got unregistered, it was trying to communicate only Primary CUCM. I had created a new Device pool for home office phone and then added only active CUCM 






CCX Historical Datastore Replicate status shows UNKNOWN

I have changed UCCX IP Address to new IP, later when I tried to generate CCX reports I couldn't get any data in the report.  We have redundant UCCX nodes and the secondary node was not shown in HR Datastore. Following are the steps I followed to fix the issue


1
-
Go to 'Cisco Unified CCX Serviceability' -> Tools -> Datastore Control Center -> Replication Servers -> Related Links -> Click Go  -> from Data Datastore select "Cisco Unified CCX Historical Datastore"

I didn't see my secondary node and Replicate Status was showing as ' UNKNOWN'


2-  Click on Synchronize Data -> Now the data will be start sync, you could check the progress -> move your cursor towards Info and click on specs Icon


Once the data sync Job status would be shown as 'Completed'

If this didn't fix the issue, check utils uccx dbreplication status from CCX CLI and perform utils uccx dbreplication reset



Tuesday, November 26, 2019

Collect Expressway Logs



Collecting Expressway(EXP) Diagnostic Logs



Select Maintenance > Diagnostics > Diagnostic Logging

Check “Take tcpdump while logging” and select “Start new log”
Do this on both EXP E and EXP C and reproduce the problem.
Once the problem is reproduced, stop the Diagnostic logs on each EXP “Stop logging”
Click Download the logs to download it. Log will be download .tar format

The file name will be diagnostic_log_fclxpresswayx01_XXX. tar

Sunday, November 24, 2019

When publisher goes down, unable to recognize DTMF for the UCCX calls

I had to shutdown my publisher server and Primary Subscriber for UCS move to different DC. Due to this CUBE media resource got unregistered and it impacted UCCX  customer calls. The system was unable to recognize DTMF. The provider uses  RFC 2833 In a band and UCCX use Out of band, due to mismatch in DTMF you need MTP resource.


Provider -  RFC 2833 In band
UCCX Support only -  Out of band

I have changed following and media resource got registered back to CUCM and UCCX issue got fixed.

sccp ccm x.x.x.x identifier 1 version 7.0

sccp ccm group 1
 associate ccm 1 priority 1

Tuesday, October 22, 2019

UCCX Prompt Covert - Using Audacity


UCCX support only below format. You could convert the file using Audacity



·       Format: CCIT U-Law

·       Sample Size: 8-bit

·       Sample Rate: 8kHz


File>Export -> In the export dialog, choose ‘Save as type’ as  “Other uncompressed files

Format Options

Header = WAV

Encoding = U-Law





Sunday, October 20, 2019

FAX Setup Over SIP

You may encounter FAX issues when you convert PRI to SIP. Few steps to troubleshoot FAX related issues

1- From CUCM/ ATA side we need to make sure T.38 FAX Relay is selected




2- ATA following should be selected

3- CUBE Side

voice service voip
fax protocol t38 version 0 ls-redundancy 0 hs-redundancy 0 fallback pass-through g711ulaw
no fax-relay sg3-to-g3


4- Dial peer add following commands


fax-relay ecm disable
fax-relay sg3-to-g3
fax rate 14400
fax nsf 000000

5- Make sure on CUCM Region is properly configured. If ATA and CUBE are in two different Region, Make this two region codec is properly added.


6 -  CUBE you could enable following debugs to see what's happening for fax inbound and outbound


debug ccsip messages
debug voice ccapi inout
debug fax relay t30 all-level-1



Friday, July 5, 2019

Custom Windows 10 shortcuts

Here is two methods to create Custom Windows 10 shortcuts

Using Shortcut  

1-  In case if you wanted to access one particular excel (any application) file using RUN short cut Right click on blank area ->New ->Shortcut ->On next window you need to browse your file  -> Type a name for the short cut -> Press Finish

2- Cut that shortcut file and past in 'C:\Windows'

3 -  Open run cmd and type your shortcut file name


Custom Shortcut using CTRL+ALT

1- Enter 'explorer shell:AppsFolder' in Run

2-  In case you wanted to setup short cut for Notepad , Right click on Notepad -> Open file location ->Right click on the Notepad.exe application-> Properties -> Press CTRL and choose the shortcut letter
3-  To open the file press CTRL+ALT+ Shortcut letter

Monday, March 18, 2019

CUCM Media resourse usage from CLI

Following commands will provide media usage details from CUCM CLI.


show perf query counter "Cisco Media Streaming App" MTPStreamsAvailable
show perf query counter "Cisco Media Streaming App" MTPStreamsActive
show perf query counter "Cisco MTP Device" OutOfResources
show perf query counter "Cisco MTP Device" ResourceActive
show perf query counter "Cisco MTP Device" ResourceAvailable
show perf query class "Cisco MTP Device"

Sunday, February 24, 2019

Identify the last User login in CUCM


Login CUCM SSH

Enter file list activelog tomcat/logs/*

you will find localhost_access_log.txt text files , copy one of the file name

Enter file view  activelog tomcat/logs/localhost_access_log.txt

you could see the IP and user ID of users who logged in CUCM.



Saturday, October 6, 2018

RTMT-ALERT CCXToCUICCVDSyncFailed

I was getting this alert every day. This was because, "aaa" ID was not there in UCCX DB, however same ID present in CUIC reporting. I tried to delete it from CUIC but unable to delete it and I was getting cannot delete error.

RTMT Alert:


 RTR : User with userID:aaa failed to be synced to CUIC. Please run sync CLI command to fix the issue.
AppID : Cisco Unified CCX Cluster View Daemon ClusterID : 
NodeID : uccx01
 TimeStamp : Sat Oct 06 01:00:03 PDT 2018.
The alarm is generated on Sat Oct 06 01:00:03 PDT 2018.

run sql select * from cuic_data:cuicuser    ->This command is to see all the users that should have access on CUIC



I followed steps mentioned in the below Cisco forum and was able to delete the ID from CUIC.

https://community.cisco.com/t5/contact-center/uccx-10-5-shows-ccxtocuiccvdsyncfailed/td-p/2561092

https://community.cisco.com/t5/cisco-bug-discussions/cscup31962-commands-showing-on-the-bug-workaround-are-wrong/td-p/2499841

#UCCX Version :11.5


-------------------------------------------------------------------------------------------------------------------

I was getting below error when I removed one of the Admin CUIC user:

RTR : Failed to grant permission to the collection: XXXXX for the userGroup:AllUsers.ReportingUsers in CUIC.Please run sync CLI c AppID : Cisco Unified CCX Cluster View Daemon ClusterID :  


To fix this login UCCX CLI and Enter, you would get groupfullname

run sql select * from cuic_data:cuicgroup

Then enter following, make sure group name and defaultgroupid are matching here

·       

run sql update cuic_data:cuicgroup set groupfullname='AllUsers.ReportingUsers' where id='D7D7E1A610000132363635BD3F57F543'

·       run sql update cuic_data:cuicgroup set groupfullname='AllUsers.Agents' where id='5B526E081000013F000000BF0A4E5EB6'

·       run sql update cuic_data:cuicgroup set groupfullname='AllUsers.Supervisors' where id='5B53E1651000013F000000C40A4E5EB6'

 

·       utils service restart Cisco Unified Intelligence Center Reporting Service

·       utils service restart Cisco Unified Intelligence Center Serviceability Service

Sunday, March 4, 2018

Genesys Workspace Desktop Edition

Recently I got opportunity to work on Genesys contact centre solution with Chat,email and voice interactions.

In Cisco contact centre solution finesse is the Agent interface and voice path will be through your Cisco phone. Genesys Workspace Desktop Edition (WDE) is the agent interface and SIP endpoint will be running in the backed and that will take care of voice path.I have attached few snaps of WDE










Saturday, March 3, 2018

Finesse Certificate error

You may have noticed finesse certificate error when you access finesse from IE. Here is some tips to fix it on local machine. some time you get below error due to the certificate 


1-       Enter your finesse URL in IE and choose IE options and then add it Security – Trusted Sites
2-      Under Privacy Tab in IE option
Disable following highlighted in yellow

3-      Enter  your finesse URL in IE address bar and press Certificate error and then choose install certificate



 Choose local machine from the wizard







Install the certificate in Trusted Root certification authorities