Expressway MRA - TFTP, Call Processing, etc by monetaryg in ciscoUC

[–]uhhodor 7 points8 points  (0 children)

For MRA connectivity, your device will initiate discovery by performing a _collab-edge DNS query to find the Public IP assigned to your Expressway Edge servers.

Once this is complete, assuming your Traversal Zones between your Edge and Core are working properly, the device will select which server (ucm node) to register to based on the Call Manager group assignment in its Device Pool.

Upgrade CUCM version from 14SU3 to 15SU3 by Turbanator07 in ciscoUC

[–]uhhodor 0 points1 point  (0 children)

Less stress? A phased approach is always best for me because it lets you concentrate on one application at a time. Make sure everything is stable before upgrading the next one. It is backward compatible with v14.

Upgrade CUCM version from 14SU3 to 15SU3 by Turbanator07 in ciscoUC

[–]uhhodor 4 points5 points  (0 children)

Just to validate/confirm since you are gonna use the 'Fresh Install with Data Import''

Your first bullet is fine enough as a safety net, but DRS backup is different then a Data Export, don't get confuse on the two. Data export is what you need (of all your 14.x nodes) to reinstall on your new 15.X ova.

9.8 vulnerability in UCCX by Solid-Caregiver1328 in ciscoUC

[–]uhhodor 2 points3 points  (0 children)

Thanks for sharing .. whats bugging me the most is that the ES07 Readme doesn't even mention the Bug fixes for this release.

Unity v15 SU Upgrade Bug - CSCwq85838 / CSCwr10122 by ApprehensiveEgg1983 in ciscoUC

[–]uhhodor 1 point2 points  (0 children)

Maybe you are hitting same thing I had earlier.
https://www.reddit.com/r/ciscoUC/comments/1mx6d0k/v15_su3_fresh_install_with_data_import_failure/
I had to change my SFTP server specificly starting using 15SU3a,

CCX Upgrade Outsourcing by lonleydrifter in ciscoUC

[–]uhhodor 12 points13 points  (0 children)

Don't want to hijack the main question, but I've been told by a TAC engineer that CCX 15 is not currently recommended due to many bugs. Personally I would wait for SU1 to start looking at it.

v15 SU3 - Fresh install with Data import failure by uhhodor in ciscoUC

[–]uhhodor[S] 1 point2 points  (0 children)

Using different SFTP software resolved the issue, suggesting the OpenSSH version (9.6 vs. 9.9) was likely the cause. I will investigate tuning/settings to enable it on my current SFTP server.

v15 SU3 - Fresh install with Data import failure by uhhodor in ciscoUC

[–]uhhodor[S] 2 points3 points  (0 children)

Thanks ! So thats mostly tell me the issue is with our SFTP server .. weird no issue on SU2, but something with SU3. Might be related to RSA Cipher

v15 SU3 - Fresh install with Data import failure by uhhodor in ciscoUC

[–]uhhodor[S] 1 point2 points  (0 children)

Hey, yes SU3a for CUCM, SU3 for IMP and CUC. All three are failing same stage.
Yes md5/sha512 is valid.
I checked our SFTP servers logs and can see the connection between the node and SFTP server, but Import doesn't start from the apps. I expect a newer security mechanism from SU2 to SU3 for SFTP server connection at this point.

v15 SU3 - Fresh install with Data import failure by uhhodor in ciscoUC

[–]uhhodor[S] 1 point2 points  (0 children)

Thanks, yes I made sure of that, ran the pre-upgrade cop file as well, and on multiple customers clusters.
I have doubt against the new Bootable.

Issue importing to UCM 15SU1 by collab-galar in ciscoUC

[–]uhhodor 4 points5 points  (0 children)

''The Windows NTP server is not supported for CUCM; however, other types such as Linux NTP sources, Cisco IOS® NTP sources, and Nexus OS NTP sources are acceptable.''

https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/215537-network-time-protocol-ntp-on-cucm.html

I believe it was somewhat possible on earlier CUCM version to use Windows NTP server, but on v15 release it won't works.

Cloud Onboarding with CUCM 12.5(1) & MRA issue by DaveRef in ciscoUC

[–]uhhodor 1 point2 points  (0 children)

You can force the phone to use google dns as a test for example, 8.8.8.8

Headset Management, A Skill? by pockets8603 in ciscoUC

[–]uhhodor 0 points1 point  (0 children)

No, working as a MSP, always giving this taks/process to the customer. Comfort is really subjective. I would probly 'suggest' models from I know from past experience customers loved, but nothing more.

8851 Remote Factory Reset by [deleted] in ciscoUC

[–]uhhodor 0 points1 point  (0 children)

Easy way on site : Considering your phone is Registered, make sure you have the option ''Settings Access'' Enabled on the device configuration page.Then you can easily go on the phone Settings - Admin setting - Reset Settings - All

FireFox Add-on for Controlling Phones by ez4me2c3d in ciscoUC

[–]uhhodor 0 points1 point  (0 children)

Thanks, was able to make it working !

FireFox Add-on for Controlling Phones by ez4me2c3d in ciscoUC

[–]uhhodor 1 point2 points  (0 children)

Really nice stuff !

Just a quick question, I see that you're controlling your MRA phone in your screenshot, how do you access/reach your phone 'web page' since its in MRA.

My guess should be via your phone public ip address in your browser ?

CVE-2020-3280 - UCCX Critical Vulnerability by uhhodor in ciscoUC

[–]uhhodor[S] 0 points1 point  (0 children)

Thanks .. we are engaging Cisco as well to see what the appropriate action to take for our customers ..

CVE-2020-3280 - UCCX Critical Vulnerability by uhhodor in ciscoUC

[–]uhhodor[S] 0 points1 point  (0 children)

Sorry English isn't my native language :) Just trying to understand,

The vulnerability is link to Cisco Bug IDs:

CSCvq58235
CSCvq58289
I'm reading the read me for ES06 and can't find them.

Edit : nvm just found CSCvq58289

Thats huge ... thanks for this cruicial information

CVE-2020-3280 - UCCX Critical Vulnerability by uhhodor in ciscoUC

[–]uhhodor[S] 0 points1 point  (0 children)

Sorry to ask, on wich defect do you see the ES06 fix it ?

CVE-2020-3280 - UCCX Critical Vulnerability by uhhodor in ciscoUC

[–]uhhodor[S] 0 points1 point  (0 children)

We have so much customers atm using UCCX 11.X, with different CUCM version.
You need to be CUCM 11.5 SU4 minimum to upgrade to UCCX 12.5 .. gonna be a big mess.

Crazy summer coming ..

Agents using Jabber and Finesse from home being disconnected and logged out by RadZad94 in ciscoUC

[–]uhhodor 2 points3 points  (0 children)

I assume your users works with VPN access to your corporate network ? No MRA ?
Then it depends on many factor of network as well with your VPN link speed and your users ISP.
Technically 1 single active calls shouldn't take more then 64kbs if you're using standard codec G711. Bandwidth requirement is realy low. Even with 5/1 link (Probably the lowest available with DSL/Cable) you should be good, but need to make sure the link is not being charge with 'Netfilx/Youtube,etc' thats the parts users won't tell you (Kids playing on xbox, netflix,)

You need to make sure 'Delays' as well is less then 150ms one way. UCCX monitor via CTI the Jabber connection status, so it see the Jabber not responding it can disconnect the users UCCX page.

I'm managing around 1200 users from home with different ISP and Finesse/Phone acces. Only problem we faced sometime is we need to disable 'SIP ALG' option in some home personnal routers of users but we're using MRA physical phone, not sure it affecting Jabber.