| cms |
cms_400_malformed |
internal |
Checks “400 Malformed or invalid Ms-Asserted-Verification-Level header” has been received form S4B. CMS failed to resolve _sipinternaltls SRV record. |
evfedoto |
| cms |
cms_additional_call_to_s4b |
external |
Checks if request to create additional Lync call to URI may failed because URI does not resolve to any Lync dial plan entries. Causing presentation share is not visible for S4B users. |
evfedoto |
| cms |
cms_app_sharing_fails_tcp_3478_fails |
external |
Check for TCP connectivity issue with TURN server as this can cause application sharing with Microsoft to fail |
hocao |
| cms |
cms_CSCve08105 |
external |
Checks if defect CSCve08105 is hit: CMS media process restart. |
evfedoto |
| cms |
cms_CSCve08141 |
external |
Checks if defect CSCve08141 is hit: CMS media process restart. |
evfedoto |
| cms |
cms_CSCve83819 |
internal |
Check if there is application sharing from a remote callbridge into a dual-homed conference on certain versions. |
stejanss |
| cms |
cms_CSCvf84935 |
external |
Checks if defect CSCvf84935 causing unexpected restart with ServerManagementCmgrParticipant::actOnCmgrApiExit”. |
evfedoto |
| cms |
cms_CSCvf99765 |
external |
Checks if defect CSCvf99765 is hit: Crash with the following thread detail “server!CmgrLyncResolution::CmgrLyncResolution_process”. |
evfedoto |
| cms |
cms_CSCvg31108 |
external |
Checks if defect CSCvg31108 is hit: Crash with the following thread detail “server!CmgrLyncResolution::CmgrLyncResolution_process”. |
evfedoto |
| cms |
cms_CSCvg41087 |
external |
Checks if defect CSCvg41087 is hit: CMS media process restart. |
evfedoto |
| cms |
cms_CSCvh92717 |
external |
CSCvh92717 Polycome HDX does not decode CMS encoded H.264 HP correctly |
ftenerel |
| cms |
cms_CSCvh95331 |
external |
Checks if defect CSCvh95331 is hit: CMS out of memory when more than 1000000 calls handled. |
stejanss |
| cms |
cms_CSCvm61285_peer_reflexive |
internal |
Check if CSCvm61285 is hit where CMS is not able to cope with peer reflexive candidate: Instead of using its TURN server to send media to the remote side, it is sending media directly to the remote chosen candidate. |
hocao |
| cms |
cms_refer_cscvg04834 |
external |
Checks if defect cscvg04834 is hit: CMS removing MS-conversation-ID from REFER messages sent by Skype for Business. |
hocoa |
| cms |
cms_stun_rdp_lync_CSCvg23794 |
external |
Checks if system is affected by CSCvg23794 causing Lync to sends RDP failure over Expressway solution. |
evfedoto |
| cms |
cms_api_duplicate_config |
internal |
If we have the db access with all API config, we can check if all config made via API is unique as if not that could lead to unexpected behavior. |
stejanss |
| cms |
cms_api_gui_configcheck |
internal |
If we have the db access with all API config, we can check if all config is made via API or GUI as a mix is not recommended and known to lead to unexpected behavior. |
stejanss |
| cms |
cms_callb_webb_connection |
external |
Check if there is any connection error between the callBridge and the webBridge. |
evfedoto |
| cms |
cms_cma_cscvh58156 |
external |
Check whether we might run into defect CSCvh58156 where the presentation and normal video on CMA (WebRTC and thick client) are switched from location. Done by checking if version is 2.3.0 and if we either have xmpp server or webbridge enabled on the server. |
stejanss |
| cms |
cms_cucm_adhoc_unauthorized |
internal |
Checks if we have a warning for the CUCM escalation when it queries for the device status user.warning acano cucm-esc.CodianToCms: WARNING: Authentication failure while querying system status |
stejanss |
| cms |
cms_detect_expired_certificates |
external |
Check if all certificates have valid dates. |
evfedoto |
| cms |
cms_even_number_db |
internal |
Check if the database cluster contains a recommended number of nodes. |
evfedoto |
| cms |
cms_even_number_xmpp |
internal |
If database cluster, we can check if they have an odd number of nodes for better resiliency. Otherwise, throw an alarm. |
evfedoto |
| cms |
cms_expired_expiring_mmpaccounts |
internal |
Checks for all MMP user accounts (if available) if they are valid still or when expiring soon (within 3 weeks) |
stejanss |
| cms |
cms_h323_cscve86049 |
external |
Checks if system is affected by CSCve86049 causing H.323 gateway not to transmit/receive presentation content to 2nd joined H323 endpoint |
kogami |
| cms |
cms_ip_same_subnet |
external |
Check ip addresses of CMS are not in the same subnet. |
evfedoto |
| cms |
cms_jid_xmpp_domains_mismatch |
external |
Check if the guest jid domain does not match with one of the xmpp domains. |
evfedoto |
| cms |
cms_loadbalancer_not_listening_to_lo |
internal |
In case of CMS Edge, the Web Bridge is a XMPP client which needs to connect to the LB which will than proxy to the XMPP server via the trunk. If the WB and the LB are on the same node and listening on the same interface, LB needs to also listen to the loopback interface otherwise the WB will try to connect to the LB and will timeout. log example: Sep 5 11:34:08 user.info acano “webbridge”: INFO : Attempting XMPP connection to 91.224.226.90:5222 Sep 5 11:34:20 user.info acano “webbridge”: INFO : [SESSIONS] XMPP connect timeout for session 9217bc4c-5a0e-489c-a445-8e8e01987f9c |
hocao |
| cms |
cms_outboundrules_distributionlinks |
internal |
If we have the db access with all config, we can check if it is a CMS cluster or not. If it is a cluster and there are peer link SIP domains configured, we should have appropriate outbound rules and incoming call matching rules for it. If it is a cluster and there are no peer link SIP domains configured, we can check for the server if this is a callbridge and then check on that IP for the rules if it is applicable to all servers. |
stejanss |
| cms |
cms_streamer_issues |
external |
Streaming Warnings: Callbridge unable to connect to streamer Bad streamUrl format No stream URL configured for space. Handshake failed |
evfedoto |
| cms |
cms_turn_default_interface |
external |
Checks TURN’s default interface correctly setup. Causing TURN server is not able to route media traffic from external client to Core. |
evfedoto |
| cms |
cms_turn_incorrect_cert_config |
external |
Check whether the TURN server certificate is valid, meaning that it is configured on the server as otherwise the TURN service on UDP is not available either. |
stejanss |
| cms |
cms_xmpp_cert_validation |
internal |
From version 2.4, the Call Bridge and Web Bridge have trust stores to hold a certificate whitelist for the XMPP servers. This enables the Call Bridge and Web Bridge to check the identity of the XMPP servers when making connections to them. Using the trust store is a safer option to ensure that XMPP servers are legitimate. This removes the risk that an attacker could redirect traffic to an insecure server. |
evfedoto |
| cucm |
call_sccp_no_orc_ack |
external |
Performs a check that for an outgoing SCCP OpenReceiveChannel message an OpenReceiveChannelAck is recewived |
kvancoil |
| cucm |
cucm_adhoc_to_cms_failure |
external |
Check if Ad-hoc calls to CMS callbridge group are failing. |
belhoest |
| cucm |
cucm_call_cause_value_overview |
external |
Check for calls that has abnormal disconnect cause values. |
kvancoil |
| cucm |
cucm_call_fails_on_da |
internal |
Check if a call is blocked by digit analysis, for example due to the dial plan misconfiguration or device not found(unregistered). Do not trigger the alert when forwarding is configured. |
belhoest |
| cucm |
cucm_call_rejected |
internal |
check if a call failed because the target device rejects the call |
hocao |
| cucm |
cucm_hunt_list_CSCuv40352 |
internal |
Check if Hunt Pilot not forwarding call when members are unregistered. defect CSCuv40352. |
belhoest |
| cucm |
cucm_location_not_enough_bw |
internal |
Check if a call has failed because the bandwidth between 2 locations ran out |
hocao |
| cucm |
cucm_mtp_req_dtmf_mismatch |
internal |
Check if any calls is forced to audio only because of MTP due to DTMF mismatch. |
belhoest |
| cucm |
cucm_mtp_req_on_trunk |
internal |
Check if any calls is forced to audio only because of MTP is allocated due to trunk configuration. |
belhoest |
| cucm |
cucm_rtp_savp_CSCuq84875 |
external |
Check if CSCuq84875 is hit. |
hocao |
| cucm |
cucm_sip_message_too_big |
external |
Check if there is a SIP message unprocessed by CUCM because it is too big. |
hocao |
| cucm |
cucm_xcoder_allocation_failed |
internal |
Check if xcoder allocation failure prevent call to connects. |
belhoest |
| |
microapp_error |
internal |
Check for CVP applications which have different microapp error codes. |
ayankovs |
| |
redirect_cvperror_tcl |
internal |
None |
ayankovs |
| ipcc |
error_codes |
internal |
Check for calls that have failed due to errors. |
hkeramid |
| ipcc |
no_atr |
internal |
Check if call fails due to the agent extension not being in agant targeting rules range. |
hkeramid |
| ipcc |
busy |
internal |
Check if call end up with “Busy” event. |
ayankovs |
| ipcc |
connect_failure |
internal |
Check if call end up with “Connect Failure” event. |
ayankovs |
| ipcc |
no_answer |
internal |
Check if call end up with “No Answer” event. |
ayankovs |
| ipcc |
req_instruction_timeout |
internal |
Check if call end up with “Request Instruction” event. |
ayankovs |
| multiple |
any_binding_response_not_received |
external |
Check if a Binding Response has been sent by a party but not received by the other. |
hocao |
| multiple |
any_call_cscve90209 |
external |
Checks if cscve90209 is hit :return: |
hocao |
| multiple |
any_detect_missing_stream |
internal |
This DS will check if all streams going from device1 to device2 and from device2 to device1 arrive safe and sound at destination |
emarecha |
| multiple |
any_duplicated_packets |
external |
Check if duplicate packets are seen as part of a RTP stream. |
belhoest |
| multiple |
any_only_host_candidate |
external |
Check for calls that only have host candidates in the SDP and no relay candidates as this can cause calls without media. |
hocao |
| multiple |
any_sip_message_changed_by_firewall |
external |
Checks if there is any difference between SIP message sent from firstNode to secondNode and the same message received by secondNode. |
hocao |
| multiple |
bfcp_floor_request_not_granted |
internal |
Checks if there is negative response to BFCP Floor request which indicates issue with presentation sharing. |
vsidimak |
| multiple |
bfcp_one_way |
external |
Checks if there is one way BFCP communication for any Call and alerts about the presentation sharing failing over separate content channel. |
vsidimak |
| multiple |
call_no_ack |
external |
Checks if any call could not connect because there was no ack to 200 OK |
hocao |
| multiple |
multi_packets_statistics_over_stream_link |
internal |
|
emarecha |
| multiple |
stun_allocate_fail_insufficient_capacity |
external |
Check if a STUN allocate requests fail with insufficient capacity error code |
hocao |
| multiple |
stun_allocate_wrong_credentials |
external |
Check if a STUN allocate requests with credentials was responded with 401 unauthorised |
hocao |
| multiple |
stun_binding_request_not_permitted |
internal |
None |
hocao |
| multiple |
any_sysInfo_alert |
internal |
Checks if there is system informations available in the analysis. |
belhoest |
| multiple |
vcs_config_traversal |
external |
Check if the vcs-E is using signle NIC with static NAT and verifies that the vcs-C connects to the public IP address of the vcs-E. |
kvancoil |
| multiple |
any_faulty_sip_messgaes |
internal |
Checks if there is faulty sip messages in the analysis. |
hocao |
| vcs |
call_cmr |
external |
Check if there is a SIP call to WebEx for CMR Hybrid Deployment or CMR Cloud and when there is verifies that all requirements are met: early offer, encryption, video support, enough bandwidth and correct version. |
kvancoil |
| vcs |
call_no_media |
external |
Check if packet capture is available and if so iterates over all the calls and finds if the media is supposed to pass through the box if we receive RTP. If not we verify the pcap covers the time of the call and an alert is raised. |
kvancoil |
| vcs |
call_packet_loss_jitter |
external |
Check for packet loss and high jitter values in RTP streams as these have direct impact on quality. |
kvancoil |
| vcs |
call_skype_server_timeout |
external |
Check if there is a (Microsoft) SIP call to Skype (on-prem deployment or Office365) and when there is verifies the requirements of Skype on DNS and certificates when there is a 504 Server time-out response. |
stejanss |
| vcs |
call_webrtc_cscve37570 |
internal |
Check if CSCve37570 is hit. |
hocao |
| vcs |
im_microsoft_407 |
internal |
Check if there is a 407 returned by IM&P for instance messaging with Microsoft Federation via Expressway. |
kvancoil |
| vcs |
vcs_appsharing_skype_tcp_syn_received_for_ice |
external |
Check if application sharing fails for call from skype is failing due to tcp syn not received. |
hocao |
| vcs |
vcs_call_b2bua_not_listening |
external |
Check if a TCP connection to the B2BUA could be successfully established. The B2BUA is used for calls that involve any zone that have the encryption setting set to anything other than auto. |
hocao |
| vcs |
vcs_call_CSCui14790 |
external |
Check issues in H.323 calls with FECC enabled as Expressway uses the same ports for Data and Video on OLC. |
stejanss |
| vcs |
vcs_call_CSCuw93156 |
external |
Check issues in interworked calls missing H.264 in the SDP out from VCS leading to one-way or no video issues. |
stejanss |
| vcs |
vcs_call_CSCux85276 |
external |
Check issues in interworked calls missing videoBadMBsCap in the CapSet for H263 causing potential no video issues or call connect issues. |
stejanss |
| vcs |
vcs_call_CSCuy64490 |
external |
Check if CSCuy64490 is hit. |
hocao |
| vcs |
vcs_call_CSCvc47502 |
external |
check if CSCvc47502 is hit: B2BUA SRTCP SSRC context limit causes EPs to report ‘replay detected’ |
hocao |
| vcs |
vcs_call_CSCvc98425 |
external |
Check if CSCvc98425 is hit. |
hocao |
| vcs |
vcs_call_CSCvd57073 |
external |
Check if CSCvd57073 is hit. |
hocao |
| vcs |
vcs_call_CSCvg15240 |
internal |
Check “400 Malformed route header error” from S4B causes skype users cannot see presence of the Jabber users. |
evfedoto |
| vcs |
vcs_call_CSCvh31290 |
internal |
Check “400 Malformed route header error”. Expressway-E not forwarding all record-route info to Microsoft side on INFO, causing instant messages fails with Skype for Business. |
evfedoto |
| vcs |
vcs_call_skype_no_media |
external |
Diagnostic signature that checks if there is a (Microsoft) SIP call to O365 Skype and and if there is an ICE negotiation failure with Microsoft. |
kogami |
| vcs |
vcs_cscve41422_dual_home |
external |
Dual Home through VCS/Expressway fails because of CSCve41422 |
hocao |
| vcs |
vcs_CSCve82299 |
internal |
Check if CSCve82299 is hit. |
kvancoil |
| vcs |
vcs_h245_tcp_connection |
external |
Check issues in h245 tcp connections. |
evfedoto |
| vcs |
vcs_not_responding_to_binding_request |
external |
Check if STUN binding request received by VCS is not answered because VCS has not route to send the response |
hocao |
| vcs |
vcs_sdp_too_large |
internal |
Detects if a SIP message received was too big, leading VCS to be unable to decode the message |
hocao |
| vcs |
vcs_alarm |
external |
Check if there is alarm raised on vcs. |
belhoest |
| vcs |
vcs_certificate |
external |
Check if VCS certificate match the requirements. |
belhoest |
| vcs |
vcs_clock_synchronisation |
external |
Check if clock synchronisation issue causing MRA phone registration failures. |
kvancoil |
| vcs |
vcs_cscvc58081 |
external |
Check if vcs is affected by CSCvc58081. |
kvancoil |
| vcs |
vcs_cve_checker |
internal |
Check if all the cve for vcs. |
hocao |
| vcs |
vcs_detect_expired_certificates |
external |
Check if certificates have valid dates. |
evfedoto |
| vcs |
vcs_duplicate_dns_a_rule |
internal |
Check if there are 2 A records resolving to VCS-E IP address |
hamoshen |
| vcs |
vcs_e_no_public_address |
external |
Checks if a public IP address has been configured on -E server. |
hocao |
| vcs |
vcs_e_sip_udp_enabled |
internal |
Check if SIP UDP is enabled. |
hocao |
| vcs |
vcs_exwy26045 |
internal |
Check if the system was unable to handle a certificate with validity date 2050 or later. |
kvancoil |
| vcs |
vcs_gw_to_external_int |
external |
Check if the default gateway of expressway-E points to the external interface. |
asuchank |
| vcs |
vcs_no_cn_in_cert_CSCvc47500 |
external |
check for CSCvc47500: VCS doesn’t start properly if server cert is missing common name |
hocao |
| vcs |
vcs_old_generation_hw_check |
external |
Check if there is an unsupported software version running on 1st generation hardware. |
belhoest |
| vcs |
vcs_searchrules_priority_check |
external |
Check if 2 search rules have the same priority for the same protocol that can leads into call failures. |
hamoshen |
| vcs |
vcs_space_in_search_rule |
external |
Check if a regex starts or ends with a space. |
belhoest |
| vcs |
vcs_spark_config_check |
external |
Check if Expressway-E configurations for Spark Hybrid are correctly configured. |
kogami |
| vcs |
vcs_traversal_zones |
internal |
Check the status and failure message for the traversal zones. |
belhoest |
| vcs |
vcs_verification_error |
external |
Check if TLS handshake failed because of a missing CA certificate in the trust store or certificate received is invalid (in time). |
hocao |
| vcs |
vcs_wrong_dscp_values |
external |
Checks if Edge server marks packets with wrong DSCP value due to CSCvg76528. |
belhoest |
| vcs |
vcs_wrong_external_lan |
external |
Checks if the external LAN has been set to the correct interface. |
hocao |
| vcs |
mra_basic_auth_disabled |
external |
Check if Basic auth is disabled. Applicable for X8.10+. |
hocao |
| vcs |
mra_bug_space_in_userid |
external |
Check if CSCvb29050 is hit. |
evfedoto |
| vcs |
mra_c_responds_with_http_502 |
external |
Checks if a MRA login fails because Expressway-C was unable to resolve fqdn for one of the HTTP requests for MRA |
hocao |
| vcs |
mra_capf_authentication_failure |
external |
Check requirements for MRA login with capf. |
belhoest |
| vcs |
mra_conflicting_sip_trunk |
external |
Check if there is a registration attempt towards CUCM on a connection that is in use by a SIP Trunk on CUCM as CUCM does not allow registrations on a SIP Trunk. |
belhoest |
| vcs |
mra_cscur92743 |
external |
Check if we are hit by CSCur92743 (MRA: Call license limit reached alarm) |
stejanss |
| vcs |
mra_cscut91464 |
external |
Check if Jabber softphone failed to failover via MRA due to Jabber limitation (cscut91464). |
evfedoto |
| vcs |
mra_cscuu06649 |
external |
Check if cscuu06649 is hit. |
belhoest |
| vcs |
mra_cscva26845 |
external |
Check for occurrence of bug CSCva26845 for not being able to add IM&P 11.5 server to C from X8.8 (case-sensitive). |
stejanss |
| vcs |
mra_cscvc33543_cscvf14623 |
external |
Check whether we run into bug CSCvc33543 and CSCvf14623 by checking the symptoms for which a restart of Expressway-C is required. |
stejanss |
| vcs |
mra_cscvc90758 |
external |
Check for occurrence of bug CSCvc90758 for not being able to add IM&P 11.5 server to C from X8.8 (case-sensitive). |
stejanss |
| vcs |
mra_cscvf25604 |
external |
Check for occurrence of bug CSCvf25604. SSH tunnels are down on E nodes, but up on C nodes. |
evfedoto |
| vcs |
mra_cscvm76492 |
external |
Check for occurrence of bug CSCvm76492. Jabber BIB recording over Expressway results in single recording with incoming & outgoing audio mixed together |
belhoest |
| vcs |
mra_cvsverifier |
external |
Check if the certificate requirements are met between VCS-C and IM&P. |
hocao |
| vcs |
mra_dh_key_too_small |
external |
Check if CUCM/IM&P offerts DH key >= 1024 which is a requirement as of X8.7.2. |
hocao |
| vcs |
mra_domain_not_configured |
external |
Check if -E is failing to find a path to send SASL authentication query. |
hocao |
| vcs |
mra_edge_config_checker |
internal |
Check if a UDS server is specified in the edgeConfigResponse. |
hocao |
| vcs |
mra_external_uds_missing |
external |
Check if Expressway-C can resolve the cisco-uds external domain. |
hocao |
| vcs |
mra_get_edge_config_forbidden |
external |
Check if a 403 is returned for a get_edge_config. |
hocao |
| vcs |
mra_homecluster |
external |
Check system for “Unable to determine home CUCM” error. |
evfedoto |
| vcs |
mra_jabberd_service |
external |
Check if the Jabberd service started properly on VCS. If not, MRA will fail. |
hocao |
| vcs |
mra_jid_different_than_userid_CSCvk75664 |
external |
This DS checks if VCS has hit CSCvk75664 where MRA login failed because the userID of the user trying to login is different than its JID |
hocao |
| vcs |
mra_nat_exprc_cscvb95283 |
external |
Check if Expr-C is being NATted to the same ip address as configured as static NAT address on Expr-E. |
hocao |
| vcs |
mra_no_device |
external |
Check that a device is configured on CUCM for the platform the MRA client is logging in with. |
kvancoil |
| vcs |
mra_not_matched_in_allow_list |
external |
Check if some request could not be forwarded because some entries are missing in the allow list. |
hocao |
| vcs |
mra_phone_reg_fail_digest_authentication |
external |
Checks if any phone registration failed because Digest Authentication is enabled on the phone security profile |
hocao |
| vcs |
mra_phone_register_ucm_set_as_domain |
external |
Check if a phone registration over MRA failed because the Unified CM FQDN is configured as domain on Expressway-C |
hocao |
| vcs |
mra_phoneservices_cucm_rfc2392_noncompliant |
external |
Check for occurrence of bug CSCuv65202 for phone services over MRA failing due to Content Length issue on the CUCM (certain versions). If we hit this bug, phone services fail for Jabber. |
stejanss |
| vcs |
mra_reverse_dns |
external |
Check for reverse DNS lookup failures as this causes MRA login to fail as of X8.8. |
vsidimak |
| vcs |
mra_round_robin_algorithm |
internal |
Check if VCS can find XCP service. |
hocao |
| vcs |
mra_sip_tcp_disabled |
external |
Check if phone registration failed via over MRA because protocol is not enabled. |
hocao |
| vcs |
mra_softphone_badrequest |
external |
Check if phone registration failed via over MRA because expressway failed to decode a message |
belhoest |
| vcs |
mra_sso_CSCvf37587 |
external |
Check if system is affected by CSCvf37587 which causes MRA login with SSO to fail. |
hocao |
| vcs |
mra_UCversion_compatibility_check |
external |
Check if Expressway-C version is compatible with versions of the IM&P and CUCM added. |
belhoest |
| vcs |
mra_xcp_checker |
internal |
Check if there is xcp issue on traversal zone between -C and -E. |
vsidimak |
| vcs |
mra_xmpp_cert_failed |
external |
Check if TLS connection for XMPP fails when reverse DNS lookup of Expr-E is not present in the certificate of Expr-E. |
kvancoil |
| vcs |
mra_xmpp_traversal_down |
external |
Check if XMPP connection for MRA from Expressway-C to Expressway-E on port 7400 fails. |
kvancoil |
| vcs |
vcs_cscvb43528 |
external |
Check if vcs is affected by CSCvb43528. |
kvancoil |
| vcs |
vcs_tls_timeout |
external |
Check if a TLS handshake timed out. |
hocao |