<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Office Communications Server 2007 R2 Enterprise Deployment &#8211; Part 5</title>
	<atom:link href="http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Thu, 09 Feb 2012 12:04:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: luke</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-13393</link>
		<dc:creator>luke</dc:creator>
		<pubDate>Wed, 18 Jan 2012 10:22:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-13393</guid>
		<description>After I corrected the Certificate on the server the following Error pops up when I try to logon. 
 
TL_ERROR(TF_CONNECTION) [0]0D44.0D30::01/18/2012-10:21:20.668.00000161 (SIPStack,SIPAdminLog::TraceConnectionRecord:1224.idx(157))$$begin_record 
LogType: connection 
Severity: error 
Text: The client connection is not allowed on the internal edge of the Access Edge Server 
Peer-IP: 172.16.28.56:1524 
Transport: TLS 
Result-Code: 0xc3e93d6b SIPPROXY_E_CONNECTION_INTERNAL_FROM_CLIENT 
$$end_record 
 </description>
		<content:encoded><![CDATA[<p>After I corrected the Certificate on the server the following Error pops up when I try to logon. </p>
<p>TL_ERROR(TF_CONNECTION) [0]0D44.0D30::01/18/2012-10:21:20.668.00000161 (SIPStack,SIPAdminLog::TraceConnectionRecord:1224.idx(157))$$begin_record<br />
LogType: connection<br />
Severity: error<br />
Text: The client connection is not allowed on the internal edge of the Access Edge Server<br />
Peer-IP: 172.16.28.56:1524<br />
Transport: TLS<br />
Result-Code: 0xc3e93d6b SIPPROXY_E_CONNECTION_INTERNAL_FROM_CLIENT<br />
$$end_record</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: luke</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-13392</link>
		<dc:creator>luke</dc:creator>
		<pubDate>Wed, 18 Jan 2012 10:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-13392</guid>
		<description>Services have been restarted and all seems in order. 
 
However no matter what I do I cannot logon onto the OC EA server. The error I am getting in OCSLogger is as follows: 
 
L_ERROR(TF_CONNECTION) [0]0E2C.0E24::01/18/2012-09:04:25.856.00000160 (SIPStack,SIPAdminLog::TraceConnectionRecord:1224.idx(157))$$begin_record 
LogType: connection 
Severity: error 
Text: The connection was closed before TLS negotiation completed. Did the remote peer accept our certificate? 
Local-IP: 172.16.28.56:5061 
Peer-IP: 172.16.28.56:1503 
Connection-ID: 0x1000 
Transport: TLS 
$$end_record 
 
I can succesfully ping the FQDN of the Internal Interface of the OC AE Server. The internal Interface is on the same IP Subnet as our Internal Network.  
 
Any support in this regard would be much appreciated. </description>
		<content:encoded><![CDATA[<p>Services have been restarted and all seems in order. </p>
<p>However no matter what I do I cannot logon onto the OC EA server. The error I am getting in OCSLogger is as follows: </p>
<p>L_ERROR(TF_CONNECTION) [0]0E2C.0E24::01/18/2012-09:04:25.856.00000160 (SIPStack,SIPAdminLog::TraceConnectionRecord:1224.idx(157))$$begin_record<br />
LogType: connection<br />
Severity: error<br />
Text: The connection was closed before TLS negotiation completed. Did the remote peer accept our certificate?<br />
Local-IP: 172.16.28.56:5061<br />
Peer-IP: 172.16.28.56:1503<br />
Connection-ID: 0&#215;1000<br />
Transport: TLS<br />
$$end_record </p>
<p>I can succesfully ping the FQDN of the Internal Interface of the OC AE Server. The internal Interface is on the same IP Subnet as our Internal Network.  </p>
<p>Any support in this regard would be much appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-13391</link>
		<dc:creator>Luke</dc:creator>
		<pubDate>Wed, 18 Jan 2012 10:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-13391</guid>
		<description>Guys I know its been a while since anybody has posted here but I am desperately looking for some assistance. We have been running a OCS 2007 R2 (Just one Server running OCS2007 R2 Standard) for some time now. All seems to be working great. Now the time has come to deploy Access Edge Server. I dont need any of the Fancy stuff. All I want is to give users the ability to logon onto OC outsite the network just like they would at the office. 
 
I have configured a server with two NICs. One for DMZ and the other for Internal. I received a Public CA that I have assigned to the External Interface and then generated a new Local CA using our Enterprise CA server. This I assigned to the Internal Interface. ( I have used the same Private SA to generate the certificate for the OC SE server).  </description>
		<content:encoded><![CDATA[<p>Guys I know its been a while since anybody has posted here but I am desperately looking for some assistance. We have been running a OCS 2007 R2 (Just one Server running OCS2007 R2 Standard) for some time now. All seems to be working great. Now the time has come to deploy Access Edge Server. I dont need any of the Fancy stuff. All I want is to give users the ability to logon onto OC outsite the network just like they would at the office. </p>
<p>I have configured a server with two NICs. One for DMZ and the other for Internal. I received a Public CA that I have assigned to the External Interface and then generated a new Local CA using our Enterprise CA server. This I assigned to the Internal Interface. ( I have used the same Private SA to generate the certificate for the OC SE server).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francois</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-12695</link>
		<dc:creator>Francois</dc:creator>
		<pubDate>Mon, 16 May 2011 11:27:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-12695</guid>
		<description>hello, please i am having this error with my edge server isnt working. it keeps giving me this error.

Server could not register for notifications for configuration changes for a class from the WMI Provider.

Class: MSFT_SIPProxySetting
Cause: This could happen in some instances due to insufficient permissions or because the server is unable to contact the Active Directory (or SQL back-end).
Resolution:
Please make sure you have sufficient privileges and this computer can talk to the Active Directory (or SQL back-end).

please help out</description>
		<content:encoded><![CDATA[<p>hello, please i am having this error with my edge server isnt working. it keeps giving me this error.</p>
<p>Server could not register for notifications for configuration changes for a class from the WMI Provider.</p>
<p>Class: MSFT_SIPProxySetting<br />
Cause: This could happen in some instances due to insufficient permissions or because the server is unable to contact the Active Directory (or SQL back-end).<br />
Resolution:<br />
Please make sure you have sufficient privileges and this computer can talk to the Active Directory (or SQL back-end).</p>
<p>please help out</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saneesh</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-10398</link>
		<dc:creator>Saneesh</dc:creator>
		<pubDate>Wed, 25 Aug 2010 06:50:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-10398</guid>
		<description>Hi Elan, 
 
Can you please tell me the features available with this setup. 
 
Thanks 
Saneesh </description>
		<content:encoded><![CDATA[<p>Hi Elan, </p>
<p>Can you please tell me the features available with this setup. </p>
<p>Thanks<br />
Saneesh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marc</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-9811</link>
		<dc:creator>marc</dc:creator>
		<pubDate>Mon, 22 Mar 2010 22:24:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-9811</guid>
		<description>Hi, having a strange issue with webconf part of edge server. Seems I can ping av and sip on the external nic (4 IPs assigned to the nic), but only the ip for webconf does not reply. I believe this is causing live meeting logins to fail as authentication comes up but never finshes. Also, desktop sharing features are working externally, so I&#039;m not exactly sure whats going on since all the other IPs I can ping and get a reply from. Have tried reassigning cert as well as reboot. still same issue.  </description>
		<content:encoded><![CDATA[<p>Hi, having a strange issue with webconf part of edge server. Seems I can ping av and sip on the external nic (4 IPs assigned to the nic), but only the ip for webconf does not reply. I believe this is causing live meeting logins to fail as authentication comes up but never finshes. Also, desktop sharing features are working externally, so I&#039;m not exactly sure whats going on since all the other IPs I can ping and get a reply from. Have tried reassigning cert as well as reboot. still same issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-9581</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Mon, 25 Jan 2010 22:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-9581</guid>
		<description>Hello Elan, Scenario:  External authenticated users can IM to internal, pic, and federated partners.  I can communicate with full AV from internal to federated partners but AV between internal and external OC R2 users always fails with &quot;Remote end ending the audio session&quot;  thus terminating the attempted AV call.  It seems that possibly a port problem.  This leads me to the question about the internal interface open port requirements.  

When opening the ports on the internal interface on the edge server the guidelines say to open 443, 5062, and 3478 to ANY IP address. 

Is this to any internal Pool or FE, or literally to ANY internal client address as well as server on the corp intranet.

Many thanks in advance.........Mike</description>
		<content:encoded><![CDATA[<p>Hello Elan, Scenario:  External authenticated users can IM to internal, pic, and federated partners.  I can communicate with full AV from internal to federated partners but AV between internal and external OC R2 users always fails with &#8220;Remote end ending the audio session&#8221;  thus terminating the attempted AV call.  It seems that possibly a port problem.  This leads me to the question about the internal interface open port requirements.  </p>
<p>When opening the ports on the internal interface on the edge server the guidelines say to open 443, 5062, and 3478 to ANY IP address. </p>
<p>Is this to any internal Pool or FE, or literally to ANY internal client address as well as server on the corp intranet.</p>
<p>Many thanks in advance&#8230;&#8230;&#8230;Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: golfer kuno</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-9352</link>
		<dc:creator>golfer kuno</dc:creator>
		<pubDate>Tue, 22 Dec 2009 16:01:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-9352</guid>
		<description>I believe this next info could help to resolve this issue... 
 
I created a new host/alias for the OCS server under the new zone newdomain.com and pointed the _sipinternaltls for this newdomain to the new host/alias. I can see see (using WireShark) that the client is getting the SRV record from the DNS server, so that is at least good to know. Now it seems (only my guess) that the issue is now pointing to the certificate. The message below came for the Event Log. 
 
Communicator could not connect securely to server ocs.newdomain.com because the certificate presented by the server did not match the expected hostname (ocs.newdomain.com). 
  
 Resolution: 
 If you are using manual configuration with an IP address or a NetBIOS shortened server name, a fully-qualified server name will be required.  If you are using automatic configuration, the network administrator will need to make sure that the published server name in DNS is supported by the server certificate. 
 
Your thoughts please. Thank you. </description>
		<content:encoded><![CDATA[<p>I believe this next info could help to resolve this issue&#8230; </p>
<p>I created a new host/alias for the OCS server under the new zone newdomain.com and pointed the _sipinternaltls for this newdomain to the new host/alias. I can see see (using WireShark) that the client is getting the SRV record from the DNS server, so that is at least good to know. Now it seems (only my guess) that the issue is now pointing to the certificate. The message below came for the Event Log. </p>
<p>Communicator could not connect securely to server ocs.newdomain.com because the certificate presented by the server did not match the expected hostname (ocs.newdomain.com). </p>
<p> Resolution:<br />
 If you are using manual configuration with an IP address or a NetBIOS shortened server name, a fully-qualified server name will be required.  If you are using automatic configuration, the network administrator will need to make sure that the published server name in DNS is supported by the server certificate. </p>
<p>Your thoughts please. Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: golfer kuno</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-9351</link>
		<dc:creator>golfer kuno</dc:creator>
		<pubDate>Tue, 22 Dec 2009 15:35:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-9351</guid>
		<description>This is the event log from test PC... 
 
Communicator was unable to locate the login server.  The DNS SRV record that exist for domain newdomain.com point to an invalid server ocs.olddomain.com which is not trusted to provide support for the domain because the server&#039;s domain is not an exact match. 
  
 Resolution: 
 The network administrator will need to double-check the DNS SRV record configuration to make sure that the SRV record for the domain points to a server name that conforms to the DNS naming convention in the server deployment guide. 
 
Does it mean that I cannot point the new SIP address newdomain.com to ocs.olddomain.com because the SIP address are different? I thought we can have multiple SIP addresses using a single OCS server? 
 
Can I just create an alias for the OCS server and use the newdomain.com as its domain name? Your thoughts? Thank you. </description>
		<content:encoded><![CDATA[<p>This is the event log from test PC&#8230; </p>
<p>Communicator was unable to locate the login server.  The DNS SRV record that exist for domain newdomain.com point to an invalid server ocs.olddomain.com which is not trusted to provide support for the domain because the server&#039;s domain is not an exact match. </p>
<p> Resolution:<br />
 The network administrator will need to double-check the DNS SRV record configuration to make sure that the SRV record for the domain points to a server name that conforms to the DNS naming convention in the server deployment guide. </p>
<p>Does it mean that I cannot point the new SIP address newdomain.com to ocs.olddomain.com because the SIP address are different? I thought we can have multiple SIP addresses using a single OCS server? </p>
<p>Can I just create an alias for the OCS server and use the newdomain.com as its domain name? Your thoughts? Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/01/20/office-communications-server-2007-r2-enterprise-deployment-part-5/comment-page-3/#comment-9335</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 22 Dec 2009 01:06:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=815#comment-9335</guid>
		<description>That does seem odd. Have you tried to load up netmon or wireshark to see where the breakdown in the communication lies?  And the guidance I wrote above is for the Edge.  For the FE you&#039;ll still have to add something sip.newdomain.com as a SAN name. </description>
		<content:encoded><![CDATA[<p>That does seem odd. Have you tried to load up netmon or wireshark to see where the breakdown in the communication lies?  And the guidance I wrote above is for the Edge.  For the FE you&#039;ll still have to add something sip.newdomain.com as a SAN name.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

