Hi everyone
Here is more info on my issue.
H.323 Phone is at FW 6.8.5.2 and I never reach the SCEP server to get certificated
We used 6.8.5.2 until Avaya told us that 6.8.5.3 was out recently which we have try on a live trouble shooting session with Avaya Engineer last week. But result is the same.
96x1-IPT-H323-R6_8_5_2U-033122 even try 96x1-IPT-H323-R6_8_5_3U-061422 as suggested by Avaya.
We even enable the debug and ssh to the phone and Avaya got in the phone thru my laptop and logged in with craft because it send a challenge then with WinSCP we downloaded the PCAP file
and send it to Avaya to analyze.
Here is the response we got after.
Our SME has check the PCAP trace and found that there might be issue on the DHCP process. You need to have scope 242 configured in the DHCP server. It is potentially a network issue. We need to start with billing process. If at the end, it is not network issue, we will not bill anything. However, if it is network issue, from this point, all time and material we spend on the case will be billed.
Well DHCP scope have been there for the past 7 years and never changed.
242 Avaya Option 242 MCIPADD= xxx.xxx.xxx.xx,MCPORT=1719,HTTPSRVR=xxx.xxx.xx.xx,VLANTEST=30
006 DNS Servers xxx.xxx.xxx.xx,xxx.xx.xx.xx
How can it be potentially a network issue. If nothing have changed.
What could on our network affect phone from not talking to SCEP server. Even mirroring the switch port of the phone with Wireshark we never see any attempt to reach any SCEP server IP
Here is our closed-circuit setup to test update
1. I have a port NON 802.1x
2. Plug a phone and in CRAFT menu Clear phone to factory
3. Upon reboot I stop the phone with * to program and setup to group 91 to use my 46xxsettings_91.txt, 96x1Hupgrade is set to update phone to 6.8.5.2 or 6.8.5.3 depend on testing . then we restart the phone . Here is what I get on the screen until I get the login
(* to Prog, VLID=0, waiting for LLDP, Restart, * to Prog, VL=66, HTTPSRVR, 96x1, 46xx91, slamon and all cert 200 ok, Download TAR and update process, restart, * to Prog, waiting LLDP, restarting, * to Prog, HTTPSRVR, 96x1, 46xx91, contacting call server. Login)
4. Log back in craft and restart phone again and does not get to SCEP server.
5. Moving the phone to a 802.1x port and still does not get anywhere.
Here is my 46xxsettings
and using the same 46xxsetting for a SIP phone it does get the certificates and with h.323 is does not.
########### 46xxsetting_91.txt ################
SET MCIPADD xxx.xx.xxx.xx
SET HTTPSRVR xxx.xx.xxx.xx
SET BRURI
SET DNSSRVR xxx.xx.xxx.xx,xxx.xx.xxx.xx,xxx.xx.xxx.xx
##
##################### Certificates #############################
##
SET TRUSTCERTS slamon-cert-chain2.pem.txt,MyCieIssuingCA-Private-1.pem.txt,MyCieIssuingCA-Private-2.pem.txt,MyCieIssuingCA-Private-3.pem.txt,MyCieRootCA.pem.txt,default.cacert.pem.txt,MyHost.tad.inet.pem.txt
SET MYCERTURL
SET MYCERTCN "$MACADDR"
SET MYCERTDN /C=CA/ST=QC/L=MTL/O=IFC/OU=AVAYA_IPPhone
SET MYCERTKEYLEN 2048
SET MYCERTRENEW 99
SET MYCERTWAIT 0
SET SERVER_CERT_RECHECK_HOURS 1
SET CERT_WARNING_DAYS 1
SET CMT_RENEWAL_OFFSET "-4"
##################### DEBUG Activation #########################
## SET PROCPSWD xxxxx
##################### SLA Mon setup ############################
##
SET SLMSTAT 1
SET SLMSRVR xxx.xx.xxx.xx
SET SLMCTRL 1
SET SLMPERF 1
SET SLMCAP 2
##
##################### 802.1x Setup ############################
##
## SET DOT1XSTAT 2
## SET DOT1X 1
## SET DOT1XEAPS TLS
## SET DOT1XWAIT 0
## SET DOT1XEAPTLSONLYWITHCERT 1
##
##################### SIP Config ###############################
##
##
SET ENABLE_PPM_SOURCED_SIPPROXYSRVR 1
SET SIPDOMAIN "sip.xxxx"
## SET SIP_CONTROLLER_LIST
SET SIP_CONTROLLER_LIST xxx.xx.xx.xx:5061;transport=tls
SET CONNECTION_REUSE 1
SET ENABLE_PPM 1
SET CONFIG_SERVER_SECURE_MODE 0
SET ENABLE_AVAYA_ENVIRONMENT 1
SET STMPSRVR xxx.xx.xx.xx,yyy.yy.yy.yy
SET DSTSTART 2SunMar2L
SET DSTSTOP 1SunNov2L
##
Daniel Audet
IT Technical Advisor Senior | Infrastructure, Evolution & Services|
Intact Financial Corporation
Montreal, Quebec, Canada