Configuration · guide

Setting up Mobile and Remote Access on Cisco Expressway

Cisco Expressway

Verified 2026-09-24 · 83 sources · tier 1–2

For Collaboration administrators configuring Cisco Expressway-C and Expressway-E for off-premises Jabber and phone registration to Unified CM..

Cisco Mobile and Remote Access (MRA) provides registration, call control, provisioning, messaging, and presence to off-premises endpoints such as Cisco Jabber without requiring a corporate VPN 61​62. The newest dedicated MRA deployment guide published by Cisco is the X15.2 edition 32.

Before you start

Basic MRA requires at least Cisco Expressway X8.1.1, Cisco Unified Communications Manager (Unified CM) 10.0, and Cisco Unified IM and Presence Service 10.0 35​63. The AXL Web Service must be running on the Unified CM publisher before discovery begins 2. Ensure Expressway-C and Expressway-E have separate IP addresses and do not share a NAT address 37. Third-party network load balancers are not supported between MRA clients and Expressway-E 38​64. Cisco Jabber Video for TelePresence is not supported over MRA 65.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

How is your Expressway-E attached to the network?
Do remote clients need IM and Presence Service over MRA?
Will you use ICE passthrough to optimize call media?
What Expressway release will both nodes run?

Four questions. One permanent page you can send to your manager.

Step 1 Prepare network addressing and Unified CM prerequisites

Do

Verify that the Unified CM publisher has the AXL Web Service enabled 2. Verify that both Expressway-C and Expressway-E have distinct IP addresses without sharing a NAT address 37. Do not place a third-party load balancer between off-premises clients and Expressway-E 38.

Verify

Suggested check: Confirm in serviceability that the AXL Web Service displays a status of running on the publisher node.

Rollback

Suggested rollback: Disable any services enabled for discovery that are no longer needed.

Step 2 Configure Expressway-E network interfaces

Two interfaces (internal LAN1 and external LAN2)

Do

Navigate to System > Network interfaces > IP on Expressway-E, set Use dual network interfaces to Yes, and set External LAN interface to LAN2 17. Dual interfaces are supported only on Expressway-E and not on Expressway-C 15. Behind static NAT the interface keeps its private IPv4 address and IPv4 static NAT mode is set On with IPv4 static NAT address set to the public address as seen outside the NAT 49. Restart Expressway-E to apply the network interface changes 36.

Verify

With dual interfaces traversal clients should be configured to use the internally facing address of the Expressway-E 52. Cisco recommends a dual-NIC Expressway-E and in that design the Expressway-E address given to Expressway-C is an FQDN resolving to the internal interface IP 16.

Rollback

Set Use dual network interfaces to No, clear static NAT fields, and restart the system 17​36.

One interface behind a static NAT

Do

Behind static NAT the interface keeps its private IPv4 address and IPv4 static NAT mode is set On with IPv4 static NAT address set to the public address as seen outside the NAT 49. Changes to Expressway IP interface settings require a restart to take effect 36. Cisco does not recommend a single-NIC Expressway-E with static NAT; if used the Expressway-E address must be an FQDN resolving to the public IP and the firewall must support NAT reflection 46.

Verify

Ensure the Expressway-E FQDN resolves to the public IP address and that Expressway-C can reach this address through firewall NAT reflection 46.

Rollback

Clear the static NAT fields, then restart 49​36. Suggested rollback: Remove the NAT reflection rule.

Step 3 Publish DNS records

Yes, Jabber IM and presence traverse MRA

Do

In public DNS, publish a _collab-edge._tls.<domain> SRV record on port 8443 pointing to each Expressway-E target 8​66. SRV records must use the standard format carrying priority, weight, port, and target 48​67. Ensure the Expressway-E FQDN resolves publicly 22. Create forward and reverse DNS records for each Expressway-E, which is required when IM and Presence Service is used over MRA 23. In internal DNS, _cisco-uds._tcp.<domain> may optionally be created, but do not publish it to external DNS 6​5. Split DNS with a single common domain is recommended 47​68.

Verify

Verify externally that _collab-edge._tls.<domain> resolves and that _cisco-uds._tcp.<domain> does not resolve 5. Run SRV lookups on Expressway under Maintenance > Tools > Network utilities > DNS lookup 13.

Rollback

Delete the public _collab-edge._tls.<domain> SRV records to disable client MRA discovery 8.

No, voice and video registration only

Do

In public DNS, publish a _collab-edge._tls.<domain> SRV record on port 8443 targeting each Expressway-E host 8​66. Use the standard SRV format specifying priority, weight, port, and target 48​67. Ensure the Expressway-E FQDN resolves in public DNS 22. In internal DNS, _cisco-uds._tcp.<domain> may optionally be created, but do not expose it externally 6​5. Deploying a single domain using split DNS is recommended 47​68.

Verify

Confirm that public queries for _collab-edge._tls.<domain> succeed and that external queries for _cisco-uds._tcp.<domain> fail 5. Validate SRV resolution using Maintenance > Tools > Network utilities > DNS lookup on Expressway 13.

Rollback

Remove the _collab-edge._tls.<domain> SRV records from external DNS 8.

Step 4 Open firewall ports

Yes, enable ICE passthrough and TURN

Do

Permit outbound traffic from Expressway-C to Expressway-E on TCP 7001, TCP 2222, TCP 7400, and UDP 2776-2777 (or UDP 36000-36011 on Large systems) 40​69. Permit inbound traffic from the internet to Expressway-E on TCP 8443, TCP 5061, and TCP 5222 42​70. For ICE passthrough and TURN, permit inbound internet traffic to Expressway-E on UDP 3478 (3478-3483 on Large systems) for TURN control and UDP 24000-29999 for TURN media 53. Permit media traffic between off-premises endpoints and Expressway-E on UDP 36000-59999 71.

Verify

Suggested check: Validate that external probes to designated edge listening ports on Expressway-E succeed, and confirm the UC traversal zone establishes.

Rollback

Suggested rollback: Remove the firewall access rules allowing external traffic for TURN control and media, along with the traversal rules.

No, leave media on the Expressway traversal path

Do

Permit outbound connections from Expressway-C to Expressway-E on TCP 7001, TCP 2222, TCP 7400, and UDP 2776-2777 (or UDP 36000-36011 on Large systems) 40​69. Permit inbound connections from the internet to Expressway-E on TCP 8443, TCP 5061, and TCP 5222 42​70. Allow media between off-premises endpoints and Expressway-E on UDP 36000-59999 71.

Verify

Suggested check: Verify that port connectivity from Expressway-C to Expressway-E for traversal and tunneling is open and unblocked.

Rollback

Suggested rollback: Revert the firewall rule entries created for traversal and external client access.

Step 5 Issue and install certificates

X15.5 or later on both nodes

Do

Expressway validates certificates against the Subject Alternative Name (SAN) rather than the Common Name 44. Include Unified CM phone security profile names and the cluster name in the Expressway-C certificate SAN 21. In the Expressway-E certificate SAN, include Unified CM registration domains, as well as the base domain or collab-edge.<domain> to prevent Jabber certificate acceptance prompts 3​25. Cisco TAC states that Expressway-E is the only MRA server requiring a public-CA-signed certificate 24. Expressway-C must trust Unified CM, IM and Presence, and Expressway-E; Expressway-E must trust Expressway-C 4. On X15.5 or later, upload client and server certificates separately under Maintenance > Security 58​72. Use an Expressway-C client certificate with both client and server EKU, ideally issued by an internal CA, while its server certificate may be public and server-EKU-only 60. Leave the CLI command xconfiguration SIP TLS Certificate ExtendedKeyUsage Checking Mode set to ON unless troubleshooting 59​73.

Verify

Inspect diagnostic logs via Maintenance > Diagnostics > Diagnostic logging to verify that both certificates load properly 10. Status > Unified Communications should report no certificate validation errors 56.

Rollback

Suggested rollback: Re-upload the prior certificates from local backup files to restore previous trust stores.

Earlier than X15.5

Do

Expressway validates identities using the Subject Alternative Name rather than the Common Name 44. Ensure the Expressway-C certificate SAN contains Unified CM phone security profile names and the cluster name 21. On Expressway-E, include the Unified CM registration domains and the lookup base domain or collab-edge.<domain> in the SAN 3​25. Cisco TAC indicates only Expressway-E requires a public CA signature 24. Ensure mutual trust: Expressway-C trusts Expressway-E, Unified CM, and IM and Presence; Expressway-E trusts Expressway-C 4. Field notice FN74362 lists the UC traversal zone (where Expressway-C presents a Client Authentication EKU) and MRA Onboarding cloud connections as affected by public CAs dropping Client Authentication EKU on releases X14.0.0 through X15.3.2 18. The X15.2 MRA guide requires both Expressway-C and Expressway-E certificates to include the Client Authentication extension 7. FN74362 offers three workarounds: switch to a CA that still issues combined-EKU certificates, renew existing combined-EKU certificates before the sunset, or move to a private PKI (Expressway-C only) 74. FN74362 gives X15.4 as an interim fix allowing a ServerAuth-only certificate upload on Expressway-E and X15.5 as the solution separating client and server certificates, with Expressway-E and -C on the same version; a private CA for Expressway-C is a workaround 19. Note that self-signed Unified CM certificates prevent running TLS verify together with secure registrations 45.

Verify

Decode the installed certificates to confirm the presence of both Server and Client Authentication EKUs 7​75. Verify under Status > Unified Communications that certificate warnings are clear 56.

Rollback

Suggested rollback: Restore previously saved certificates in the Expressway administrative interface.

Step 6 Enable Unified Communications mode and domains

Yes, Jabber IM and presence traverse MRA

Do

On both Expressway-C and Expressway-E, browse to Configuration > Unified Communications > Configuration and set Unified Communications mode to Mobile and remote access 20​76. Under Configuration > Domains, add each MRA domain and enable SIP registrations and provisioning on Unified CM, and enable IM and Presence Service 14.

Verify

Check Status > Unified Communications on both nodes to confirm there are no configuration errors 56.

Rollback

Set Unified Communications mode back to Off or its previous mode and uncheck the domain services 20.

No, voice and video registration only

Do

Navigate to Configuration > Unified Communications > Configuration on Expressway-C and Expressway-E and set Unified Communications mode to Mobile and remote access 20​76. Under Configuration > Domains, add each MRA domain and select SIP registrations and provisioning on Unified CM only 14.

Verify

Confirm that Status > Unified Communications displays no configuration errors 56.

Rollback

Revert Unified Communications mode to its previous setting and remove the domain configuration 20.

Step 7 Discover Unified Communications servers on Expressway-C

Yes, Jabber IM and presence traverse MRA

Do

On Expressway-C, navigate to Configuration > Unified Communications > Unified CM servers, add the publisher node using a user account assigned the Standard AXL API Access role, select the desired TLS verify mode, and click Refresh servers 12​77. Then navigate to Configuration > Unified Communications > IM and Presence Service nodes and add the IM and Presence publisher using a Standard AXL API Access account 11​77.

Verify

Verify that subscriber nodes appear automatically and that auto-generated neighbor zones to Unified CM are created with TLS verify set to On if TLS verify was selected during discovery 1. Confirm that Status > Unified Communications shows no missing services 56.

Rollback

Delete the discovered Unified CM and IM and Presence publisher server entries; this automatically removes the associated neighbor zones 1.

No, voice and video registration only

Do

On Expressway-C, go to Configuration > Unified Communications > Unified CM servers, enter the publisher node with an account possessing the Standard AXL API Access role and your chosen TLS verify setting, and click Refresh servers 12​77.

Verify

Confirm that all Unified CM nodes are discovered and that auto-generated neighbor zones exist with TLS verify matching the discovery configuration 1. Check Status > Unified Communications for a healthy status 56.

Rollback

Delete the Unified CM publisher entry from the Unified CM servers page, which removes the auto-generated zones 1.

Step 8 Build the Unified Communications traversal zone

Two interfaces (internal LAN1 and external LAN2)

Do

Traversal credentials are created in the Expressway-E local authentication database and entered as connection credentials on Expressway-C; the zone authentication policy is Do not check credentials 50. Under Configuration > Zones > Zones on both nodes, create a zone of type Unified Communications traversal 54​78. In the UC traversal zone Expressway-E uses SIP port 7001 by default with TLS verify subject name set to the name in the Expressway-C certificate, and Expressway-C uses the same port with Peer 1 address set to the Expressway-E FQDN 51. With dual interfaces traversal clients should be configured to use the internally facing address of the Expressway-E 52.

Verify

Verify that the traversal zone shows an active status on both nodes and that Status > Unified Communications displays no errors 56.

Rollback

Delete the Unified Communications traversal zone from both Expressway-C and Expressway-E 54.

One interface behind a static NAT

Do

Create traversal credentials in the local authentication database of Expressway-E 50. On both Expressways, navigate to Configuration > Zones > Zones and create a zone of type Unified Communications traversal 54​78. On Expressway-E, configure SIP port 7001, set TLS verify subject name to match the Expressway-C certificate name, and set Authentication policy to Do not check credentials 50​51. On Expressway-C, set SIP port 7001, supply the traversal credentials, and configure Peer 1 address to the Expressway-E FQDN that resolves to the external public NAT address 50​51​46.

Verify

Ensure the traversal zone reaches the active state on both systems 56. If connection fails, verify firewall NAT reflection rules 46.

Rollback

Delete the traversal zone on both Expressway-C and Expressway-E 54.

Step 9 Configure Unified CM trust and review bandwidth

Do

Install the CA certificate that signed the Expressway-C certificate into CallManager-trust and Tomcat-trust on Unified CM 55. If IM and Presence is used, install the CA into cup-xmpp-trust and Tomcat-trust on IM and Presence 55. Review the default 384 kbps video bit rate in the Unified CM region configuration and the 384 kbps default call bandwidth on Expressway-C, adjusting them if needed to support video calls over MRA 57.

Verify

Suggested check: Verify that server certificates in Unified CM show the uploaded CA in CallManager-trust and Tomcat-trust stores without validation warnings.

Rollback

Suggested rollback: Delete the Expressway-C CA certificates from CallManager-trust, Tomcat-trust, and cup-xmpp-trust stores, and return region bit rates to their default values.

Step 10 Configure ICE passthrough

Yes, enable ICE passthrough and TURN

Do

Verify prerequisites: Expressway X12.5 or later, Unified CM 11.5 or later, Unified CM in SIP OAuth or mixed mode, and endpoints using TLS-encrypted phone security profiles 28​79. On Expressway-E, set TURN services to On and generate TURN client credentials 27​80. On Expressway-C, navigate to the UC traversal zone SIP pane, set ICE Passthrough support to On, and set ICE support to Off 26. On Expressway-C, also set ICE Passthrough support to On under each Unified CM server entry 26. In Unified CM Common Phone Profile, set ICE to Enabled with Default Candidate Type set to Host and Server Reflexive Address Enabled, and enter the TURN server host names and credentials 30. ICE passthrough allows MRA endpoints to pass media directly between endpoints while non-ICE endpoints continue using the Expressway traversal path 29​81.

Verify

Check Status > ICE Passthrough metrics on Expressway-C, and confirm in Status > Calls > History that active calls display ICE call types other than none, such as host_to_host or relay_to_relay 31.

Rollback

Set ICE Passthrough support to Off on the Expressway-C traversal zone and Unified CM server configs, disable ICE in the Unified CM Common Phone Profile, and turn TURN services Off on Expressway-E 26​30​27.

No, leave media on the Expressway traversal path

Do

Leave ICE passthrough settings in their default disabled state on Expressway-C and do not enable TURN services on Expressway-E 29.

Verify

Review Status > Calls > History to ensure that MRA calls display an ICE passthrough call type of none 31.

Rollback

Suggested rollback: No action required.

Step 11 Validate registration and verify end to end

Do

Inspect Status > Alarms, followed by Status > Unified Communications on both Expressway nodes 56. Run the Cisco Collaboration Solutions Analyzer CollabEdge validator to simulate a remote Jabber sign-in 9. Connect an off-premises Jabber client or supported IP phone over an external internet connection 62. The MRA troubleshooting chapter lists unreliable NTP synchronisation on the Expressways as a cause of 403 Forbidden responses 39. To troubleshoot further issues, collect logs under Maintenance > Diagnostics > Diagnostic logging and analyse them in Collaboration Solutions Analyzer 10.

Verify

Under Status > Unified Communications, click View provisioning sessions to confirm the active client session is listed 43. In Unified CM Administration, check the device registration status to confirm the endpoint is registered and shows the Expressway-C IP address 43.

Rollback

Suggested rollback: Sign out test clients and collect final diagnostic logs to clear testing traces.

See also

See also Expressway and Mobile and Remote Access and DNS SRV and service discovery for SIP.

Applicability

Applies to: Cisco Expressway, Cisco Unified Communications Manager, and IETF DNS. Deployments: on-premises, dedicated instance, and any. Sources checked 2026-09-24. The minimum version requirements for MRA are Expressway X8.1.1, Unified CM 10.0, and IM and Presence Service 10.0 35. Activation-code onboarding of IP phones requires at least Expressway X12.5.1, Unified CM 12.5(1)SU1, and phone firmware 12.5(1)SR3 82. Separate client and server certificate stores require Expressway X15.5 or later 58​72. Field notice FN74362 lists Expressway X14.0.0 through X14.3.7 and X15.0.0 through X15.3.2 as affected by public CAs sunsetting the Client Authentication EKU 83.

What remains uncertain

Whether any specific option key is needed to enable dual network interfaces on particular hardware appliances is not covered by the sources below. Whether TCP port 5222 can remain closed on external firewalls in deployments without IM and Presence Service is not covered by the sources below.

See also

Builds on

Related to

Sources

  1. 1
    Discovery makes Expressway-C generate non-configurable neighbor zones to Unified CM whose TLS verify mode is On when discovery used TLS verify.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · Secure Communications Configuration, automatically generated zones · Checked 2026-09-24
  2. 2
    The AXL Web Service must be enabled on the Unified CM publisher node for Expressway-C to discover Unified CM for MRA.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites, Unified CM requirements · Checked 2026-09-24
  3. 3
    If the SRV lookup base domain is absent from the Expressway-E certificate SAN (as example.com or collab-edge.example.com) Jabber users must accept the certificate on first connection.
    Configure and Troubleshoot Collaboration Edge (MRA) Certificates · Expressway-E certificate SAN section · Checked 2026-09-24
  4. 4
    Expressway-C must trust the Unified CM and IM and Presence certificates and the Expressway-E certificate while Expressway-E must trust the Expressway-C certificate.
  5. 5
    The _cisco-uds SRV records must not resolve outside the internal network or Jabber will not start MRA negotiation through the Expressway-E.
  6. 6
    Cisco recommends internal _cisco-uds._tcp.<domain> SRV records but they have not been a requirement since X12.5.
  7. 7
    The X15.2 MRA guide requires both Expressway-C and Expressway-E certificates to include the Client Authentication extension.
  8. 8
    Public DNS must publish _collab-edge._tls.<domain> SRV records on port 8443 whose targets are the Expressway-E systems.
  9. 9
    Cisco's Collaboration Solutions Analyzer CollabEdge validator simulates a Jabber sign-in to validate an MRA deployment.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting, Collaboration Solutions Analyzer · Checked 2026-09-24
  10. 10
    Expressway diagnostic logging is run from Maintenance > Diagnostics > Diagnostic logging and the resulting logs can be analysed in Collaboration Solutions Analyzer.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting, diagnostic logging · Checked 2026-09-24
  11. 11
    IM and Presence nodes are discovered on Expressway-C at Configuration > Unified Communications > IM and Presence Service nodes with a Standard AXL API Access account.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration Task Flow, discover IM and Presence Service nodes · Checked 2026-09-24
  12. 12
    Expressway-C discovers Unified CM at Configuration > Unified Communications > Unified CM servers using an account with the Standard AXL API Access role and a chosen TLS verify mode, then Refresh servers discovers the other nodes.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration Task Flow, discover Unified CM servers · Checked 2026-09-24
  13. 13
    Maintenance > Tools > Network utilities > DNS lookup on Expressway can run SRV lookups for _collab-edge._tls and _cisco-uds._tcp.
  14. 14
    At Configuration > Domains each MRA domain enables SIP registrations and provisioning on Unified CM and where used IM and Presence Service.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration Task Flow, configure domains · Checked 2026-09-24
  15. 15
    Dual network interfaces are supported only on Expressway-E and not on Expressway-C.
    Cisco Expressway Administrator Guide (X15.4) - Network and System Settings · Network and System Settings, Configuring Dual Network Interfaces · Checked 2026-09-24
  16. 17
    Dual interfaces are enabled at System > Network interfaces > IP by setting Use dual network interfaces to Yes and External LAN interface to LAN2.
    Cisco Expressway Administrator Guide (X15.4) - Network and System Settings · Network and System Settings, Configuring Dual Network Interfaces · Checked 2026-09-24
  17. 18
    Field notice FN74362 lists the UC traversal zone (where Expressway-C presents a Client Authentication EKU) and MRA Onboarding cloud connections as affected by public CAs dropping Client Authentication EKU on releases X14.0.0 through X15.3.2.
  18. 19
    FN74362 gives X15.4 as an interim fix allowing a ServerAuth-only certificate upload on Expressway-E and X15.5 as the solution separating client and server certificates, with Expressway-E and -C on the same version; a private CA for Expressway-C is a workaround.
  19. 20
    MRA is enabled on both Expressway-C and Expressway-E at Configuration > Unified Communications > Configuration by setting Unified Communications mode to Mobile and remote access.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration Task Flow, enable MRA · Checked 2026-09-24
  20. 21
    The Expressway-C certificate SAN must include Unified CM phone security profile names used for MRA and the cluster name on clustered systems.
    Cisco Expressway Certificate Creation and Use Deployment Guide (X15.5) - Server Certificate Requirements for Unified Communications · Server Certificate Requirements for Unified Communications, SAN requirements table · Checked 2026-09-24
  21. 22
    The Expressway-E FQDN built from its System host name and Domain name must be resolvable in public DNS.
  22. 23
    Forward and reverse DNS entries are required for each Expressway-E system when IM and Presence Service is used over MRA (XCP TLS).
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · DNS Records, Expressway-E forward and reverse entries · Checked 2026-09-24
  23. 24
    Cisco TAC states the Expressway-E is the only MRA server that really needs a public-CA-signed certificate so clients and 7800/8800 phones connect without manual certificate acceptance.
    Configure and Troubleshoot Collaboration Edge (MRA) Certificates · Certificate signing, Expressway-E · Checked 2026-09-24
  24. 25
    For MRA the Expressway-E certificate SAN must include the Unified CM registrations domains; XMPP federation domains and chat node aliases are added where those features are used.
    Cisco Expressway Certificate Creation and Use Deployment Guide (X15.5) - Server Certificate Requirements for Unified Communications · Server Certificate Requirements for Unified Communications, SAN requirements table · Checked 2026-09-24
  25. 26
    On Expressway-C ICE Passthrough support is set On and ICE support Off in the UC traversal zone SIP pane and ICE Passthrough support is set On per Unified CM server lookup.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization Task Flow, Expressway-C · Checked 2026-09-24
  26. 27
    Expressway-E TURN services are turned On with default port and realm and media range 24000-29999 and TURN client credentials are created in its local authentication database.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization Task Flow, Expressway-E TURN · Checked 2026-09-24
  27. 28
    ICE passthrough needs Expressway X12.5 or later and Unified CM 11.5 or later with Unified CM in SIP OAuth or mixed mode and endpoints on a TLS-encrypted phone security profile.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · Prerequisites for ICE Media Path Optimization · Checked 2026-09-24
  28. 29
    ICE passthrough lets MRA-registered endpoints send media directly to each other bypassing the Expressway servers after first flowing through Expressway-E and -C, with non-ICE endpoints keeping the traversal path.
  29. 30
    In the Unified CM Common Phone Profile ICE is Enabled with Default Candidate Type Host and Server Reflexive Address Enabled plus the TURN server host names and TURN username and password.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization Task Flow, Unified CM Common Phone Profile · Checked 2026-09-24
  30. 31
    ICE passthrough is verified at Status > ICE Passthrough metrics and in Status > Calls > History where the ICE passthrough call type shows values such as none or host_to_host or relay_to_relay.
  31. 32
    The newest Mobile and Remote Access deployment guide on Cisco's Expressway configuration-guide listing is the X15.2 edition; no X15.3 X15.4 or X15.5 edition is listed.
    Cisco Expressway Series - Configuration Guides · Configuration Guides listing, Mobile and Remote Access deployment guide entries · Checked 2026-09-24
  32. 33
    The MRA X15.2 requirements chapter lists UDP 36002-59999 as the inbound media range to Expressway-E.disputed
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · Firewall and port requirements, inbound to Expressway-E · Checked 2026-09-24
  33. 34
    The IP port usage guide lists UDP 36000-59999 as the RTP/RTCP media range from off-premises endpoints to Expressway-E.disputed
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access, Table 2, RTP/RTCP media row · Checked 2026-09-24
  34. 35
    MRA requires at least Expressway X8.1.1 with Unified CM 10.0 and IM and Presence Service 10.0.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites, supported versions table · Checked 2026-09-24
  35. 36
    Changes to Expressway IP interface settings require a restart to take effect.
    Cisco Expressway Administrator Guide (X15.4) - Network and System Settings · Network and System Settings, IP configuration · Checked 2026-09-24
  36. 37
    Expressway-C and Expressway-E must have separate IP addresses and must not share a NAT address because the firewall cannot tell them apart.
  37. 38
    Third-party network load balancers between MRA clients and Expressway-E are not supported.
  38. 39
    The MRA troubleshooting chapter lists unreliable NTP synchronisation on the Expressways as a cause of 403 Forbidden responses.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting, 403 Forbidden responses · Checked 2026-09-24
  39. 40
    Expressway-C connects outbound to Expressway-E on TCP 7001 for SIP traversal and TCP 2222 for the HTTPS SSH tunnel and TCP 7400 for XMPP and UDP 2776-2777 (or 36000-36011 on Large systems) for traversal media.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access, Table 3 (Expressway-C to Expressway-E) · Checked 2026-09-24
  40. 41
    Expressway-C reaches Unified CM and IM and Presence on ports including 5060 5061 8443 and 6970-6972.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access, Table 4 (Expressway-C to on-premises infrastructure) · Checked 2026-09-24
  41. 42
    From the internet to Expressway-E MRA uses TCP 8443 for UDS/provisioning and TCP 5061 for SIP TLS and TCP 5222 for XMPP to IM and Presence.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access, Table 2 (off-premises endpoints to Expressway-E) · Checked 2026-09-24
  42. 43
    MRA device sessions are listed via View provisioning sessions under Status > Unified Communications and devices registered through Expressway show the Expressway-C IP address in Unified CM.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting, registration checks · Checked 2026-09-24
  43. 44
    Expressway validates received certificates using the Subject Alternative Name attribute and not the Common Name.
  44. 45
    With self-signed Unified CM certificates TLS verify and secure device registrations cannot both be used; Cisco's remedy is CA-signed Unified CM certificates.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · Certificate requirements, self-signed Unified CM note · Checked 2026-09-24
  45. 46
    Cisco does not recommend a single-NIC Expressway-E with static NAT; if used the Expressway-E address must be an FQDN resolving to the public IP and the firewall must support NAT reflection.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · Expressway-E deployment, single NIC with static NAT · Checked 2026-09-24
  46. 47
    The MRA guide describes a single common domain served by separate internal and external DNS servers (split DNS) as aligning with Jabber service discovery.
  47. 48
    A DNS SRV record has the form _Service._Proto.Name TTL Class SRV Priority Weight Port Target and clients try the lowest-numbered priority first then use weight among equal priorities.
    RFC 2782: A DNS RR for specifying the location of services (DNS SRV) · The format of the SRV RR; Priority and Weight field definitions · Checked 2026-09-24
  48. 49
    Behind static NAT the interface keeps its private IPv4 address and IPv4 static NAT mode is set On with IPv4 static NAT address set to the public address as seen outside the NAT.
    Cisco Expressway Administrator Guide (X15.4) - Network and System Settings · Network and System Settings, static NAT configuration · Checked 2026-09-24
  49. 50
    Traversal credentials are created in the Expressway-E local authentication database and entered as connection credentials on Expressway-C; the zone authentication policy is Do not check credentials.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · Configure Secure Traversal Zone, credentials and authentication policy · Checked 2026-09-24
  50. 51
    In the UC traversal zone Expressway-E uses SIP port 7001 by default with TLS verify subject name set to the name in the Expressway-C certificate, and Expressway-C uses the same port with Peer 1 address set to the Expressway-E FQDN.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · Configure Secure Traversal Zone, settings table · Checked 2026-09-24
  51. 52
    With dual interfaces traversal clients should be configured to use the internally facing address of the Expressway-E.
    Cisco Expressway Administrator Guide (X15.4) - Network and System Settings · Network and System Settings, dual interface deployment guidance · Checked 2026-09-24
  52. 53
    When TURN is used Expressway-E receives TURN control on UDP 3478 (3478-3483 on Large systems) and TURN media on UDP 24000-29999 from the internet.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access, Table 2, TURN control and TURN media rows · Checked 2026-09-24
  53. 54
    The MRA traversal zone is created at Configuration > Zones > Zones with type Unified Communications traversal which sets SIP TLS with TLS verify On and media encryption Force encrypted.
  54. 55
    Unified CM must trust the Expressway-C certificate in CallManager-trust and Tomcat-trust and IM and Presence must trust it in cup-xmpp-trust and Tomcat-trust.
  55. 56
    Status > Unified Communications on Expressway-C and Expressway-E shows MRA configuration errors and missing services and Status > Alarms should be checked first.
  56. 57
    The Unified CM default region caps video session bit rate at 384 kbps and the Expressway-C default call bandwidth is also 384 kbps which Cisco warns may be too low for MRA video.
  57. 58
    From X15.5 Maintenance > Security has separate client certificate and server certificate sections and a server certificate can be uploaded as the client certificate.
    Navigate Client EKU Sunset with Expressway x15.5 · Technote 225693, X15.5 certificate changes · Checked 2026-09-24
  58. 59
    X15.5 adds the CLI xconfiguration SIP TLS Certificate ExtendedKeyUsage Checking Mode which defaults to ON and checks that the TLS initiator's certificate has a client EKU.
    Navigate Client EKU Sunset with Expressway x15.5 · Technote 225693, EKU checking · Checked 2026-09-24
  59. 60
    For the UC zone on X15.5 Cisco TAC recommends an Expressway-C client certificate carrying both client and server EKU ideally from an internal CA while its server certificate may be a public server-only-EKU certificate.
    Navigate Client EKU Sunset with Expressway x15.5 · Technote 225693, recommended configuration for UC zone · Checked 2026-09-24
  60. 61
    Cisco Mobile and Remote Access (MRA) is part of the Cisco Collaboration Edge Architecture. It lets Unified CM provide registration, call control, provisioning, messaging and presence to endpoints such as Cisco Jabber when they are outside the enterprise network.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Overview · MRA Overview chapter, opening section · Checked 2026-09-24
  61. 62
    MRA lets Jabber clients communicate without connecting to the corporate network over a VPN.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Overview · MRA Overview chapter, Jabber client connectivity section · Checked 2026-09-24
  62. 63
    The minimum Unified CM version for basic MRA is 10.0.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites chapter, Unified Communications requirements, version table · Checked 2026-09-24
  63. 64
    Cisco does not support third-party network load balancers between MRA clients and Expressway-E.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites chapter, unsupported features and limitations · Checked 2026-09-24
  64. 65
    Cisco Jabber Video for TelePresence does not work with MRA.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Overview · MRA Overview chapter, client support note · Checked 2026-09-24
  65. 66
    Remote endpoints find Expressway-E through a public DNS SRV record named _collab-edge._tls.<domain>.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites chapter, DNS records section, public DNS table · Checked 2026-09-24
  66. 67
    An SRV record's owner name has the form _Service._Proto.Name, and the record carries priority, weight, port and target fields.
    RFC 2782: A DNS RR for specifying the location of services (DNS SRV) · The format of the SRV RR · Checked 2026-09-24
  67. 68
    Cisco recommends a single domain with split DNS as the ideal MRA configuration.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites chapter, DNS records section · Checked 2026-09-24
  68. 69
    From Expressway-C to Expressway-E, MRA uses TCP 7001 for SIP signaling, TCP 2222 for the SSH tunnels, TCP 7400 for XMPP, and UDP 2776-2777 for traversal media (UDP 36000-36011 on large systems).
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access chapter, Table 3 Connections Between Expressway-C and Expressway-E · Checked 2026-09-24
  69. 70
    Off-premises MRA endpoints reach Expressway-E on TLS 5061 for SIP, TLS 8443 for HTTPS/UDS and TCP 5222 for XMPP.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access chapter, Table 2 Connections Between Off-premises Endpoints and the Expressway-E · Checked 2026-09-24
  70. 71
    The port guide lists UDP 36000-59999 for RTP/RTCP media between off-premises endpoints and Expressway-E.
    Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access · Mobile and Remote Access chapter, Table 2 Connections Between Off-premises Endpoints and the Expressway-E · Checked 2026-09-24
  71. 72
    Expressway X15.5 has separate server and client certificate stores. On upgrade from X15.4, existing server certificates are copied into the client store.
    Navigate Client EKU Sunset with Expressway x15.5 · Navigate Client EKU Sunset with Expressway x15.5, background / feature overview · Checked 2026-09-24
  72. 73
    X15.5 adds the CLI setting xconfiguration SIP TLS Certificate ExtendedKeyUsage Checking Mode, which is ON by default. When OFF, inbound SIP TLS stops checking for the client EKU but still checks for the server EKU.
    Navigate Client EKU Sunset with Expressway x15.5 · Navigate Client EKU Sunset with Expressway x15.5, CLI configuration section · Checked 2026-09-24
  73. 74
    FN74362 offers three workarounds: switch to a CA that still issues combined-EKU certificates, renew existing combined-EKU certificates before the sunset, or move to a private PKI (Expressway-C only).
  74. 75
    FN74362 says public CAs stop issuing certificates that combine Server and Client Authentication EKUs from May 2026. Expressway mTLS connections expect both EKUs.
  75. 76
    MRA is enabled by setting Unified Communications mode to Mobile and Remote Access on both Expressway-C and Expressway-E.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration chapter, enabling Unified Communications mode · Checked 2026-09-24
  76. 77
    On Expressway-C the administrator adds the publisher nodes of Unified CM, IM and Presence Service and Unity Connection. Expressway then discovers the subscriber nodes when Refresh Servers is run.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration chapter, discovering internal UC servers · Checked 2026-09-24
  77. 78
    Expressway-C and Expressway-E are linked for MRA by a traversal zone of type Unified Communications traversal, with TLS and media encryption.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration · MRA Configuration chapter, creating the traversal zone · Checked 2026-09-24
  78. 79
    ICE passthrough requires the internal leg between Expressway-C and Unified CM to be encrypted. Unified CM must be in a secure mode, either SIP OAuth or mixed mode.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization chapter, limitations / prerequisites · Checked 2026-09-24
  79. 80
    ICE over MRA needs Expressway-E configured as a TURN server to supply relay candidates.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization chapter, TURN server configuration · Checked 2026-09-24
  80. 81
    ICE Media Path Optimization lets MRA-registered endpoints send media directly to each other, bypassing the WAN and the Expressway servers.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization · ICE Media Path Optimization chapter, overview · Checked 2026-09-24
  81. 82
    Activation-code onboarding of phones over MRA needs Expressway X12.5.1, Unified CM 12.5(1)SU1 and IP phone firmware 12.5(1)SR3, or later.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - Onboarding MRA Devices · Onboarding MRA Devices chapter, prerequisites for activation code onboarding · Checked 2026-09-24
  82. 83
    Field notice FN74362 lists Expressway X14.0.0 through X14.3.7 and X15.0.0 through X15.3.2 as affected by public CAs sunsetting the Client Authentication EKU.

Documents

tier 1 standards and regulators

RFC 2782: A DNS RR for specifying the location of services (DNS SRV)

IETF · 2000-02-01 · accessed 2026-09-24

tier 1 standards and regulators

RFC 2782: A DNS RR for specifying the location of services (DNS SRV)

RFC Editor / IETF · 2000-02-01 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.4) - Network and System Settings

Cisco Systems · 2026-02-09 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Expressway IP Port Usage Configuration Guide (Includes X14.3 and X15.0 releases) - Mobile and Remote Access

Cisco Systems · 2024-01-11 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Expressway Series - Configuration Guides

Cisco Systems · 2026-09-24 · accessed 2026-09-24

tier 2 current vendor documentation

Configure and Troubleshoot Collaboration Edge (MRA) Certificates

Cisco Systems · 2023-06-22 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Configuration

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Overview

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - Onboarding MRA Devices

Cisco Systems · 2024-10-15 · accessed 2026-09-24

tier 2 current vendor documentation

Navigate Client EKU Sunset with Expressway x15.5

Cisco Systems · 2026-04-15 · accessed 2026-09-24

Cite this page

APA

WarmTransfer. (2026, September 24). Setting up Mobile and Remote Access on Cisco Expressway. WarmTransfer. https://warmtransfer.net/guides/expressway-mra-setup

BibTeX

@misc{warmtransfer-expressway-mra-setup,
  title  = {Setting up Mobile and Remote Access on Cisco Expressway},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/expressway-mra-setup},
  note   = {Verified 2026-09-24}
}