cisco onprem uc · stub
Troubleshooting Expressway business-to-business calls
Verified 2026-10-02 · 59 sources · tier 1–2
Also known as Expressway B2B call failures.
Stub. This topic has 59 sources and no published article. The sources below are everything recorded so far.
So far, no summary has been generated for this topic. The sources below are everything recorded so far.
See also
Related to
- DNS SRV and service discovery for SIP — Outbound B2B routing depends on NAPTR and SRV resolution per RFC 3263
- Expressway business-to-business calling — Concept topic for Expressway B2B calling; this topic covers failure modes only
- One-way and no-way audio diagnosis — Single-NIC static NAT reflection and firewall SIP inspection cause B2B media failures
- SIP TLS handshake failures on trunks — Mutual TLS failures on B2B; traversal and neighbor zones
- Setting up certificates on Cisco Expressway — TLS verify and client-auth EKU failures depend on certificate content
- Troubleshooting a down Expressway traversal zonestub — Traversal zone failures (wrong peer address and ACK loss) are one B2B symptom class
Troubleshoots
- Setting up business-to-business calling on Cisco Expressway — Symptom-driven counterpart to the B2B URI dialing build topic; configuration values cited here come from the same Cisco technote 213864
Sources
- 1When the ACK from Unified CM is not passed to Expressway-E, the cause given is a traversal client zone pointing at the wrong Expressway-E address: the public IP for a single-NIC Expressway-E, or the internal (typically LAN1) IP for a dual-NIC Expressway-E.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'ACK Message Received from CUCM Is Not Sent to VCS-E/Expressway-E' · Checked 2026-10-02
- 2The basic configuration guide warns that an Any alias search rule on Expressway-E can lead to denial of service.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > Traversal zone search rules note · Checked 2026-10-02
- 3The B2B technote configures the B2B traversal zone between Expressway-C (client) and Expressway-E (server) on port 7003, distinct from the port 7001 used by the UC traversal zone.Configure Business to Business Audio/Video Calls through Expressway · Configure > Traversal Zone section · Checked 2026-10-02
- 4When enabled, Call Policy is executed for all calls going through the Expressway, and can be defined by web-interface rules, an uploaded CPL script, or an external policy service.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Call Policy > Configuring Call Policy · Checked 2026-10-02
- 5If Call Policy is enabled but no policy is configured or uploaded, Expressway applies a default policy that allows all calls regardless of source or destination.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Call Policy > About Call Policy · Checked 2026-10-02
- 6Web-interface Call Policy rules are compared with the call top-down until one matches, and that rule's Allow or Reject action is applied; source and destination patterns accept regular expressions.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Configuring Call Policy Rules Using the Web Interface · Checked 2026-10-02
- 7With TLS verify enabled, a TLS handshake toward Unified CM fails with a 'no certificate returned' error when the Unified CM certificate lacks the client authentication attribute; the certificate must carry both server and client authentication.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'CUCM Certificate Must Have the Client Authentication Attribute Applied' · Checked 2026-10-02
- 8Unified CM dropping the TCP session on inbound B2B calls is caused by a mismatch between the Expressway-C neighbor zone destination port and the incoming port of the Unified CM SIP trunk security profile; MRA and B2B cannot share 5060/5061, so both sides must use the same custom port.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'CUCM drops TCP session on inbound calls' · Checked 2026-10-02
- 9If the Unified CM Organization Top Level Domain enterprise parameter is not set, inbound B2B calls can loop back to Expressway-C or fail with 404 Not Found because Unified CM routes the domain through SIP route patterns.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Top Level Domain Not Configured in CUCM' · Checked 2026-10-02
- 10For a TLS SIP trunk from Unified CM to Expressway-C, the X.509 subject name in the Unified CM SIP trunk security profile must match the Expressway-C certificate CN.Configure Business to Business Audio/Video Calls through Expressway · Configure > SIP Trunk Security Profile on CUCM · Checked 2026-10-02
- 11In a cluster, starting and stopping diagnostic logging and tcpdump applies to all peers, but markers apply only to the current peer and the log is downloaded only from the current peer.Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Configuring diagnostic logging > cluster notes · Checked 2026-10-02
- 12Diagnostic logging is run from Maintenance > Diagnostics > Diagnostic logging with an optional Take tcpdump while logging; the archive includes the logging snapshot, xconfig and xstatus dumps, certificate files and per-interface pcap files.Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Configuring diagnostic logging · Checked 2026-10-02
- 13Maintenance > Tools > Network utilities > DNS lookup can query All, A, AAAA, SRV or NAPTR records against the system default DNS servers or a custom server, and an SRV lookup tries service/protocol pairs including _sip._tcp, _sips._tcp, _h323ls._udp and _h323cs._tcp.Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Network utilities > DNS lookup · Checked 2026-10-02
- 14The basic configuration guide's DNS zone search rule (priority 150, source All zones, mode Alias pattern match with a regex, target the DNS zone) uses a negative-lookahead pattern so that aliases in the organisation's own SIP domains are never sent to the DNS zone.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > DNS zone search rule table · Checked 2026-10-02
- 15For outbound B2B, the DNS zone on Expressway-E performs a DNS SRV lookup for _sip or _sips derived from the domain portion of the dialled SIP URI.Configure Business to Business Audio/Video Calls through Expressway · Configure > DNS Zone on Expressway-E section · Checked 2026-10-02
- 16On a DNS zone, the TLS verify subject name is the name Expressway looks for in the destination server certificate, and it must be present in the SAN attribute.Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > TLS verify subject name · Checked 2026-10-02
- 17Cisco describes dual-NIC Expressway-E with static NAT as the recommended option over a single-NIC implementation that relies on NAT reflection.ASA NAT Configuration And Recommendations For The Expressway-E Dual Network Interfaces Implementation · Introduction / dual network interfaces recommendation · Checked 2026-10-02
- 18For SIP B2B over mTLS, Expressway-E acts as TLS client or TLS server depending on which side originates the session, so its certificate is presented in both roles.Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · Specific Affected Use Cases > SIP B2B over mTLS · Checked 2026-10-02
- 19FN74362 states X15.4 supports server-auth-only certificates on Expressway-E, X15.5 adds separate client and server certificates and an option to disable the EKU check, and Expressway-C and Expressway-E must be upgraded to matching versions.Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided · Workaround/Solution > fixed releases · Checked 2026-10-02
- 20Field notice FN74362 lists SIP B2B calls over mutual TLS as affected when the Expressway certificate is a public-CA certificate without the Client Authentication EKU.Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided · Problem Description / affected use cases · Checked 2026-10-02
- 21FN74362 workarounds before upgrading are: obtain combined server-and-client EKU certificates from a CA root that still issues them, renew existing combined-EKU certificates before the cut-off, or use a private internal CA (Expressway-C only).Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided · Workaround/Solution options 1 to 3 · Checked 2026-10-02
- 22Because a B2B partner validates Expressway-E as a TLS client on outbound calls, a server-auth-only Expressway-E certificate can make outbound B2B TLS calls fail at a partner whose system still enforces the client EKU, even after the local Expressway is upgraded.inferredPrepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · Specific Affected Use Cases > SIP B2B over mTLS; recommendation to exchange root information with peers · Checked 2026-10-02
- 23The Cisco EKU-sunset technote describes X15.5 adding a service parameter that lets administrators disable the Client Authentication EKU check, allowing Expressway to ignore the EKU presented by the remote peer.Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · X15.5 comprehensive solution section · Checked 2026-10-02
- 24When several search rules share the same priority, any matching target zones are queried simultaneously.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Search rules > search rule priority · Checked 2026-10-02
- 25The DNS zone Fallback transport protocol sets the transport for SIP calls when DNS NAPTR records and SIP URI parameters give no preferred transport; the X15.5 default is UDP (if enabled), while the basic configuration guide example sets TCP.Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Fallback transport protocol · Checked 2026-10-02
- 26Cisco recommends turning off SIP and H.323 protocol support (ALG or inspection) on firewalls carrying Expressway-E traffic because it is not needed and may interfere with Expressway's traversal.Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Firewall configuration recommendations · Checked 2026-10-02
- 27With the DNS zone setting Include address record Off (the default), Expressway does not query A and AAAA records when SRV/NAPTR lookups return nothing, and continues searching lower-priority zones.Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Include address record · Checked 2026-10-02
- 28In the recommended dual-NIC Expressway-E deployment, LAN1 and LAN2 must be in non-overlapping subnets, with static NAT on the outward-facing interface.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments · Dual NIC with static NAT section · Checked 2026-10-02
- 29If the internal firewall does not NAT traffic from Expressway-C, a static route toward that source must be created from LAN1 on Expressway-E, otherwise return traffic goes to the default gateway.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments · Dual NIC deployment > static routes note · Checked 2026-10-02
- 30On large Expressway-E systems, media demultiplexing uses six RTP/RTCP port pairs, ports 36000 to 36011 by default; small and medium systems use one pair, configurable under Configuration > Traversal > Ports with a restart.Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Media demultiplexing ports · Checked 2026-10-02
- 31The version-specific defects in technote 213863 (fixed in X8.6.1 and X8.7) should not apply to a supported X15 Expressway, so on current releases the configuration-class causes in that technote are the relevant ones.inferredTroubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem sections citing CSCuv11790, CSCuw85626 and CSCuw85715 · Checked 2026-10-02
- 32Maintenance > Tools > Locate tests whether Expressway can find an endpoint for a given alias within a set number of hops without actually placing a call.Cisco Expressway Administrator Guide (X15.5) - Maintenance · Tools > Locate · Checked 2026-10-02
- 33The default traversal media port range is 36000 to 59999, set on Expressway-C under Configuration > Local Zones > Traversal Subzone.Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Configuring traversal media ports / Traversal Subzone · Checked 2026-10-02
- 34The DNS zone option Modify DNS request routes outbound SIP calls to a manually specified SIP domain instead of the dialled domain and is primarily intended for Call Service Connect, so leaving it on a general B2B DNS zone sends every call to that one domain.Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Modify DNS request · Checked 2026-10-02
- 35When TLS verify mode is on for the Expressway-C neighbor zone to Unified CM, the configured peer address must match the CN or a SAN in the certificate the peer presents; the technote recommends an FQDN peer address in that case.Configure Business to Business Audio/Video Calls through Expressway · Configure > Neighbor Zone section, TLS verify mode note · Checked 2026-10-02
- 36Cisco's B2B configuration technote uses TCP port 6060 (non-secure) and TLS port 6061 (secure) for the Expressway-C neighbor zone to Unified CM, rather than 5060/5061, so B2B traffic does not collide with edge (MRA) traffic.Configure Business to Business Audio/Video Calls through Expressway · Configure > Neighbor Zone on Expressway-C and SIP Trunk on CUCM sections · Checked 2026-10-02
- 38A search rule with On successful match set to Stop prevents any further search rules being applied even if the alias is not found in that rule's target zone; Continue keeps applying remaining rules in priority order.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Configuring search rules > On successful match · Checked 2026-10-02
- 39Incoming aliases are compared against pre-search transforms in priority order and only one transform can be matched per search.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Pre-search transforms · Checked 2026-10-02
- 40RFC 3263 says a client SHOULD perform a NAPTR query only when no transport or port is specified and the target is not a numeric IP address; if no NAPTR records are found it constructs SRV queries.RFC 3263: Session Initiation Protocol (SIP): Locating SIP Servers · Section 4.1 · Checked 2026-10-02
- 41RFC 3263 specifies that when a SIP URI target is a domain name and a port is present, the client performs an A or AAAA lookup of the domain rather than SRV.RFC 3263: Session Initiation Protocol (SIP): Locating SIP Servers · Section 4.2 · Checked 2026-10-02
- 42Expressway applies all priority 1 search rules first, then priority 2, and so on.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Search rules > search rule priority · Checked 2026-10-02
- 43With a single-NIC Expressway-E using static NAT, media handled by the B2BUA must hairpin (reflect) through the external firewall to reach the private address, and not all firewalls allow this reflection.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments · Single NIC with static NAT section · Checked 2026-10-02
- 44The SDL error 'Ignoring large message. Only allow up to 5000 bytes. Resetting connection.' on B2B video calls is fixed by raising the Unified CM CallManager service parameter SIP Max Incoming Message Size from 5000 to 11000 bytes.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Error //SIP/SIPTcp/wait_SdlReadRsp: Ignoring large message' · Checked 2026-10-02
- 45Static NAT on Expressway-E needs the Advanced Networking option: the private IP goes in the IPv4 address field, IPv4 static NAT mode is set On, and the public IP goes in IPv4 static NAT address.Cisco Expressway Administrator Guide (X15.5) - Network and System Settings · Configuring IP settings > static NAT · Checked 2026-10-02
- 46With static NAT enabled on the outward interface, Expressway-E replaces references to that interface's (LAN2) address in the payload with the configured IPv4 static NAT address.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments · Dual NIC with static NAT section · Checked 2026-10-02
- 47For a TLS B2B path between Expressway-C and Unified CM, the Expressway-C server certificate or its issuing CA must be in the Unified CM trust store, and the CallManager certificate or its issuing CA must be in the Expressway-C trusted CA list.Configure Business to Business Audio/Video Calls through Expressway · Certificate requirements in the Configure section · Checked 2026-10-02
- 48Cisco's toll-fraud CPL examples reject calls from the gateway zone back out to the gateway (destination pattern 9.*), and calls from unauthenticated origins, with reject status 403.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Optional Configuration Tasks · Toll fraud prevention > Call Policy CPL examples · Checked 2026-10-02
- 49For toll-fraud prevention on Expressway-E, the guide pairs a Source All zones rule with a Source Any rule whose replace string is do-not-route-this-call, both with On successful match Stop.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Optional Configuration Tasks · Toll fraud prevention > search rules · Checked 2026-10-02
- 50Media stopping (one-way audio or buzzing) after another call server transfers a B2B call, caused by reuse of the originally negotiated crypto lines, is fixed in VCS/Expressway X8.6.1 and later (CSCuv11790).Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Media Streams Stop If Another Call Server Transfers the Call' · Checked 2026-10-02
- 51The B2B technote instructs creating a transform on Expressway-C that removes the port from the URI in INVITEs received from Unified CM so the DNS zone can route on the domain.Configure Business to Business Audio/Video Calls through Expressway · Create a Transform on Expressway-C which Removes the Port from the URI Received in the Invite from CUCM · Checked 2026-10-02
- 52Pre-search transforms are applied before any Call Policy or User Policy and before any searches take place.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Pre-search transforms · Checked 2026-10-02
- 53All Expressway traversal clients must authenticate with the Expressway-E, even if the Expressway-E does not use device authentication for endpoints.Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Authentication and NTP section · Checked 2026-10-02
- 54Traversal zones default to UDP 6001 for H.323 and TCP 7001 for SIP, each incrementing by one for every additional traversal zone.Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Ports used by traversal zones · Checked 2026-10-02
- 55B2B calls fail with a 'Call license limit reached' error naming concurrent traversal call licenses when the Expressway has exhausted its traversal (rich media) licences.Configure Business to Business Audio/Video Calls through Expressway · Rich Media Licensing section · Checked 2026-10-02
- 56The basic configuration guide sets Calls to unknown IP addresses to Indirect on Expressway-C and Direct on Expressway-E.Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > IP address routing settings · Checked 2026-10-02
- 57The Calls to unknown IP addresses setting has three values: Direct (call the IP without querying neighbours), Indirect (query neighbours on receiving a call to an unknown IP), and Off (only IPs of systems registered to that Expressway).Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Dial plan configuration > Calls to unknown IP addresses · Checked 2026-10-02
- 58For URI dialing via DNS, Expressway sends a NAPTR query first; if NAPTR yields nothing it sends SRV queries for _sips._tcp, _sip._tcp and _sip._udp in that order, and then A/AAAA queries if no SRV records exist.Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · URI dialing > URI resolution process using DNS · Checked 2026-10-02
- 59When Unified CM sends a B2B request URI with an appended port (for example user@domain:5060), Expressway queries only A/AAAA records and does not perform the SRV lookup, so the call can fail to reach the partner; the fix is a transform that strips the port.Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'VCS is unable to properly resolve FQDNs or fails to query SRV records' · Checked 2026-10-02
Documents
tier 1 standards and regulators
RFC 3263: Session Initiation Protocol (SIP): Locating SIP Servers
tier 2 current vendor documentation
ASA NAT Configuration And Recommendations For The Expressway-E Dual Network Interfaces Implementation
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Maintenance
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Network and System Settings
tier 2 current vendor documentation
Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors
tier 2 current vendor documentation
Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments
tier 2 current vendor documentation
Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Optional Configuration Tasks
tier 2 current vendor documentation
Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration
tier 2 current vendor documentation
Configure Business to Business Audio/Video Calls through Expressway
tier 2 current vendor documentation
Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided
tier 2 current vendor documentation
Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates
tier 2 current vendor documentation
Troubleshoot Most Common Issues for Business to Business Calls Through Expressway
Cite this page
APA
WarmTransfer. (2026, October 2). Troubleshooting Expressway business-to-business calls. WarmTransfer. https://warmtransfer.net/knowledge/expressway-b2b-troubleshooting
BibTeX
@misc{warmtransfer-expressway-b2b-troubleshooting,
title = {Troubleshooting Expressway business-to-business calls},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/expressway-b2b-troubleshooting},
note = {Verified 2026-10-02}
}