cisco onprem uc · stub

Troubleshooting Expressway business-to-business calls

Verified 2026-10-02 · 59 sources · tier 1–2

Also known as Expressway B2B call failures.

Stub. This topic has 59 sources and no published article. The sources below are everything recorded so far.

So far, no summary has been generated for this topic. The sources below are everything recorded so far.

See also

Related to

Troubleshoots

Sources

  1. 1
    When the ACK from Unified CM is not passed to Expressway-E, the cause given is a traversal client zone pointing at the wrong Expressway-E address: the public IP for a single-NIC Expressway-E, or the internal (typically LAN1) IP for a dual-NIC Expressway-E.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'ACK Message Received from CUCM Is Not Sent to VCS-E/Expressway-E' · Checked 2026-10-02
  2. 2
    The basic configuration guide warns that an Any alias search rule on Expressway-E can lead to denial of service.
    Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > Traversal zone search rules note · Checked 2026-10-02
  3. 3
    The B2B technote configures the B2B traversal zone between Expressway-C (client) and Expressway-E (server) on port 7003, distinct from the port 7001 used by the UC traversal zone.
    Configure Business to Business Audio/Video Calls through Expressway · Configure > Traversal Zone section · Checked 2026-10-02
  4. 4
    When enabled, Call Policy is executed for all calls going through the Expressway, and can be defined by web-interface rules, an uploaded CPL script, or an external policy service.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Call Policy > Configuring Call Policy · Checked 2026-10-02
  5. 5
    If Call Policy is enabled but no policy is configured or uploaded, Expressway applies a default policy that allows all calls regardless of source or destination.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Call Policy > About Call Policy · Checked 2026-10-02
  6. 6
    Web-interface Call Policy rules are compared with the call top-down until one matches, and that rule's Allow or Reject action is applied; source and destination patterns accept regular expressions.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Configuring Call Policy Rules Using the Web Interface · Checked 2026-10-02
  7. 7
    With TLS verify enabled, a TLS handshake toward Unified CM fails with a 'no certificate returned' error when the Unified CM certificate lacks the client authentication attribute; the certificate must carry both server and client authentication.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'CUCM Certificate Must Have the Client Authentication Attribute Applied' · Checked 2026-10-02
  8. 8
    Unified CM dropping the TCP session on inbound B2B calls is caused by a mismatch between the Expressway-C neighbor zone destination port and the incoming port of the Unified CM SIP trunk security profile; MRA and B2B cannot share 5060/5061, so both sides must use the same custom port.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'CUCM drops TCP session on inbound calls' · Checked 2026-10-02
  9. 9
    If the Unified CM Organization Top Level Domain enterprise parameter is not set, inbound B2B calls can loop back to Expressway-C or fail with 404 Not Found because Unified CM routes the domain through SIP route patterns.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Top Level Domain Not Configured in CUCM' · Checked 2026-10-02
  10. 10
    For a TLS SIP trunk from Unified CM to Expressway-C, the X.509 subject name in the Unified CM SIP trunk security profile must match the Expressway-C certificate CN.
    Configure Business to Business Audio/Video Calls through Expressway · Configure > SIP Trunk Security Profile on CUCM · Checked 2026-10-02
  11. 11
    In a cluster, starting and stopping diagnostic logging and tcpdump applies to all peers, but markers apply only to the current peer and the log is downloaded only from the current peer.
    Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Configuring diagnostic logging > cluster notes · Checked 2026-10-02
  12. 12
    Diagnostic logging is run from Maintenance > Diagnostics > Diagnostic logging with an optional Take tcpdump while logging; the archive includes the logging snapshot, xconfig and xstatus dumps, certificate files and per-interface pcap files.
    Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Configuring diagnostic logging · Checked 2026-10-02
  13. 13
    Maintenance > Tools > Network utilities > DNS lookup can query All, A, AAAA, SRV or NAPTR records against the system default DNS servers or a custom server, and an SRV lookup tries service/protocol pairs including _sip._tcp, _sips._tcp, _h323ls._udp and _h323cs._tcp.
    Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting · Network utilities > DNS lookup · Checked 2026-10-02
  14. 14
    The basic configuration guide's DNS zone search rule (priority 150, source All zones, mode Alias pattern match with a regex, target the DNS zone) uses a negative-lookahead pattern so that aliases in the organisation's own SIP domains are never sent to the DNS zone.
    Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > DNS zone search rule table · Checked 2026-10-02
  15. 15
    For outbound B2B, the DNS zone on Expressway-E performs a DNS SRV lookup for _sip or _sips derived from the domain portion of the dialled SIP URI.
    Configure Business to Business Audio/Video Calls through Expressway · Configure > DNS Zone on Expressway-E section · Checked 2026-10-02
  16. 16
    On a DNS zone, the TLS verify subject name is the name Expressway looks for in the destination server certificate, and it must be present in the SAN attribute.
    Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > TLS verify subject name · Checked 2026-10-02
  17. 18
    For SIP B2B over mTLS, Expressway-E acts as TLS client or TLS server depending on which side originates the session, so its certificate is presented in both roles.
    Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · Specific Affected Use Cases > SIP B2B over mTLS · Checked 2026-10-02
  18. 19
    FN74362 states X15.4 supports server-auth-only certificates on Expressway-E, X15.5 adds separate client and server certificates and an option to disable the EKU check, and Expressway-C and Expressway-E must be upgraded to matching versions.
  19. 20
    Field notice FN74362 lists SIP B2B calls over mutual TLS as affected when the Expressway certificate is a public-CA certificate without the Client Authentication EKU.
  20. 21
    FN74362 workarounds before upgrading are: obtain combined server-and-client EKU certificates from a CA root that still issues them, renew existing combined-EKU certificates before the cut-off, or use a private internal CA (Expressway-C only).
  21. 22
    Because a B2B partner validates Expressway-E as a TLS client on outbound calls, a server-auth-only Expressway-E certificate can make outbound B2B TLS calls fail at a partner whose system still enforces the client EKU, even after the local Expressway is upgraded.inferred
    Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · Specific Affected Use Cases > SIP B2B over mTLS; recommendation to exchange root information with peers · Checked 2026-10-02
  22. 23
    The Cisco EKU-sunset technote describes X15.5 adding a service parameter that lets administrators disable the Client Authentication EKU check, allowing Expressway to ignore the EKU presented by the remote peer.
    Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates · X15.5 comprehensive solution section · Checked 2026-10-02
  23. 24
    When several search rules share the same priority, any matching target zones are queried simultaneously.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Search rules > search rule priority · Checked 2026-10-02
  24. 25
    The DNS zone Fallback transport protocol sets the transport for SIP calls when DNS NAPTR records and SIP URI parameters give no preferred transport; the X15.5 default is UDP (if enabled), while the basic configuration guide example sets TCP.
    Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Fallback transport protocol · Checked 2026-10-02
  25. 26
    Cisco recommends turning off SIP and H.323 protocol support (ALG or inspection) on firewalls carrying Expressway-E traffic because it is not needed and may interfere with Expressway's traversal.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Firewall configuration recommendations · Checked 2026-10-02
  26. 27
    With the DNS zone setting Include address record Off (the default), Expressway does not query A and AAAA records when SRV/NAPTR lookups return nothing, and continues searching lower-priority zones.
    Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Include address record · Checked 2026-10-02
  27. 28
    In the recommended dual-NIC Expressway-E deployment, LAN1 and LAN2 must be in non-overlapping subnets, with static NAT on the outward-facing interface.
  28. 29
    If the internal firewall does not NAT traffic from Expressway-C, a static route toward that source must be created from LAN1 on Expressway-E, otherwise return traffic goes to the default gateway.
  29. 30
    On large Expressway-E systems, media demultiplexing uses six RTP/RTCP port pairs, ports 36000 to 36011 by default; small and medium systems use one pair, configurable under Configuration > Traversal > Ports with a restart.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Media demultiplexing ports · Checked 2026-10-02
  30. 31
    The version-specific defects in technote 213863 (fixed in X8.6.1 and X8.7) should not apply to a supported X15 Expressway, so on current releases the configuration-class causes in that technote are the relevant ones.inferred
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem sections citing CSCuv11790, CSCuw85626 and CSCuw85715 · Checked 2026-10-02
  31. 32
    Maintenance > Tools > Locate tests whether Expressway can find an endpoint for a given alias within a set number of hops without actually placing a call.
    Cisco Expressway Administrator Guide (X15.5) - Maintenance · Tools > Locate · Checked 2026-10-02
  32. 33
    The default traversal media port range is 36000 to 59999, set on Expressway-C under Configuration > Local Zones > Traversal Subzone.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Configuring traversal media ports / Traversal Subzone · Checked 2026-10-02
  33. 34
    The DNS zone option Modify DNS request routes outbound SIP calls to a manually specified SIP domain instead of the dialled domain and is primarily intended for Call Service Connect, so leaving it on a general B2B DNS zone sends every call to that one domain.
    Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors · Configuring DNS zones > Modify DNS request · Checked 2026-10-02
  34. 35
    When TLS verify mode is on for the Expressway-C neighbor zone to Unified CM, the configured peer address must match the CN or a SAN in the certificate the peer presents; the technote recommends an FQDN peer address in that case.
    Configure Business to Business Audio/Video Calls through Expressway · Configure > Neighbor Zone section, TLS verify mode note · Checked 2026-10-02
  35. 36
    Cisco's B2B configuration technote uses TCP port 6060 (non-secure) and TLS port 6061 (secure) for the Expressway-C neighbor zone to Unified CM, rather than 5060/5061, so B2B traffic does not collide with edge (MRA) traffic.
    Configure Business to Business Audio/Video Calls through Expressway · Configure > Neighbor Zone on Expressway-C and SIP Trunk on CUCM sections · Checked 2026-10-02
  36. 37
    Cisco warns not to use a shared address for Expressway-E and Expressway-C because the firewall cannot distinguish between them.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Advanced Networking / static NAT section · Checked 2026-10-02
  37. 38
    A search rule with On successful match set to Stop prevents any further search rules being applied even if the alias is not found in that rule's target zone; Continue keeps applying remaining rules in priority order.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Configuring search rules > On successful match · Checked 2026-10-02
  38. 40
    RFC 3263 says a client SHOULD perform a NAPTR query only when no transport or port is specified and the target is not a numeric IP address; if no NAPTR records are found it constructs SRV queries.
  39. 41
    RFC 3263 specifies that when a SIP URI target is a domain name and a port is present, the client performs an A or AAAA lookup of the domain rather than SRV.
  40. 42
    Expressway applies all priority 1 search rules first, then priority 2, and so on.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Search rules > search rule priority · Checked 2026-10-02
  41. 43
    With a single-NIC Expressway-E using static NAT, media handled by the B2BUA must hairpin (reflect) through the external firewall to reach the private address, and not all firewalls allow this reflection.
  42. 44
    The SDL error 'Ignoring large message. Only allow up to 5000 bytes. Resetting connection.' on B2B video calls is fixed by raising the Unified CM CallManager service parameter SIP Max Incoming Message Size from 5000 to 11000 bytes.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Error //SIP/SIPTcp/wait_SdlReadRsp: Ignoring large message' · Checked 2026-10-02
  43. 45
    Static NAT on Expressway-E needs the Advanced Networking option: the private IP goes in the IPv4 address field, IPv4 static NAT mode is set On, and the public IP goes in IPv4 static NAT address.
    Cisco Expressway Administrator Guide (X15.5) - Network and System Settings · Configuring IP settings > static NAT · Checked 2026-10-02
  44. 46
    With static NAT enabled on the outward interface, Expressway-E replaces references to that interface's (LAN2) address in the payload with the configured IPv4 static NAT address.
  45. 47
    For a TLS B2B path between Expressway-C and Unified CM, the Expressway-C server certificate or its issuing CA must be in the Unified CM trust store, and the CallManager certificate or its issuing CA must be in the Expressway-C trusted CA list.
    Configure Business to Business Audio/Video Calls through Expressway · Certificate requirements in the Configure section · Checked 2026-10-02
  46. 48
    Cisco's toll-fraud CPL examples reject calls from the gateway zone back out to the gateway (destination pattern 9.*), and calls from unauthenticated origins, with reject status 403.
    Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Optional Configuration Tasks · Toll fraud prevention > Call Policy CPL examples · Checked 2026-10-02
  47. 49
    For toll-fraud prevention on Expressway-E, the guide pairs a Source All zones rule with a Source Any rule whose replace string is do-not-route-this-call, both with On successful match Stop.
  48. 50
    Media stopping (one-way audio or buzzing) after another call server transfers a B2B call, caused by reuse of the originally negotiated crypto lines, is fixed in VCS/Expressway X8.6.1 and later (CSCuv11790).
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'Media Streams Stop If Another Call Server Transfers the Call' · Checked 2026-10-02
  49. 51
    The B2B technote instructs creating a transform on Expressway-C that removes the port from the URI in INVITEs received from Unified CM so the DNS zone can route on the domain.
    Configure Business to Business Audio/Video Calls through Expressway · Create a Transform on Expressway-C which Removes the Port from the URI Received in the Invite from CUCM · Checked 2026-10-02
  50. 52
    Pre-search transforms are applied before any Call Policy or User Policy and before any searches take place.
  51. 53
    All Expressway traversal clients must authenticate with the Expressway-E, even if the Expressway-E does not use device authentication for endpoints.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Authentication and NTP section · Checked 2026-10-02
  52. 54
    Traversal zones default to UDP 6001 for H.323 and TCP 7001 for SIP, each incrementing by one for every additional traversal zone.
    Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal · Ports used by traversal zones · Checked 2026-10-02
  53. 55
    B2B calls fail with a 'Call license limit reached' error naming concurrent traversal call licenses when the Expressway has exhausted its traversal (rich media) licences.
    Configure Business to Business Audio/Video Calls through Expressway · Rich Media Licensing section · Checked 2026-10-02
  54. 56
    The basic configuration guide sets Calls to unknown IP addresses to Indirect on Expressway-C and Direct on Expressway-E.
    Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration · Routing configuration > IP address routing settings · Checked 2026-10-02
  55. 57
    The Calls to unknown IP addresses setting has three values: Direct (call the IP without querying neighbours), Indirect (query neighbours on receiving a call to an unknown IP), and Off (only IPs of systems registered to that Expressway).
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · Dial plan configuration > Calls to unknown IP addresses · Checked 2026-10-02
  56. 58
    For URI dialing via DNS, Expressway sends a NAPTR query first; if NAPTR yields nothing it sends SRV queries for _sips._tcp, _sip._tcp and _sip._udp in that order, and then A/AAAA queries if no SRV records exist.
    Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing · URI dialing > URI resolution process using DNS · Checked 2026-10-02
  57. 59
    When Unified CM sends a B2B request URI with an appended port (for example user@domain:5060), Expressway queries only A/AAAA records and does not perform the SRV lookup, so the call can fail to reach the partner; the fix is a transform that strips the port.
    Troubleshoot Most Common Issues for Business to Business Calls Through Expressway · Problem section 'VCS is unable to properly resolve FQDNs or fails to query SRV records' · Checked 2026-10-02

Documents

tier 1 standards and regulators

RFC 3263: Session Initiation Protocol (SIP): Locating SIP Servers

RFC Editor / IETF · 2002-06-01 · accessed 2026-09-24

tier 2 current vendor documentation

ASA NAT Configuration And Recommendations For The Expressway-E Dual Network Interfaces Implementation

Cisco Systems · 2018-08-13 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Diagnostics and Troubleshooting

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Dial Plan and Call Processing

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Firewall Traversal

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Maintenance

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Network and System Settings

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway Administrator Guide (X15.5) - Zones and Neighbors

Cisco Systems · 2026-02-09 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Advanced Networking Deployments

Cisco Systems · 2021-04-14 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Optional Configuration Tasks

Cisco Systems · 2021-04-14 · accessed 2026-09-25

tier 2 current vendor documentation

Cisco Expressway-E and Expressway-C Basic Configuration Deployment Guide (X14.0) - Routing Configuration

Cisco Systems · 2021-04-14 · accessed 2026-09-25

tier 2 current vendor documentation

Configure Business to Business Audio/Video Calls through Expressway

Cisco Systems · 2024-03-06 · accessed 2026-09-25

tier 2 current vendor documentation

Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates

Cisco Systems · 2026-02-13 · accessed 2026-09-30

tier 2 current vendor documentation

Troubleshoot Most Common Issues for Business to Business Calls Through Expressway

Cisco Systems · 2018-10-12 · accessed 2026-09-22

Cite this page

APA

WarmTransfer. (2026, October 2). Troubleshooting Expressway business-to-business calls. WarmTransfer. https://warmtransfer.net/knowledge/expressway-b2b-troubleshooting

BibTeX

@misc{warmtransfer-expressway-b2b-troubleshooting,
  title  = {Troubleshooting Expressway business-to-business calls},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/expressway-b2b-troubleshooting},
  note   = {Verified 2026-10-02}
}