# Troubleshooting Expressway Mobile and Remote Access

Canonical: https://warmtransfer.net/knowledge/expressway-mra-troubleshooting

Last verified: 2026-10-01

Cisco's Mobile and Remote Access (MRA) troubleshooting begins by checking Status > Alarms on both Expressway-C and Expressway-E and reviewing the Status > Unified Communications page[^1]. Guidance recommends using the Collaboration Solutions Analyzer CollabEdge validator to simulate endpoint sign-in and, if that fails, running collected logs through the log analysis component[^10].

## Diagnostic Tools and Initial Verification

The Collaboration Solutions Analyzer CollabEdge Validator verifies public DNS, external connectivity, and the Expressway-E certificate[^9]. When supplied with test credentials, it retrieves Cisco Unified Communications Manager user and device configuration, authenticates to Cisco Unified Communications Manager IM and Presence Service, and registers a device, while providing a checkbox to skip IM and Presence Service for phone-only deployments[^9].

The Expressway DNS lookup tool located under Maintenance > Tools > Network utilities > DNS lookup allows administrators to check the `_collab-edge._tls` and `_cisco-uds._tcp` SRV records[^11]. Executing the tool on Expressway-C provides the enterprise view, while running it on Expressway-E provides the DMZ view[^11]. In Expressway-C call status, an MRA call appears as 3 components using zones prefixed with CEtcp or CEtls, whereas on Expressway-E it appears as 1 component routed through the CollaborationEdgeZone[^30].

## Network, Firewall, and DNS Requirements

Public external DNS must contain `_collab-edge._tls.<domain>` SRV records to allow endpoints to discover Expressway-E[^38]. The Expressway-E FQDN, which consists of its System host name plus Domain name, must be resolvable in public DNS[^21]. The `_collab-edge` SRV target FQDN should match the configured Expressway-E host name and domain; a mismatch breaks Jabber communication with Expressway-E (CSCuo83458; CSCuo82526)[^47]. Conversely, `_cisco-uds` SRV records must not resolve outside the internal network, or Jabber will not initiate MRA negotiation through Expressway-E[^5]. Starting in release X12.5, internal `_cisco-uds._tcp` SRV records are no longer a strict requirement for Expressway-C, though Cisco still recommends them[^27]. From Expressway X8.8 forward, forward and reverse DNS records are required for Expressway-C, Expressway-E, and Unified CM nodes; missing PTR records lead to reverseDNSLookup exceptions or "Certificate verification failed... Invalid Hostname"[^40].

The external firewall must permit inbound traffic to Expressway-E on SIP TCP 5061, HTTPS TCP 8443, XMPP TCP 5222, and media UDP ports 36002 through 59999[^26]. Missing `_collab-edge` SRV records or unreachability of Expressway-E TCP port 8443 due to firewall rules, default gateway misconfigurations, or static route errors will cause Jabber MRA sign-in to fail[^8]. An Expressway-E log entry showing "TCP Connection Closed" with the reason "Idle countdown expired" on port 5061 indicates interference from firewall SIP inspection or Application Layer Gateway (ALG); SIP inspection must be disabled for MRA traffic[^45].

Internal firewalls must allow outbound traffic from Expressway-C to Expressway-E on SIP TCP 7001, traversal media UDP ports 2776 through 2777, XMPP TCP 7400, and HTTPS tunneled over SSH TCP 2222[^36]. Expressway-C logging "Unable to connect to host... port 7400: (111) Connection Refused" is caused by a single-NIC Expressway-E configured with "Use Dual Network Interfaces" set to Yes; setting it to No resolves the issue[^12].

Expressway-E and Expressway-C must not share an address (including a shared NAT address) because the firewall cannot distinguish between them, and Cisco does not support it[^34]. Cisco positions single-NIC Expressway-E deployments using static NAT as not recommended because they rely on firewall NAT reflection[^42]. For single-NIC Expressway-E using static NAT, Cisco's documented fix requires pointing the Expressway-C UC traversal zone to the Expressway-E public IP and configuring NAT reflection on the firewall[^43]. When Expressway-C displays the status "Provisioning server: Waiting for traversal server info", the condition is caused by duplicate internal DNS A records for Expressway-E; administrators must delete the internal-IP record for single-NIC static NAT or the external-IP record for dual-NIC static NAT[^55].

## Certificate Requirements and TLS Verification

For MRA deployments, the Expressway-C server certificate Subject Alternative Name (SAN) must include the phone security profile names used by MRA endpoints, the cluster name when clustered, and IM and Presence chat node aliases if federated group chat is deployed[^20]. The Expressway-E server certificate SAN must include Unified CM registration domains, XMPP federation domains, and IM and Presence chat node aliases where used[^22]. Cisco Jabber presents an invalid-certificate warning over MRA if the Expressway-E certificate is self-signed or omits the external DNS domain from its SAN; resolving this requires a certificate issued by a CA trusted by Jabber that includes those domains[^29]. Cisco 7800 and 8800 series phones fail to register over MRA if the Expressway-E certificate is signed by an internal or unknown CA; the certificate must chain to a CA present in the phones' preloaded trust list[^37].

An MRA traversal zone fails to establish when only the peer leaf certificate is trusted; the entire certificate chain containing intermediates and root must reside in each Expressway node's trusted CA list[^49]. Secure MRA registrations fail with "Failed to establish SSL connection" if the Expressway-C server certificate SAN omits the Unified CM phone security profile names; starting in release X12.6, these profile names must be formatted as FQDNs[^41].

Field Notice FN74362 identifies Expressway Core and Edge X14 releases and releases X15.0.0 through X15.3.2 as affected by public CAs phasing out the Client Authentication Extended Key Usage (EKU)[^13]. Prior to release X15.4, Expressway-C validates both Server Authentication and Client Authentication EKUs on the certificate presented by Expressway-E during the MRA SIP SERVICE exchange; consequently, presenting a server-only EKU certificate on Expressway-E results in failed SIP registration[^17]. WarmTransfer's reading of the sources is that an MRA deployment running X14 or X15.0 through X15.3.2 that renews its Expressway-E certificate from a public CA after mid-2026 faces likely MRA SIP registration failures unless it relies on a combined-EKU alternative root or private PKI where permitted[^18].

Expressway X15.4, released in February 2026, supports Server Authentication EKU-only certificates on Expressway-E for MRA when configured with `xConfiguration XCP TLS Certificate CVS EnableServerEkuUpload: On`[^56]. Cisco requires both Expressway-E and Expressway-C to be upgraded to the same version (either X15.4 or X15.5) to apply the Client Auth EKU fix[^16]. Expressway X15.5 splits certificate management into an inbound server store and an outbound client store; upon upgrade from X15.4, the existing server certificate is duplicated into the client store[^60]. In Cisco tests on X15.5, MRA, UC traversal, and SSH tunnels established successfully when the Expressway-C client certificate contained both Server and Client EKU while all other certificates used Server EKU only; configuring a Server-only EKU on Expressway-C with EKU checking enabled on Expressway-E caused the UC traversal zone to report FAILED[^57]. In X15.5 environments, SSH tunnels that remain inactive while the UC traversal zone is active indicate that the client certificate lacks the Client Authentication EKU required for port 2222[^19].

## Service Synchronization and Registration Failures

Following configuration changes to a Unified CM cluster or node, Expressway-C must rediscover all Unified CM and IM and Presence Service nodes under Configuration > Unified Communications; omitting rediscovery can cause MRA communication failures[^39].

MRA endpoints can fail to register when a SIP trunk is configured between Unified CM and Expressway-C; this is resolved by assigning the trunk a listening port on Unified CM distinct from the SIP line registration port[^46]. A SIP 405 Method Not Allowed response accompanied by Warning 399 'SIP trunk disallows REGISTER' during endpoint registration indicates a port collision with a SIP trunk on port 5060 or 5061[^44]. This conflict is resolved by moving the Unified CM trunk security profile to port 5065 and updating the Expressway-C neighbor zone target to port 5065[^44].

Jabber may authenticate over MRA but fail to register phone services due to a case-handling mismatch between Expressway and UDS; users must sign in with the user ID exactly as stored in UDS (CSCux16696)[^51]. An underscore in the Expressway-E DNS host name prevents MRA SSH tunnels from establishing, causing Jabber sign-in failures; the System host name must contain only letters, digits, and hyphens[^53]. Additionally, DNS domain names must be identical across Expressway-E cluster peers, including letter casing, or Jabber sign-ins can fail intermittently[^7].

## HTTP, Authentication, and Call Signaling Errors

| Error Symptom | Documented Root Cause | Documented Resolution |
| --- | --- | --- |
| MRA 401 Unauthorized | Unknown username, incorrect password, or missing ILS setup across all Unified CM clusters[^52] | Correct credentials or configure Intercluster Lookup Service on all Unified CM clusters[^52] |
| 403 Forbidden (Voicemail) | Cisco Unity Connection host missing from HTTP server allow list[^54] | Ensure Cisco Unity Connection is included on Expressway-C HTTP allow list[^54] |
| 403 Forbidden (Service requests) | Expressway-C and Expressway-E time out of synchronization[^35] | Synchronize Expressway-C and Expressway-E to a reliable NTP server[^35] |
| 407 Proxy Authentication Required / 500 Internal Server Error | Traversal zone Authentication policy configured as "Check credentials"[^48] | Set traversal zone Authentication policy to "Do not check credentials"[^48] |
| 502 Next Hop Connection Failed | Failure in the connection between Expressway-E and Expressway-C[^32] | Inspect SSH tunnel status on Expressway-E under Status > Unified Communications[^32] |

When using OAuth token authorization, Jabber reconnect attempts using an expired access token can trigger automated intrusion protection if more than 5 HTTP proxy authorization failures occur, resulting in a 10-minute client IP address block by default[^28]. Cisco suggests increasing the trigger threshold from 5 to 10[^28]. Furthermore, client HTTPS requests over MRA may be dropped if consecutive 404 responses trigger the HTTP proxy resource access failure rule; this category of intrusion protection can be disabled[^23].

Expressway-C automatically populates inbound rules on its HTTP allow list during node discovery or server refresh for Unified CM, IM and Presence Service, Cisco Unity Connection, and TFTP nodes; these rules cannot be edited or deleted[^2]. Custom rules can be added under Configuration > Unified Communications > HTTP allow list > Editable inbound rules by specifying URL, port, path, match type (Exact or Prefix), and allowed HTTP methods[^3].

MRA calls will fail if the destination endpoint is situated more than 15 hops from Expressway-E, as the default traversal zone hop count limit is 15; Cisco highlights 70 as an example of an increased limit[^50].

## Media Path and ICE Diagnostics

Connected MRA calls that suffer from no audio are typically traced to missing static NAT settings on Expressway-E under System > Network Interfaces > IP, blocked media ports in intermediate firewalls, or single-NIC deployments that lack NAT reflection[^33]. 

Interactive Connectivity Establishment (ICE) passthrough over MRA requires Unified CM to operate in SIP OAuth mode or mixed mode using an encrypted phone security profile[^24]. This encryption mode is mandatory because the leg connecting Expressway-C to Unified CM must use TLS to safeguard media encryption keys[^24].

## See also

- See also [Setting up Mobile and Remote Access on Cisco Expressway](https://warmtransfer.net/knowledge/expressway-mra-setup).
- See also [Expressway and Mobile and Remote Access](https://warmtransfer.net/knowledge/cucm-expressway-mra).
- See also [Setting up certificates on Cisco Expressway](https://warmtransfer.net/knowledge/expressway-certificate-setup).
- See also [One-way and no-way audio diagnosis](https://warmtransfer.net/knowledge/one-way-audio).
- See also [DNS SRV and service discovery for SIP](https://warmtransfer.net/knowledge/dns-srv-voice).
- See also [SIP TLS handshake failures on trunks](https://warmtransfer.net/knowledge/sip-tls-handshake-failures).
- See also [Unified CM SIP trunks and security profiles](https://warmtransfer.net/knowledge/cucm-sip-trunks).
- See also [Cisco Unity Connection voicemail and migration](https://warmtransfer.net/knowledge/cucm-unity-connection).

## Applicability

Applies to: Cisco Expressway and Cisco Collaboration Solutions Analyzer. Deployments: on-premises and cloud-tool. Sources checked 2026-10-01. The documented software releases range from Expressway X8.8 through X15.5[^40][^60]. As of 2026-10-01, the newest Mobile and Remote Access deployment guide published on Cisco's configuration guide page was release X15.2 (dated 15 Oct 2024), whereas the certificate guide had reached release X15.5 (dated 29 Jul 2026)[^31].

## What remains uncertain

The impact of Field Notice FN74345 on on-premises calling products regarding Client Authentication EKU requirements on the Unified CM side of MRA is not covered by the sources below. The handling and behavior of ACME certificates on Expressway-E after Let's Encrypt dropped the Client Authentication EKU is not covered by the sources below. Primary text and official effective dates from the Chrome Root Program policy concerning server-auth-only certificates are not covered by the sources below. Differences between Cisco Webex App and Cisco Jabber sign-in behaviors over MRA are not covered by the sources below. Release note caveats, known bugs, and specific defect fixes in Expressway X15.5 related to MRA are not covered by the sources below. The maximum MRA registration capacity per hardware appliance or virtual machine size is not covered by the sources below. Failures occurring during MRA activation-code onboarding for devices are not covered by the sources below. Specific failures relating to MRA OAuth refresh tokens and external Single Sign-On (SSO) integrations are not covered by the sources below.

## Sources

[^1]: Cisco's MRA troubleshooting guidance starts with checking Status > Alarms on both Expressway-C and Expressway-E and reviewing the Status > Unified Communications page. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Checking Alarms and Status. Checked 2026-10-01.
[^2]: Expressway-C adds HTTP allow list inbound rules automatically on node discovery or server refresh for Unified CM; IM and Presence; Unity Connection and TFTP nodes, and these automatic rules cannot be edited or deleted. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - Features and Additional Configurations](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_features-and-additional-configurations.html), HTTP Allow List > Automatic Inbound Rules. Checked 2026-10-01.
[^3]: Administrators add their own HTTP allow list entries at Configuration > Unified Communications > HTTP allow list > Editable inbound rules with a URL; port; path; match type of Exact or Prefix; and allowed HTTP methods. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - Features and Additional Configurations](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_features-and-additional-configurations.html), HTTP Allow List > Editable Inbound Rules. Checked 2026-10-01.
[^4]: Services such as the Jabber update server; directory photo host; Problem Report Tool server; Extension Mobility; Managed File Transfer and visual voicemail need manual HTTP allow list entries beyond the automatic rules. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - Features and Additional Configurations](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_features-and-additional-configurations.html), HTTP Allow List (services requiring manual entries). Checked 2026-10-01.
[^5]: _cisco-uds SRV records must not be resolvable outside the internal network or Jabber will not start MRA negotiation through the Expressway-E. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), DNS Records > Local DNS (Internal Domains). Checked 2026-10-01.
[^6]: The X15.2 MRA guide states Expressway certificates must include the Client Authentication extension and that the system will not accept an upload without it. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), CSR Requirements. Checked 2026-10-01.
[^7]: Jabber sign-in can fail intermittently when Expressway-E cluster peers have different DNS Domain names; the domain must be identical on all peers including letter case. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Cisco Jabber Sign-In Issues > Inconsistent DNS domain names in Expressway-E cluster. Checked 2026-10-01.
[^8]: Jabber MRA sign-in fails when the _collab-edge SRV is missing or Expressway-E TCP 8443 is unreachable because of firewall rules or Expressway-E gateway or static route errors. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Log In Issues > SRV record not created or port 8443 unreachable. Checked 2026-10-01.
[^9]: CollabEdge Validator in Collaboration Solutions Analyzer checks public DNS; external connectivity; the Expressway-E certificate; and with test credentials it pulls UCM user and device configuration, authenticates to IM and Presence and registers a device; a checkbox skips IM and Presence for phone-only deployments. Source: [About - CollabEdge Validator - Collaboration Solutions Analyzer 2.0 documentation](https://cway.cisco.com/docs/tools/CollaborationSolutionsAnalyzer/csa.collabedge.about.html), About (CollabEdge Validator). Checked 2026-10-01.
[^10]: The MRA troubleshooting chapter recommends the Collaboration Solutions Analyzer CollabEdge validator to simulate a Jabber sign-in; if it fails then collect logs and run them through the CSA log analysis component. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Collaboration Solutions Analyzer. Checked 2026-10-01.
[^11]: The Expressway DNS lookup tool (Maintenance > Tools > Network utilities > DNS lookup) can check the _collab-edge._tls and _cisco-uds._tcp SRV records; run on Expressway-C it shows the enterprise view and on Expressway-E the DMZ view. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Checking DNS Records. Checked 2026-10-01.
[^12]: Expressway-C logging 'Unable to connect to host ... port 7400: (111) Connection Refused' is caused by a single-NIC Expressway-E with Use Dual Network Interfaces set to Yes; set it to No. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Log In Issues > XCP_JABBERD connection refused. Checked 2026-10-01.
[^13]: Field Notice FN74362 rates Expressway Core and Edge X14 (all releases) and X15.0.0 through X15.3.2 as affected by public CAs dropping the Client Authentication EKU. Source: [Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided](https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74362.html), Affected Products. Checked 2026-10-01.
[^14]: Cisco technote 225482 places full enforcement of the Chrome Root Program server-auth-only policy in June 2026, with public CAs stopping Client Authentication EKU issuance in May 2026 (disputed). Source: [Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html), Chrome Root Program Policy & Timeline. Checked 2026-10-01.
[^15]: Field Notice FN74362 (rev 1.2) says the Chrome Root Program Policy restriction on root CA certificates takes effect in March 2027 (disputed). Source: [Field Notice: FN74362 - Cisco Expressway: Impact on Secure Communication due to Upcoming Changes to TLS Certificates Issued by Public Certificate Authorities with Client Authentication EKU, Starting May 2026 - Workaround Provided](https://www.cisco.com/c/en/us/support/docs/field-notices/743/fn74362.html), Background / Problem Description. Checked 2026-10-01.
[^16]: Cisco requires Expressway-E and Expressway-C to be upgraded to the same version (X15.4 or X15.5) for the Client Auth EKU fix. Source: [Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html), Expressway Software Fixes. Checked 2026-10-01.
[^17]: Before X15.4 Expressway-C validates both Server and Client Authentication EKUs on the certificate Expressway-E presents for the MRA SIP SERVICE exchange, so a server-only EKU certificate on Expressway-E shows up as failed SIP registration. Source: [Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html), How MRA; Traversal Zones; B2B and Clustering Are Impacted > MRA. Checked 2026-10-01.
[^18]: An MRA deployment still on X14 or X15.0 through X15.3.2 that renews its Expressway-E certificate from a public CA after mid-2026 is likely to see MRA SIP registration fail unless it uses a combined-EKU alternative root or private PKI where allowed (inferred). Source: [Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html), How MRA ... Are Impacted; Workarounds. Checked 2026-10-01.
[^19]: Per Cisco's X15.5 guidance, SSH tunnels that stay inactive while the UC traversal zone is active indicate the client certificate lacks the Client Authentication EKU needed for port 2222. Source: [Navigate Client EKU Sunset with Expressway x15.5](https://www.cisco.com/c/en/us/support/docs/unified-communications/telepresence-video-communication-server-expressway/225693-navigate-client-eku-sunset-with.html), Troubleshooting Log Indicators for EKU Failures > SSH Tunnel Failure Pattern. Checked 2026-10-01.
[^20]: For MRA the Expressway-C server certificate SAN must include the phone security profile names used by MRA endpoints; the cluster name when clustered; and IM and Presence chat node aliases when federated group chat is used. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), CSR Requirements. Checked 2026-10-01.
[^21]: For MRA the Expressway-E FQDN (System host name plus Domain name) must be resolvable in public DNS. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Checking Reachability of the Expressway-E. Checked 2026-10-01.
[^22]: For MRA the Expressway-E server certificate SAN must include the Unified CM registration domains; XMPP federation domains; and IM and Presence chat node aliases where used. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), CSR Requirements. Checked 2026-10-01.
[^23]: Client HTTPS requests over MRA can be dropped when repeated 404 responses trigger the HTTP proxy resource access failure category of automated intrusion protection; that category can be disabled. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > Client HTTPS requests are dropped by Expressway. Checked 2026-10-01.
[^24]: ICE passthrough over MRA requires Unified CM in SIP OAuth mode or mixed mode with an encrypted phone security profile, because the Expressway-C to Unified CM leg must use TLS to protect media keys. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_ice-media-path-optimization.html), ICE Media Path Optimization > Prerequisites and Encryption. Checked 2026-10-01.
[^25]: ICE media path optimization for MRA needs TURN enabled on Expressway-E (default port 3478; TURN media 24000 to 29999); Expressway-C X12.5 or later with CEtls zones; ICE passthrough enabled on UC traversal and neighbor zones; and Unified CM 11.5 or later. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - ICE Media Path Optimization](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_ice-media-path-optimization.html), ICE Media Path Optimization > Prerequisites. Checked 2026-10-01.
[^26]: The external firewall must allow inbound to Expressway-E for MRA: SIP TCP 5061; HTTPS TCP 8443; XMPP TCP 5222; media UDP 36002 to 59999. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), Firewall Configuration. Checked 2026-10-01.
[^27]: Internal _cisco-uds._tcp SRV records stopped being a strict MRA requirement for Expressway-C from X12.5 though Cisco still recommends them. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), DNS Records > Local DNS (Internal Domains). Checked 2026-10-01.
[^28]: With OAuth token authorization Jabber reconnects using an expired access token can trip Expressway automated intrusion protection: more than 5 HTTP proxy authorization failures block the client IP for ten minutes by default; Cisco suggests raising the trigger level from 5 to 10. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Cisco Jabber Sign-In Issues > Jabber sign in fails due to Automated Intrusion Protection. Checked 2026-10-01.
[^29]: Jabber shows an invalid-certificate warning over MRA when the Expressway-E certificate is self-signed or does not list the external DNS domain in its SAN; the fix is a certificate from a CA Jabber trusts that includes those domains. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Cisco Jabber Sign-In Issues > Jabber popup warns about invalid certificate. Checked 2026-10-01.
[^30]: In Expressway-C call status an MRA call appears as three components using zones prefixed CEtcp or CEtls; on Expressway-E it appears as one component routed through the CollaborationEdgeZone. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Identifying Mobile and Remote Access calls. Checked 2026-10-01.
[^31]: On 2026-10-01 the newest Mobile and Remote Access deployment guide on Cisco's Expressway configuration guides page was X15.2 (15 Oct 2024), while the certificate guide had reached X15.5 (29 Jul 2026). Source: [Cisco Expressway Series - Configuration Guides](https://www.cisco.com/c/en/us/support/unified-communications/expressway-series/products-installation-and-configuration-guides-list.html), Mobile and Remote Access guides; Certificate Creation and Use guides. Checked 2026-10-01.
[^32]: A 502 Next Hop Connection Failed on Expressway-E usually points to the connection to Expressway-C; check SSH tunnel status from Status > Unified Communications. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > Expressway returns 502 Next hop connection failed. Checked 2026-10-01.
[^33]: Calls that connect over MRA with no audio are traced to static NAT not set on Expressway-E (System > Network Interfaces > IP); blocked media ports in the firewall; or a single-NIC deployment without NAT reflection. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Call-Related Issues > No Media over MRA. Checked 2026-10-01.
[^34]: Expressway-E and Expressway-C must not share an address (including a shared NAT address) because the firewall cannot distinguish between them; Cisco does not support it. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), IP Addresses. Checked 2026-10-01.
[^35]: MRA service requests can be rejected with 403 Forbidden when Expressway-C and Expressway-E are not synchronized to a reliable NTP server. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > 403 Forbidden responses for any service requests. Checked 2026-10-01.
[^36]: The internal firewall must allow outbound from Expressway-C to Expressway-E for MRA: SIP TCP 7001; traversal media UDP 2776 to 2777; XMPP TCP 7400; HTTPS tunneled over SSH TCP 2222. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), Firewall Configuration. Checked 2026-10-01.
[^37]: Cisco 7800 and 8800 phones will not register over MRA when the Expressway-E certificate is signed by an internal or unknown CA; it must chain to a CA in the phones' preloaded trust list. Source: [Configure and Troubleshoot Collaboration Edge (MRA) Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/213872-configure-and-troubleshoot-collaboration.html), Common Certificate Issues > 7800/8800 phones fail to register. Checked 2026-10-01.
[^38]: Public external DNS must hold _collab-edge._tls.<domain> SRV records so endpoints can discover the Expressway-E for MRA. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), DNS Records > Public DNS (External Domains). Checked 2026-10-01.
[^39]: After Unified CM cluster or node configuration changes Expressway-C must rediscover all Unified CM and IM and Presence Service nodes under Configuration > Unified Communications or MRA communication problems can follow. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), General Techniques > Expressway-C Synchronization to Unified CM. Checked 2026-10-01.
[^40]: From Expressway X8.8 forward and reverse DNS records are required for Expressway-C; Expressway-E and Unified CM nodes; missing PTRs show as reverseDNSLookup exceptions or 'Certificate verification failed ... Invalid Hostname'. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Log In Issues > Expressway reverse DNS lookup fails. Checked 2026-10-01.
[^41]: Secure MRA registrations fail with 'Failed to establish SSL connection' when the Expressway-C server certificate SAN lacks the Unified CM phone security profile names; from X12.6 those profile names must be in FQDN format. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Registration Issues > Endpoints Cannot Register to Unified CM (secure registrations). Checked 2026-10-01.
[^42]: Cisco marks single-NIC Expressway-E with static NAT as not recommended because it depends on NAT reflection in the firewall. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_requirements-for-mra.html), Firewall Configuration (single NIC with static NAT). Checked 2026-10-01.
[^43]: For single-NIC Expressway-E with static NAT, Cisco's fix is to point the Expressway-C UC traversal zone at the Expressway-E public IP and configure NAT reflection on the firewall. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Call-Related Issues > No Media over MRA. Checked 2026-10-01.
[^44]: A SIP 405 Method Not Allowed with Warning 399 'SIP trunk disallows REGISTER' on MRA registration means a SIP trunk on 5060 or 5061 conflicts; move the Unified CM trunk security profile to port 5065 and target 5065 from the Expressway-C neighbor zone. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Registration Issues > SIP/2.0 405 Method Not Allowed. Checked 2026-10-01.
[^45]: An Expressway-E log of TCP Connection Closed with Reason 'Idle countdown expired' on 5061 indicates firewall SIP inspection or ALG interfering; disable SIP inspection for MRA traffic. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Registration Issues > Idle countdown expired. Checked 2026-10-01.
[^46]: MRA endpoints can fail to register when a SIP trunk exists between Unified CM and Expressway-C; the fix is a trunk listening port on Unified CM different from the SIP line registration port. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Registration Issues > Endpoints Cannot Register to Unified CM. Checked 2026-10-01.
[^47]: The _collab-edge SRV target FQDN should match the Expressway-E configured host name and domain; a mismatch breaks Jabber communication with Expressway-E (CSCuo83458; CSCuo82526). Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Log In Issues > Expressway-E hostname and domain do not match the _collab-edge SRV. Checked 2026-10-01.
[^48]: MRA call failures with 407 Proxy Authentication Required or 500 Internal Server Error are caused by traversal zones whose Authentication policy is Check credentials; set it to Do not check credentials. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > Call failures due to 407 Proxy Authentication Required or 500 Internal Server Error errors. Checked 2026-10-01.
[^49]: An MRA traversal zone fails to establish when only the leaf certificate is trusted; the full chain (intermediates and root) of the peer certificate must be in each Expressway's trusted CA list. Source: [Configure and Troubleshoot Collaboration Edge (MRA) Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/213872-configure-and-troubleshoot-collaboration.html), Common Certificate Issues > Traversal zone fails to establish. Checked 2026-10-01.
[^50]: MRA calls fail when the called endpoint is more than 15 hops from Expressway-E because the traversal zone default hop count is 15; Cisco gives 70 as an example of a larger value. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > MRA calls fail if called endpoint is more than 15 hops away. Checked 2026-10-01.
[^51]: Jabber can sign in over MRA yet fail to register phone services because of a case-handling mismatch between Expressway and UDS; the user must sign in with the user ID exactly as stored in UDS (CSCux16696). Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Cisco Jabber Sign-In Issues > Jabber registers but cannot use phone services. Checked 2026-10-01.
[^52]: MRA 401 Unauthorized failures are attributed to an unknown username or wrong password or to Intercluster Lookup Service not being set up on all Unified CM clusters. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > 401 Unauthorized failure messages. Checked 2026-10-01.
[^53]: An underscore in the Expressway-E DNS host name stops the MRA SSH tunnels from establishing and Jabber sign-in fails; the System host name may contain only letters, digits and hyphens. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Cisco Jabber Sign-In Issues > Jabber fails to sign in due to SSH tunnels failure. Checked 2026-10-01.
[^54]: No voicemail service over MRA with 403 Forbidden is fixed by making sure the Cisco Unity Connection host is on the Expressway-C HTTP server allow list. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-2/mra/exwy_b_mra-deployment-guide-x152/exwy_m_mra-troubleshooting.html), Specific Issues > No voicemail service (403 Forbidden response). Checked 2026-10-01.
[^55]: The Expressway-C status 'Provisioning server: Waiting for traversal server info' is caused by duplicate internal DNS A records for Expressway-E; delete the internal-IP record for single NIC with static NAT or the external-IP record for dual NIC with static NAT. Source: [Resolve Collaboration Edge Most Common Issues](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway/118798-technote-cucm-00.html), Log In Issues > Configured but with errors. Provisioning server: Waiting for traversal server info. Checked 2026-10-01.
[^56]: Expressway X15.4 (February 2026) accepts a Server Authentication EKU-only certificate on Expressway-E for MRA, enabled by xConfiguration XCP TLS Certificate CVS EnableServerEkuUpload: On. Source: [Prepare Expressway for Client Authentication EKU Sunset in Public CA Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/expressway-series/225482-prepare-expressway-for-client.html), Cisco Expressway X15.4 Solution Details (February 2026); Frequently Asked Questions > Upgrade Questions. Checked 2026-10-01.
[^57]: In Cisco's X15.5 tests, MRA plus UC traversal plus SSH tunnels worked when the Expressway-C client certificate held both Server and Client EKU and all other certificates were Server EKU only; with Server-only EKU on Expressway-C and EKU checking ON at Expressway-E, the UC zone showed FAILED. Source: [Navigate Client EKU Sunset with Expressway x15.5](https://www.cisco.com/c/en/us/support/docs/unified-communications/telepresence-video-communication-server-expressway/225693-navigate-client-eku-sunset-with.html), Critical EKU Requirements by Use Case; Test Case 1. Checked 2026-10-01.
[^58]: X15.5 adds xconfiguration SIP TLS Certificate ExtendedKeyUsage Checking Mode (default ON), which checks inbound SIP TLS peers for the Client Authentication EKU; OFF bypasses that check. Source: [Navigate Client EKU Sunset with Expressway x15.5](https://www.cisco.com/c/en/us/support/docs/unified-communications/telepresence-video-communication-server-expressway/225693-navigate-client-eku-sunset-with.html), EKU Validation Configuration. Checked 2026-10-01.
[^59]: In X15.5 the UC traversal zone; MRA client authentication to Expressway-C; and the SSH tunnels on port 2222 use the client certificate, while inbound SIP TLS and secure neighbor zones on 5061 use the server certificate. Source: [Navigate Client EKU Sunset with Expressway x15.5](https://www.cisco.com/c/en/us/support/docs/unified-communications/telepresence-video-communication-server-expressway/225693-navigate-client-eku-sunset-with.html), Certificate Store Usage by Connection Type. Checked 2026-10-01.
[^60]: Expressway X15.5 splits certificates into a server store (presented on inbound TLS) and a client store (presented when Expressway initiates TLS); on upgrade from X15.4 the server certificate is copied into the client store. Source: [Navigate Client EKU Sunset with Expressway x15.5](https://www.cisco.com/c/en/us/support/docs/unified-communications/telepresence-video-communication-server-expressway/225693-navigate-client-eku-sunset-with.html), Key X15.5 Changes; Upgrade Behavior. Checked 2026-10-01.
