Home | Register |    
 
Forums         |        Articles          |      Software          |      Portals          |      Resource          |      Wiki      |    White Papers         
 
Go Back   PBX Info :: Your Free PBX, PABX and Telephone Information Resource > PBX SYSTEMS > NORTEL > Meridian Systems
   SEARCH  
     
User Name Password      
Save ?
Meridian Systems Welcome to the Nortel Meridian Forums Including Meridian Options 11-81C CS1000M Meridian Mail Call Pilot Companion and Sucession Hospitality OTM MAT MICB RAN NetGateway ..., and all other Applications


Post New Thread  Reply
 
LinkBack Thread Tools Display Modes
Old 12-17-2007, 09:57 PM   #1 (permalink)
BAMEDEO
Junior Member
 
BAMEDEO's Avatar

Activity Longevity
0/20 5/20
Today Posts
0/0 ssssssss3
Location: CINCINNATI, OH
Rep Power: 0BAMEDEO is an unknown quantity at this point

Total Points:
Donate
Gender:
Country:

Send a message via AIM to BAMEDEO Send a message via Yahoo to BAMEDEO
Question UNIStim IP Phone Forced to Re-register

we have been having an issue for months now with IP sets (1140E series) rebooting in Bangalore, India - Tamarac, Fl - and Manila. These are three of many other sites off this node (CS1000 Rls 4.5). We have checked our PBX, the LAN, our WAN, and were going to contact the MPLS carriers, except they are not the same for each site.

Then I found this security alert online: Nortel: Technical Support: Type:Security AdvisoriesNumber:2007008385, Rev 1Status:ActiveDate:2007-10-17


Risk:
This attack may cause a potential DoS situation for the IP Phone user and has been brought to Nortel's attention by Compass Security Network Computing. To our knowledge, this attack has not been launched against any of our customers.

While it says no customers have been affected as of yet [to their knowledge], can we possibly be the first ones!? Any other idea what would cause phones to just 'drop dead' and re-register almost daily??
BAMEDEO is offline   sendpm.gif Reply With Quote
Old 12-18-2007, 03:37 PM   #2 (permalink)
pedropenduko
Junior Member

Activity Longevity
2/20 3/20
Today Posts
0/0 ssssssss3
Rep Power: 0pedropenduko is an unknown quantity at this point

Total Points:
Donate
Country:

Capture the packet coming into the set, if you have lots of packets coming into the set ( caused by DoS) then your IP set is subject to DoS. If not, what's the interval of the re-registration time. What messages did you get from your TPS?What type of set do you have i200X? Do you have the latest set firmware
pedropenduko is offline   sendpm.gif Reply With Quote
Old 12-18-2007, 10:48 PM   #3 (permalink)
Fletch
Senior Member
 
Fletch's Avatar

Activity Longevity
10/20 20/20
Today Posts
0/0 ssssss972
Location: NORTEL - NJ
Rep Power: 6Fletch is on a distinguished road

Total Points:
Donate
Gender:
Country:

Send a message via Yahoo to Fletch
There are a few things that can make the set deregister and reboot.

First let's look at the set side. It has a Watchdog timer that starts a 200 and counts down to zero. When it reaches zero, the phone reboots. The TPS comes in about every 100 seconds or so and resets this timer to 200 to prevent the reboot.

So capture the packets at the phone and make sure you are seeing the watchdog timer reset come in every 100 seconds or so. (Get the Wireshark Decoder plug-in for Nortel phones here by searching on Wireshark and UNIStim)

Second thing on the phone side is that if a key is pressed the phone sends a message to the TPS and is looking for an ACK to come back to show the command was received. IF no ACK is received, then the phone tries 10 more times in rapid succession (once every 400 ms.) If there is no ACK back from the TPS, the phone assumes the TPS is gone and tries to establish a new session based on the Retry settings in the phone.

Now the TPS side, everytime the watchdog reset is sent out to the phone the TPS is also looking for an ACK. Same rule applies, if no ACK is received, then the TPS tries 10 more times in rapid succession (once every 400 ms.) If there is still no ACK back from the phone, the TPS assumes the phone is gone and kills the session and deregisters the phone.

Now in addition to the watchdog, there are display and time updates that get sent to the phone every 30 seconds or so. These also have to be ACK'd, or the TPS says 'see ya!'.

One additional thing is any update to the keys or display, like a multiple appearance DN ringing, or a DWC key update. All of these messages must be ACK's back to the TPS, or the set is de-registered.

In order to properly trouble shoot this you are going to have to set up 2 monitor points on your network (where the 'X' are):

[TPS(SS)] ---X---[Data Switch] ---LAN---[Data Switch]---X---[Phone]

Only by doing this will you be able to see what was sent, and what was recieved. This will point you in the right direction. Once you isolate the message being dropped, you can look at the port in use, make sure the Firewalls are passing traffic on that TCP/IP Port, etc.

Good luck!
__________________
Fletch

For more on Nortel E911 Solutions on the web:
http://nortel.com/e911
Fletch is offline   Reply With Quote
Post New Thread  Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
IP Phones will not Register scuzzie2k BCM and Norstar 8 10-26-2007 06:42 PM
Public Version of UNIStim Decoder for Wireshark Fletch Meridian Systems 15 09-10-2007 04:43 PM
Companion Problem Not Able to Register hsantos Meridian Systems 6 05-20-2004 03:54 PM
25.40 call register issue telecom116 Meridian Systems 6 02-07-2003 01:33 PM
UNISTIM ScottBye Meridian Systems 1 01-10-2003 09:44 AM

Tags   |   Advertise    |    Media Partners   |    Admin   |   About us   |   Contact Us   |   RSS   


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0
Copyright PBXINFO LLC 2006