SfB Client fail to Sign-in Over DA - Malformed SIP URI

SfB Client 2016 fail to sign-in over DA. It just spins for sign-in to connect to SfB servers but nothing happens.
Environment:
  • Back-end Server: Windows 2008 R2 + SfB 2015
  • Client Operating Server: Windows 7 - Service Pack 1 / Windows 10
  • Client: Skype for Business Client 2016 (Office 2016 Pro Plus)
  • Direct Access Servers: (Windows 2008 R2 + UAG 2010)
Error in Lync/SfB Client logs:
SIP/2.0 400 Malformed SIP URI
From: <sip:[2001:0:8a68:e317:38bb:374:ae22:7d11]:56825>
To: <sip:[2002:8a58:e417:8001::afd:215]:5061>

ms-diagnostics: 1018;reason="Parsing failure";source="LyncFE.mydomain.int"

On further investigation, it is identified that the SfB client over DA was trying to connect to the internal SfB pool instead of connecting via the Edge server.

The quick and easy fix was to include a new rule into the Name Resolution Policy Table (NRPT) table on DA servers to exclude SfB FE pools to restrict SfB clients to use the internal DNS server. Once a required rule is added to the NRPT table and published, the SfB client started to sign-in over DA without any problem. As shown below, SfB FE Pool is now part of the UAG DA rule without and Direct Access DNS server IP (to force it to route via the Internet).

Name Resolution Policy Table (NRPT) in Registry editor


No comments:

Post a Comment