External users unable to download Lync GAL

Manoj Bojewar
Manoj Bojewar used Ask the Experts™
on
Hello Expert,

i have issues with Lync Gal, my external users unable to download the GAL.  when i ran the Lync configuration from lync client, i got to know GAL url is taking my internal website URL "pool1.domain.local).. i am not sure why it is taking internal web URL and this internal url is not rechable outside or internet due to pool1.domain.local. i am not sure how to change this GAL URL to external website URL. i hope this will resolve my problem. any help regards to this greatly appricated.

here is my lync configuration output for your reference.

DG URL Internal;https://pool1.hosting.local:443/groupexpansion/service.svc;--;
DG URL External;https://lyncweb.exchangemails.com:443/groupexpansion/service.svc;--;
Quality Metrics URI;sip:pool1.hosting.local@hosting.local;gruu;opaque=srvr:HomeServer:0AE5zW36FFihpJf8TdUKzgAA;--;
URL Internal From Server;https://pool1.hosting.local:443/abs/handler;--;
URL External From Server;https://lyncweb.exchangemails.com:443/abs/handler;--;
Voice mail URI;sip:manoj.bojewar@globaloutlook.com;opaque=app:voicemail;--;
Exum Enabled;FALSE;--;
Exum URL;;--;
MRAS Server;sip:goh-lyncedge.hosting.local@hosting.local;gruu;opaque=srvr:MRAS:UdeU1d6lTlWoqVSEUh0e4AAA;Enabled;
GAL Status;https://pool1.hosting.local:443/abs/handler;Cannot synchronize with the corporate address book. This may be because the proxy server setting in your web browser does not allow access to the address book. If the problem continues, please contact your support team.;
Controlled Phones;TRUE;--;
PC to PC AV Encryption;AV Encryption Supported;--;
Focus Factory;sip:manoj.bojewar@globaloutlook.com;gruu;opaque=app:conf:focusfactory;--;
Telephony Mode;Telephony Mode Disabled;--;
Line;;--;
Line Configured From;Auto Line Configuration;--;
Location Profile;DefaultProfile;--;
Call Park Server URI;;--;
UCS Mode;Lync Server Mode;--;
Configuration Mode;Auto Configuration;--;
Server Address Internal;--;--;
Server Address External;--;--;
Server SIP URI;manoj.bojewar@globaloutlook.com;--;
GAL or Server Based Search;GAL search;--;
Local Log Folder;C:\Users\Manoj\tracing;--;
MAPI Information;MAPI Status OK;MAPI Status OK;
EWS Information;--;EWS Status OK;
Inside User Status;FALSE;--;
Auto Update Download Started;--;--;
Auto Update Download Completed;--;--;
Last Auto Update Request;--;--;
Pairing State;Lync cannot connect to your desk phone because the USB cable is not plugged in. Make sure that you connect the cable.;Enabled;
Contact List Provider;Lync Server;--;
UCS Connectivity State;Exchange connection Down;--;
Connected Lync Server;sip.exchangemails.com;--;
Skill Search URL;;--;
SharePoint Search Center URL;;--;
EWS Internal URL;https://goh-cas02.hosting.local/EWS/Exchange.asmx;--;
EWS External URL;https://webmail.exchangemails.com/ews/exchange.asmx;--;
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®

Author

Commented:
Dear Expert,

please look into my query and let us know if you need any more info for it.
Please advise, since your configuration data seems not to be complete. There is also a field named Inside User Status, which should not be true in your scenario (users being external). If it is set to True, the Lync client thinks to be internal (probably due to an open VPN tunnel with the office). This would mean it will try to connect to the internal webservices instead of the external one.

Author

Commented:
yes, you are right. i was connnected to VPN.

please find the below lync configuration without VPN and from external device.

DG URL Internal;https://pool1.hosting.local:443/groupexpansion/service.svc;--;
DG URL External;https://lyncweb.exchangemails.com:443/groupexpansion/service.svc;--;
Quality Metrics URI;sip:pool1.hosting.local@hosting.local;gruu;opaque=srvr:HomeServer:0AE5zW36FFihpJf8TdUKzgAA;--;
URL Internal From Server;https://pool1.hosting.local:443/abs/handler;--;
URL External From Server;https://lyncweb.exchangemails.com:443/abs/handler;--;
Voice mail URI;sip:karthik.p@globaloutlook.com;opaque=app:voicemail;--;
Exum Enabled;FALSE;--;
Exum URL;;--;
MRAS Server;sip:goh-lyncedge.hosting.local@hosting.local;gruu;opaque=srvr:MRAS:UdeU1d6lTlWoqVSEUh0e4AAA;Enabled;
GAL Status;https://pool1.hosting.local:443/abs/handler;Cannot synchronize with the corporate address book. This may be because the proxy server setting in your web browser does not allow access to the address book. If the problem continues, please contact your support team.;
Controlled Phones;TRUE;--;
PC to PC AV Encryption;AV Encryption Supported;--;
Focus Factory;sip:karthik.p@globaloutlook.com;gruu;opaque=app:conf:focusfactory;--;
Telephony Mode;Telephony Mode Disabled;--;
Line;;--;
Line Configured From;Auto Line Configuration;--;
Location Profile;DefaultProfile;--;
Call Park Server URI;;--;
UCS Mode;Lync Server Mode;--;
Configuration Mode;Auto Configuration;--;
Server Address Internal;--;--;
Server Address External;--;--;
Server SIP URI;karthik.p@globaloutlook.com;--;
GAL or Server Based Search;GAL search;--;
Local Log Folder;C:\Users\trainee\tracing;--;
MAPI Information;MAPI Status OK;MAPI Status OK;
EWS Information;--;EWS Status OK;
Inside User Status;FALSE;--;
Auto Update Download Started;--;--;
Auto Update Download Completed;--;--;
Last Auto Update Request;--;--;
Pairing State;Lync cannot connect to your desk phone because the USB cable is not plugged in. Make sure that you connect the cable.;Enabled;
Contact List Provider;Lync Server;--;
UCS Connectivity State;Exchange connection Down;--;
Connected Lync Server;sip.exchangemails.com;--;
Skill Search URL;;--;
SharePoint Search Center URL;;--;
EWS Internal URL;https://goh-cas02.hosting.local/EWS/Exchange.asmx;--;
EWS External URL;https://webmail.exchangemails.com/EWS/exchange.asmx;--;
Server SIP URI - 1;sip.exchangemails.com:443;TLS Mode;
11/26 Forrester Webinar: Savings for Enterprise

How can your organization benefit from savings just by replacing your legacy backup solutions with Acronis' #CyberProtection? Join Forrester's Joe Branca and Ryan Davis from Acronis live as they explain how you can too.

Sorry for asking more questions, but is your reverse proxy setup right so that external calls for the addressbook are forwarded to the Lync frontend external webservices port 4443?
Are you using multiple front end enterprise edition servers in a pool? If so, did you setup Hardware load balancers? Are your certificates for the External webservices ok. A few URL's that might help in getting the addressbook isues resolved are:

http://blog.insidelync.com/2012/02/lync-address-book-client-synchronization-errors-and-common-problems/

http://www.ehloworld.com/751

Author

Commented:
i  dont have public certifcate for external webservices but my other features are working fine.. does address book require public certifcate for external users?

i am not using reverse proxy.. i am using Cisco ASA and doing port forwarding.
The external webservices should have the certificate for lyncweb.exchangemails.com (if this is your public webservices url) . You can get the configured external webservices fqdn through the powershell cmd-let Get-CsService -WebServer | FL ExternalFQDN.

Once the certificate is in place, make sure that the Cisco ASA is correctly forwarding to port 4443 on the frontend server, which is the external webservices port. To test this i would stop the internal webservices website through IIS management (this site is listening on port 443) and then from outside your netwerk try telnet to ExternalFQDN 443 and verify if it connects.

Author

Commented:
this help me resolve this issue. i installed public certifcate to external services. now all my lync issues resolved.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial