Cisco UC520 integration with Exchange 2013

I would like to integrate our phone system with exchange.

We are running Exchange 2013 CU3
Cisco UC520 runs
Cisco IOS Software  UC500-ADVIPSERVICESK9-M  
Software Version  15.1(4)M6 / CME 8.6  

I cant seem to find any step by step instructions for this setup or the list of features that become available once integrated.
Some of the features we are interested in is having access to voicemail in outlook and being able to click on a phone number in outlook contacts and have your Cisco IP 7945G phone set dial it automatically. Keeping in mind we have to dial 9 to get out so some sort of rule needs to acomodate that.

Once this is done I would like to integrate UC520 with our Lync 2013 as well unless someone thinks doing the Lync integration first is preffered.

Any help is appreciated.
arnoldConnect With a Mentor Commented:
What you need first is to enable the feature On UC520 that will allow IMAP connections.
I this this is under the additional application option. (Are you using CCA)?
You then need to configure the CUE mailbox/logins to login and access the data
Using a web browser.

You could configure the CUE to email the voicemail to an email address.

Here you would need to make the logins members imap user to allow imap access.
Outlook will effectively have two email accounts through which the user will be able to listen and delete the messages.
You need Cisco Unified CallConnector to accomplish this.
baysysadminAuthor Commented:
Thanks for reply

Can you tell me the actual benefit of seting up unified messaging in exchange?
What features become available?

There's two things to look at here.
1) Cisco Unified CallConnector - allows you to do click to call, call logs on your screen, quickly search and dial contact from Outlook.

2) Exchange Unified Messaging - make Exchange your repository for voicemail and email. Play voicemails from Outlook and do speech to text conversion.
baysysadminAuthor Commented:
Ive enabled the IMAP and I can see my session in the logs, but outlook just keep prompting for password, it wont accept my cretedntials that are stored in CUE.
You need to use a web browser to the CUE IP.  This should be the same IP as your phones.
i.e. if you did not change the defaults.
baysysadminAuthor Commented:
I can login to the CUE browser web console using the account but when I setup a IMAP account in outlook using the same login and CUE IP it wont authenticate.
For email i entered name@ but no luck.
I can see the session in CUE from my workstation but thats as far as I got.
Ive enabled all the settings for that username in CUE required for IMAP connection.
You need to make sure that the user (login) is a member of the vm-imap and broadcasters group.
Do you set the password, or did you let it set the initial one?
Under configure, look at the users and the groups to which they belong.

Then check the settings on the extension.
baysysadminAuthor Commented:
Ok im getting closer.
I added my account to those groups.
Now outlook accepts the incoming credentials and server but for outgoing test it gives me this error.
421 4.3.2 System not acc
I tried setting the outgoing auth to be same as incoming but got same error.

Also when i open the inbox for this newly added account in outlook i see 1 voicemail entry with attachment icon but the body is blank and no data or attachment are found inside the email. The size is 268KB
The status for this account is connected.
If i mark the message UNREAD, my phone message light will go red so its definitivelly connected but its having a weird effect where outlook window keeps blinking weird when that message is selected.

I should point out that on my CUE i did not have vm-imap group, it was called IMAPgrp
Some of this setup is original.
baysysadminAuthor Commented:
Well i deleted that message and saved a new voicemail, now its fine.
Must have been a corrupted old message.

IMAPgrp is the group that needs to be created with vm-imap or something similar.

glad to hear you have it up and running.
baysysadminAuthor Commented:
Its working but with some bugs.
Every once in a while a message does not display the attachemnt in outlook, almost as if its corrupt. The message body shows BLANK like the first one I described.

Also some of my users cant access the CUE IP. They can ping it but cant browse the webui or have outlook connect. It just times out.
So far I cant find any firewall rules that could block this or http access on the CME and CUE.
It works for 3 people so far which are on the same subnet as the rest.
I think it has something to do with CUE becuase CUE can ping back those 3 IPs but not the rest.
While everyone can ping CUE.
Is the cisco UC520 IP accessible from the LAN?

The CUE IP should not be disclosed to users.  Depending on the phones you have, you can enable and they could then access their emails on the phone which is usually on the same segment.

Your UC520 has three IPS

Voice VLAN for the phones
DATA VLAN for the devices if any connecting via/through the phone

The WAN portion of the UC520 which could be an IP on the LAN if you have one data dedicated LAN and one for the VOICE LAN.

The users should if they can access the IP or use the WAN IP.
baysysadminAuthor Commented:
This is the CME config with the routes
VLAN 1 is our local LAN VLAN100 is where the phones sets are.
I am not sure what access-list 105 is for, i dont see it applied anywhere.

interface Vlan1
 ip address
interface Vlan10
 no ip address
interface Vlan100
 ip address
 ip nat inside
 ip virtual-reassembly
 ip traffic-export apply TAC size 10000000
ip forward-protocol nd
ip http server
ip http secure-server
ip http path flash:/gui
ip nat inside source list 1 interface FastEthernet0/0 overload
ip route
ip route Integrated-Service-Engine0/0
access-list 1 remark SDM_ACL Category=2
access-list 1 permit
access-list 1 permit
access-list 1 permit
access-list 105 permit ip host any
access-list 105 deny   ip any any
baysysadminAuthor Commented:
I think my is the same as the 192 IP in example.
Yes the users can access this IP but they cant get to CUE using this IP.
I get the router interface and CME webui using this ip.
None of this explans why it works for few users.
Looking at the config file I cant find any specific entries that would allow acces to just a few ips.

I tried adding it in outlook instead of but it did not log in.

This entry concerns me, as I did not set this system up.
access-list 1 permit

We dont have a 10.11... subnet, im thinking it may have been a typo and should be 10.10...
You might be missing vlan90 that is the data VLAN and possibly the 10.11

10.10. Seems to be the WAN IP and is unlikely to be the dedictated management IP

How are your systems connected?

Do you have two separate networks a dedicated data LAN and a dedicated VOICE LAN?

Look at your UC520's DHCP reconfiguration.  

Show running | include DHCP

See what IPs are defined on the DHCP server.
baysysadminAuthor Commented:
This guy seems to have the same issue as me.
baysysadminAuthor Commented:
No vlan 90, but there is BLANK vlan 10, but i think that was a typo too.
The phone system has 3 subnets.
10.10 which is same as the computer LAN VLAN1 which is the ip7945 phone ip VLAN100 which is the CUE service engine IP.
interface Integrated-Service-Engine0/0
 description cue is initialized with default IMAP group
 ip unnumbered Loopback0
 ip nat inside
 ip virtual-reassembly
 service-module ip address
 service-module ip default-gateway
interface Loopback0
 ip address

ip dhcp relay information trust-all
ip dhcp excluded-address
ip dhcp excluded-address
ip dhcp pool phone
   option 150 ip

Again this line doesnt make any sense, we dont have that subnet #.
ip dhcp excluded-address
Who ever set this up made a lot of stupid typos.
baysysadminAuthor Commented:
Is there maybe  a limit to how many people can connect to CUE
Maybe thats why the first 3 people worked but not the rest.
This how ever doesnt explan why CUE can ping the GW and those 3 people but not any other IP on vlan1, not even the DNS server,  while everyone on vlan1 can ping CUE
I think the IMAP should support access for as many licenses as you need.

Check the IP configuration on the system from which the users are able and from which the users are not.

Another option you can use is the voice to email configuration.  When a voice mail is left, it will email it to the user.

I've seen corrupted voicemail messages. at times they dealt with a deletion that did not complete. i.e. checked via the phone and marked it for deletion. Or similarly via the IMAP but the message was not completely purged.

The voice to email, would only require the users to go in and delete/clear the cue if they do not want to do it via the phone interface.

the UC520 can have four separate networks.
1 WAN connection


The users to access IMAP/Messaging should use

Do you have your UC520 connected on the WAN port?
baysysadminAuthor Commented:
I did setup the email notification but its not working.
The CUE can ping the email server which is in DMZ 172... but only that one DMZ server.
Again this weird selective ping when all should work.

The corruped voicemail was a brand new unlisted voicemail.
At first I thought maybe because it was bigger than all my test ones.
So i left myself a 1 min voicemail and that one came in fine.
It seems random.

My UC520 has 8 ports, only 1 i used.
But looking phyiscall at the unit the 8 POE ports are not plugged in, the WAN is NOT used only EXPANSION port is plugged in. This doesnt seem to match what I am seeing in config.
Maybe im looking at the wrong place.

Port    Name               Status       Vlan       Duplex Speed Type
Fa0/1/0                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/1                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/2                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/3                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/4                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/5                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/6                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/7                    notconnect   1            auto    auto 10/100BaseTX
Fa0/1/8                    connected    trunk      a-full   a-100 10/100BaseTX

I tried connecting IMAP using but outlook failed to connect.
It only seems to be accepting connections on but for 3 users.
baysysadminAuthor Commented:
I ran a different command which gave me complete list of ALL interfaces.
Is WAN port required? Im not sure why we are not using it or what exactly its for.

Interface                   IHQ       IQD       OHQ       OQD      RXBS      RXPS      TXBS      TXPS      TRTL
  FastEthernet0/0               0         0         0         0         0         0         0         0         0
* In0/0                         0         0         0         0         0         0         0         0         0
  FastEthernet0/1/0             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/1             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/2             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/3             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/4             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/5             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/6             0         0         0         0         0         0         0         0         0
  FastEthernet0/1/7             0         0         0         0         0         0         0         0         0
* FastEthernet0/1/8             0         0         0         0     10000        13     94000        54         0
  Serial0/2/0:0                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:1                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:2                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:3                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:4                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:5                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:6                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:7                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:8                 0         0         0         0         0         0         0         0         0
  Serial0/2/0:9                 0         0         0         0         0         0         0         0         0
* Serial0/2/0:23                0         0         0         0         0         0         0         0         0
* Vlan1                         0         0         0         0      5000         7      2000         2         0
* Vlan10                        0         0         0         0         0         0         0         0         0
* Vlan100                       0         0         0         0         0         1     85000        50         0
* NVI0                          0         0         0         0         0         0         0         0         0
* Loopback0                     0         0         0         0         0         0         0         0         0
What is the IP on the system from which you connect?

I do not think the CUE IP is should be hit by anything other than the phones.

I do not believe the UC has POE ports.  IT has plain Ethernet ports.

is there a path from to the DMZ IP?  See what rules exists on the firewall that is handling the DMZ port.
Does it allow access from network?
baysysadminAuthor Commented:
Mine is
Our UC has POE, it says right there on the device.
We dont use them , we use the 9th expansion interface which goes to a POE 24port switch.
Then that switch goes to our LAN swtiches which goes to the ASA firewall.
the firewall simply has a route to /24 and sends it to on the private interface. There are no ACLS on ASA that block this, it comes in on private and is routed back on private
I just figured it out, I and 2 others have a static route and its the same as the one on ASA which means the ASA one doesnt work. The ASA private interface has no ACL, it has the
Any less secure networks
default setting.

Network Address          Netmask  Gateway Address  Metric       1

This does not explain why everyone can ping the CUE.
If the route was messed up even the pings should not find their way.

So back to your comment, how do I make outlook work with IP instead.
Or should I try to fix the ASA route so everyone can get to
baysysadminAuthor Commented:
The ASA route is definitively responsible for making the pings work.
I removed it and pings stopped.
But i cant find anything blocking http access to CUE.
Packet tracer on ASA shows all green.
Your setup seems strange that you would have the ASA between your UC520 and your phones.

What are the IPS on your PCs?
baysysadminAuthor Commented:
No the ASA is not between the phones and UC, its between the LAN and UC
Phones are on another local switch directly connected to UC.

I would have connected the PC LAN to the WAN portion of the UC520.

Try the following if you can, create another network on the ASA.  Connect that to the WAN Port of the UC520.

On the ASA setup the acl/routes for this new segment and then use it as the IMAP access point.  See whether that makes a difference.

how many active interfaces does your UC520 have. only the FA0/1/8?
it is a 10/100 line and is VLANed and prioritized using QoS voice over data.
Do you have an option to setup cacti ( snmp polling of the UC560's network usage of FA0/1/8 interface to make sure it is not being saturated?)
baysysadminAuthor Commented:
Hi I hope someone is still watchiing this thread.
I ran into a issue with connecitng IMAP with outlook 2013.
In this case we use a fake outgoing server because we are only recieveing messages from the phone system, not sending but outlook 2013 requires a valid outgoing server so it cant send a test message.
Without it the test fails and it wont let you add the account to outlook.

How do you get around this?
arnoldConnect With a Mentor Commented:
You setup a local SMTP (IIS SMTP) or point the outgoing server settings to an email provider that you have.

I.e. incoming IMAP type uc520.yourdomain.local
Outgoing SMTP
