Cisco Systems OL-24124-01 manual Supported Devices, Configuring the VPN Feature, 17-1

Page 1

C H A P T E R 17

Configuring Virtual Private Networks

The Cisco VPN Client for Cisco Unified IP Phones adds another option for customers attempting to solve the remote telecommuter problem by complementing other Cisco remote telecommuting offerings.

Easy to DeployAll settings configured via CUCM administration.

Easy to UseAfter configuring the phone within the Enterprise, the user can take it home and plug it into their broadband router for instant connectivity, without any difficult menus to configure.

Easy to Manage—Phone can receive firmware updates and configuration changes remotely.

Secure—VPN tunnel only applies to voice and Cisco Unified IP Phone services. A PC connected to the PC port is responsible for authenticating and establishing it own tunnel with VPN client software.

Supported Devices

You can use Cisco Unified Reporting to determine which Cisco Unified IP Phones support the VPN client. From Cisco Unified Reporting, click Unified CM Phone Feature List. For the Feature, choose Virtual Private Network Client from the pull-down menu. The system displays a list of products that support the feature.

For more information about using Cisco Unified Reporting, see the Cisco Unified Reporting

Administration Guide.

Configuring the VPN Feature

To configure the VPN feature for supported Cisco Unified IP Phones, follow the steps in the following table.

Note The IP Phone VPN requires both TCP and UDP port 443 enabled to successfully build the VPN tunnel.

 

 

Cisco Unified Communications Manager Security Guide

 

 

 

 

 

 

 

OL-24124-01

 

 

17-1

 

 

 

 

 

Image 1
Contents Supported Devices Configuring the VPN Feature17-1 17-2 Configuration StepsConfiguring IOS for VPN client on IP phone IOS configuration requirements17-3 17-4 Routerconfig# ip route destip mask gatewayip17-5 Sample IOS configuration summaryAaa new-model 17-6Hidekeys 17-717-8 Configuring ASA for VPN client on IP phone ASA configuration requirements17-9 17-10 17-11 Sample ASA configuration summarySame-security-traffic permit inter-interface 17-1217-13 Svc rekey time 17-1417-15 17-16