Contents
xxxv
Cisco ASA 5500 Series Configuration Guide using the CLI
Phone Proxy Guidelines and Limitations 48-12
General Guidelines and Limitations 48-13
Media Termination Address Guidelines and Limitations 48-14
Configuring the Phone Proxy 48-14
Task Flow for Configuring the Phone Proxy in a Non-secure Cisco UCM Cluster 48-15
Importing Certificates from the Cisco UCM 48-15
Task Flow for Configuring the Phone Proxy in a Mixed-mode Cisco UCM Cluster 48-17
Creating Trustpoints and Generating Certificates 48-17
Creating the CTL File 48-18
Using an Existing CTL File 48-20
Creating the TLS Proxy Instance for a Non-secure Cisco UCM Cluster 48-20
Creating the TLS Proxy for a Mixed-mode Cisco UCM Cluster 48-21
Creating the Media Termination Instance 48-22
Creating the Phone Proxy Instance 48-23
Enabling the Phone Proxy with SIP and Skinny Inspection 48-25
Configuring Linksys Routers with UDP Port Forwarding for the Phone Proxy 48-26
Configuring Your Router 48-27
Troubleshooting the Phone Proxy 48-27
Debugging Information from the Security Appliance 48-27
Debugging Information from IP Phones 48-31
IP Phone Registration Failure 48-32
TFTP Auth Error Displays on IP Phone Console 48-32
Configuration File Parsing Error 48-33
Configuration File Parsing Error: Unable to Get DNS Response 48-33
Non-configuration File Parsing Error 48-34
Cisco UCM Does Not Respond to TFTP Request for Configuration File 48-34
IP Phone Does Not Respond After the Security Appliance Sends TFTP Data 48-35
IP Phone Requesting Unsigned File Error 48-36
IP Phone Unable to Download CTL File 48-36
IP Phone Registration Failure from Signaling Connections 48-37
SSL Handshake Failure 48-39
Certificate Validation Errors 48-40
Media Termination Address Errors 48-40
Audio Problems with IP Phones 48-41
Saving SAST Keys 48-41
Configuration Examples for the Phone Proxy 48-43
Example 1: Nonsecure Cisco UCM cluster, Cisco UCM and TFTP Server on Publisher 48-43
Example 2: Mixed-mode Cisco UCM cluster, Cisco UCM and TFTP Server on Publisher 48-45
Example 3: Mixed-mode Cisco UCM cluster, Cisco UCM and TFTP Server on Different Servers 48-46