Cisco Systems ASA 5580, ASA 5505, ASA 5545-X, ASA 5555-X, ASA 5585-X manual 16-22

Models: ASA 5555-X and the ASA Services Module ASA 5545-X ASA 5585-X ASA 5580 ASA 5505

1 712
Download 712 pages 25.77 Kb
Page 352
Image 352

Chapter 16 Configuring the Cisco Phone Proxy

Configuring the Phone Proxy

 

Command

Purpose

 

 

 

Step 6

hostname(config-ca-trustpoint)# subject-name

Includes the indicated subject DN in the certificate

 

X.500_name

during enrollment

 

Example:

Where the X.500_name is for the LDC.

 

hostname(config-ca-trustpoint)# subject-name

 

cn=FW_LDC_SIGNER_172_23_45_200

Use commas to separate attribute-value pairs. Insert

 

 

 

 

quotation marks around any value that contains

 

 

commas or spaces.

 

 

For example:

 

 

cn=crl,ou=certs,o="cisco systems, inc.",c=US

 

 

The maximum length is 500 characters.

 

 

 

Step 7

hostname(config-ca-trustpoint)# keypair keypair

Specifies the key pair whose public key is to be

 

Example:

certified.

 

hostname(config-ca-trustpoint)# keypair

Where the keypair is for the LDC.

 

ldc_signer_key

 

 

 

Step 8

hostname(config)# crypto ca enroll ldc_server

Starts the enrollment process with the CA.

 

Example:

 

 

hostname(config)# crypto ca enroll ldc_server

 

 

 

 

Step 9

hostname(config)# tls-proxyproxy_name

Creates the TLS proxy instance.

 

Example:

 

 

tls-proxy mytls

 

 

 

 

Step 10

hostname(config-tlsp)# server trust-point

Configures the server trustpoint and references the

 

_internal_PP_ctl-instance_filename

internal trustpoint named

 

Example:

_internal_PP_ctl-instance_filename.

 

hostname(config-tlsp)# server trust-point

 

 

 

_internal_PP_myctl

 

 

 

 

Step 11

hostname(config-tlsp)# client ldc issuer ca_tp_name

Specifies the local CA trustpoint to issue client

 

Example:

dynamic certificates.

 

client ldc issuer ldc_server

 

 

 

 

Step 12

hostname(config-tlsp)# client ldc keypair key_label

Specifies the RSA keypair to be used by client

 

Example:

dynamic certificates.

 

hostname(config-tlsp)# client ldc keypair

 

 

phone_common

 

 

 

 

Step 13

hostname(config-tlsp)# client cipher-suite

Specifies the cipher suite.

 

cipher-suite

Options include des-sha1, 3des-sha1, aes128-sha1,

 

Example:

 

hostname(config-tlsp)# client cipher-suite

aes256-sha1, or null-sha1.

 

aes128-sha1 aes256-sha1

 

 

 

 

Step 14

 

Exports the local CA certificate and installs it as a

 

 

trusted certificate on the Cisco Unified

 

 

Communications Manager server by performing one

 

 

of the following actions.

 

 

 

Cisco ASA Series Firewall CLI Configuration Guide

16-22

Page 352
Image 352
Cisco Systems ASA 5580, ASA 5505, ASA 5545-X, ASA 5555-X, ASA 5585-X, and the ASA Services Module manual 16-22