20-10
Cisco ASA Series Firewall CLI Configuration Guide
Chapter20 Configuring Cisco Intercompany Media E ngine Proxy
Configuring Cisco Intercompany Media Engine Proxy
Assume for example, the ASA is configured to have a maximum of 100 TLS proxy sessions and IME
calls between SCCP IP phones establish 101 TLS proxy sessions. In this example, the next IME call
is initiated successfully by the originating SCCP IP phone but fails after the call is accepted by the
terminating SCCP IP phone. The terminating IP phone rings and on answering the call, the call
hangs due to an incomplete TLS handshake. The call does not fall back to the PSTN.
Configuring Cisco Intercompany Media Engine Proxy
This section contains the following topics:
Task Flow for Configuring Cisco Intercompany Media Engine, page20-10
Configuring NAT for Cisco Intercompany Media Engine Proxy, page 20-11
Configuring PAT for the Cisco UCM Server, page 20-13
Creating ACLs for Cisco Intercompany Media Engine Proxy, page20-15
Creating the Media Termination Instance, page20-16
Creating the Cisco Intercompany Media Engine Proxy, page20-17
Creating Trustpoints and Generating Certificates, page20-20
Creating the TLS Proxy, page20-23
Enabling SIP Inspection for the Cisco Intercompany Media Engine Proxy, page20-24
(Optional) Configuring TLS within the Local Enterprise, page20-26
(Optional) Configuring Off Path Signaling, page20-29

Task Flow for Configuring Cisco Intercompany Media Engine

Figure 20-5 provides an example for a basic deployment of the Cisco Intercompany Media Engine. The
following tasks include command line examples based on Figure20-5.
Figure20-5 Example for Basic (in-line) Deployment Tasks
Internet
Remote Enterprise
Local
Cisco UCMs
Local ASA
Corporate
Network
Remote
Cisco UCM
Remote ASA
Local Enterprise
IP
IP
IP
192.168.10.30
192.168.10.31
192.168.10.12
ASA inside
interface
192.168.10.1
Inside media
termination
192.168.10.3
Outside media termination
209.165.200.226
Outside Cisco UMC
209.165.200.228
TLS
TCP
248764
Local
UC-IME
Server Remote
UC-IME
Server
M

M

UC-IME
Bootstrap
Server
ASA outside interface
209.165.200.225

M