53-7
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter53 Configuring the TLS Proxy for Encrypted Voice Inspection
CTL Provider
Parse the CTL file provided by the CTL Client and install trustpoints—Trustpoints installed by
this option have names prefixed with “_internal_CTL_.” If disabled, each Call Manager server
and CAPF certificate must be manually imported and installed.
Port Number—Specifies the port to which the CTL provider listens. The port must be the same
as the one listened to by the CallManager servers in the cluster (as configured under Enterprise
Parameters on the CallManager administration page). The default is 2444.
Authentication—Specifies the username and password that the client authenticates with the
provider.
Username—Client username.
Password—Client password.
Confirm Password—Client password.
Modes
The following table shows the modes in which this feature is available:
Configure TLS Proxy Pane
Note This feature is not supported for the Adaptive Security Appliance version 8.1.2.
You can configure the TLS Proxy from the Configuration > Firewall > Unified Communications > TLS
Proxy pane.
Configuring a TLS Proxy lets you use the TLS Proxy to enable inspection of SSL encrypted VoIP
signaling, namely Skinny and SIP, interacting with Cisco Call Manager and enable the ASA for the Cisco
Unified Communications features:
TLS Proxy for the Cisco Unified Presence Server (CUPS), part of Presence Federation
TLS Proxy for the Cisco Unified Mobility Advantage (CUMA) server, part of Mobile Advantage
Phone Proxy
Fields
TLS Proxy Name—Lists the TLS Proxy name.
Server Proxy Certificate—Lists the trustpoint, which is either self-signed or enrolled with a
certificate server.
Local Dynamic Certificate Issuer—Lists the local certificate authority to issue client or server
dynamic certificates.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
••••