53-8
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter53 Configuring the TLS Proxy for Encrypted Voice Inspe ction
CTL Provider
Client Proxy Certificate—Lists the proxy certificate for the TLS client. The ASA uses the client
proxy certificate to authenticate the TLS client during the handshake between the proxy and the TLS
client. The certificate can be either self-signed, enrolled with a certificate authority, o r issu ed by t he
third party.
Add—Adds a TLS Proxy by launching the Add TLS Proxy Instance Wizard. See Adding a TLS
Proxy Instance, page 53-8 for the steps to create a TLS Proxy instance.
Edit—Edits a TLS Proxy. The fields in the Edit panel area identical to the fields displayed when you
add a TLS Proxy instance. See Edit TLS Proxy Instance – Server Configuration, page53-13 and Edit
TLS Proxy Instance – Client Configuration, page53-14.
Delete—Deletes a TLS Proxy.
Maximum Sessions—Lets you specify the maximum number of TLS Proxy sessions to support.
Specify the maximum number of TLS Proxy sessions that the ASA needs to support.
Maximum number of sessions—The minimum is 1. The maximum is dependent on the platform:
Cisco ASA 5505 security appliance: 10
Cisco ASA 5510 security appliance: 100
Cisco ASA 5520 security appliance: 300
Cisco ASA 5540 security appliance: 1000
Cisco ASA 5550 security appliance: 2000
Cisco ASA 5580 security appliance: 4000
Note The maximum number of sessions is global to all TLS proxy sessions.
Modes
The following table shows the modes in which this feature is available:
Adding a TLS Proxy Instance
Note This feature is not supported for the Adaptive Security Appliance version 8.1.2.
Use the Add TLS Proxy Instance Wizard to add a TLS Proxy to enable inspection of SSL encrypted VoIP
signaling, namely Skinny and SIP, interacting with Cisco Call Manager and to support the Cisco Unified
Communications features on the ASA.
This wizard is available from the Configuration > Firewall > Unified Communications > TLS Proxy
pane.
Step1 Open the Configuration > Firewall > Unified Communications > TLS Proxy pane.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
••••