8-6
ASDM configuration guide
Chapter8 Using the Cisco Unified Communication Wizard
Configuring the Phone Proxy by using the Unified Communication Wizard
Step2 Specify each entity in the network (all Cisco UCM and TFTP servers) that the IP phones must trust. Click
Add to add the servers. See Configuring Servers for the Phone Proxy, page8-6.
To modify the configuration of a server already added to the configuration, select the server in the table
and click Edit. The Edit Server dialog appears. See Configuring Servers for the Phone Proxy, page8-6.
At least one Cisco UCM and at least one TFTP server must be configured for the phone proxy.
Step3 Specify the security mode of the Cisco UCM cluster by clicking one of the following options in the
Unified CM Cluster Mode field:
Non-secure—Specifies the cluster to be in nonsecure mode when configuring the Phone Proxy
feature.
Mixed—Specifies the cluster to be in mixed mode when configuring the Phone Proxy feature.
If you selected the Mixed security mode, the Generate and Export LDC Certificate button becomes
available.
Step4 For a Mixed security mode only, configure local dynamic certificates (LDC) for the IP phones by
performing the following steps:
a. Click the Generate and Export LDC Certificate button.
A dialog box appears stating “Enrollment succeeded,” which indicates that the LDC was generated.
b. Click OK to close the Enrollment Status dialog box. The Export certificate dialog box appears.
c. In the Export to File field, enter the file name and path for the LDC or click browse to locate and
select an existing file.
d. Click the Export Certificate button. A dialog box appears indicating that the file was exported
successfully.
e. Click OK to close the dialog box. A dialog box appears reminding you to install the LDC on the
Cisco UCMs.
f. Click OK to close the dialog box.
Once configured, the ASA presents this unique, dynamically-created certificate to the Cisco UCM
on behalf of the IP phones.
Step5 Click Next.
Configuring Servers for the Phone Proxy
The values that you specify in this page generate address translation settings, access list entries,
trustpoints, and the corresponding CTL file entries for each server.
You must add a server for each entity in the network that the IP phones must trust. These servers include
all Cisco UCM servers in the cluster and all the TFTP servers.
You must add at least one TFTP server and at least one Cisco UCM server for the phone proxy. You can
configure up to five TFTP servers for the phone proxy. The TFTP server is assumed to be behind the
firewall on the trusted network; therefore, the phone proxy intercepts the requests between the IP phones
and TFTP server.
The servers that the IP phones must trust can be deployed on the network in one of the following ways: