Cisco ASA 5505 User Manual

Page 1029

Advertising
background image

48-47

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 48 Configuring the Cisco Phone Proxy

Configuration Examples for the Phone Proxy

host 192.0.2.101

nat (inside,outside) static interface udp 69 69

access-list pp extended permit udp any host 10.10.0.24 eq 69

access-group pp in interface outside

crypto key generate rsa label cucm_kp modulus 1024

crypto ca trustpoint cucm

enrollment self

keypair cucm_kp

crypto ca enroll cucm

crypto key generate rsa label tftp_kp modulus 1024

crypto ca trustpoint tftp_server

enrollment self

keypair tftp_kp

crypto ca enroll tftp_server

ctl-file myctl

record-entry cucm trustpoint cucm_server address 10.10.0.26

no shutdown

crypto key generate rsa label ldc_signer_key modulus 1024

crypto key generate rsa label phone_common modulus 1024

crypto ca trustpoint ldc_server

enrollment self

proxy_ldc_issuer

fqdn my-ldc-ca.exmaple.com

subject-name cn=FW_LDC_SIGNER_172_23_45_200

keypair ldc_signer_key

crypto ca enroll ldc_server

tls-proxy my_proxy

server trust-point _internal_PP_myctl

client ldc issuer ldc_server

client ldc keypair phone_common

client cipher-suite aes128-sha1 aes256-sha1

media-termination my_mediaterm

address 192.0.2.25 interface inside

address 10.10.0.25 interface outside

phone-proxy mypp

media-termination my_mediaterm

tftp-server address 192.0.2.101 interface inside

tls-proxy mytls

ctl-file myctl

cluster-mode mixed

class-map sec_sccp

match port tcp 2443

class-map sec_sip

match port tcp eq 5061

policy-map pp_policy

class sec_sccp

inspect skinny phone-proxy mypp

class sec_sip

inspect sip phone-proxy mypp

service-policy pp_policy interface outside

Example 4: Mixed-mode Cisco UCM cluster, Primary Cisco UCM, Secondary
and TFTP Server on Different Servers

Figure 48-5

shows an example of the configuration for a mixed-mode Cisco UCM cluster using the

following topology where the TFTP server resides on a different server from the primary and secondary
Cisco UCMs.

In this sample, the static interface PAT for the TFTP server is configured to appear like the ASA’s outside
interface IP address.

Advertising