EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition Configuration Guide

Cisco 5510 - ASA SSL / IPsec VPN Edition
1822 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #957 background imageLoading...
Page #957 background image
43-7
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 43 Configuring the Cisco Phone Proxy
Prerequisites for the Phone Proxy
DNS Lookup Prerequisites
If you have an fully qualified domain name (FQDN) configured for the Cisco UCM rather than an
IP address, you must configure and enable DNS lookup on the adaptive security appliance.
After configuring the DNS lookup, make sure that the adaptive security appliance can ping the Cisco
UCM with the configured FQDN.
You must configure DNS lookup when you have a CAPF service enabled and the Cisco UCM is not
running on the Publisher but the Publisher is configured with a FQDN instead of an IP address.
Cisco Unified Communications Manager Prerequisites
The TFTP server must reside on the same interface as the Cisco UCM.
The Cisco UCM can be on a private network on the inside but you need to have a static mapping for
the Cisco UCM on the adaptive security appliance to a public routable address.
If NAT is required for Cisco UCM, it must be configured on the adaptive security appliance, not on
the existing firewall.
Access List Rules
If the phone proxy is deployed behind an existing firewall, access-list rules to permit signaling, TFTP
requests, and media traffic to the phone proxy must be configured.
If NAT is configured for the TFTP server or Cisco UCMs, the translated “global” address must be used
in the access lists.
Table 43-1 lists the ports that are required to be configured on the existing firewall:
Note All these ports are configurable on the Cisco UCM, except for TFTP. These are the default
values and should be modified if they are modified on the Cisco UCM. For example, 3804 is the
default port for the CAPF Service. This default value should be modified if it is modified on the
Cisco UCM.
Table 43-1 Port Configuration Requirements
Address Port Protocol Description
Media Termination 1024-65535 UDP Allow incoming SRTP
TFTP Server 69 UDP Allow incoming TFTP
Cisco UCM 2443 TCP Allow incoming secure
SCCP
Cisco UCM 5061 TCP Allow incoming secure
SIP
CAPF Service (on Cisco
UCM)
3804 TCP Allow CAPF service for
LSC provisioning

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals