Cisco ASA 5505 Configuration Manual page 957

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Chapter 43
Configuring the Cisco Phone Proxy
DNS Lookup Prerequisites
Cisco Unified Communications Manager Prerequisites
Access List Rules
If the phone proxy is deployed behind an existing firewall, access-list rules to permit signaling, TFTP
requests, and media traffic to the phone proxy must be configured.
If NAT is configured for the TFTP server or Cisco UCMs, the translated "global" address must be used
in the access lists.
Table 43-1
Table 43-1
Address
Media Termination
TFTP Server
Cisco UCM
Cisco UCM
CAPF Service (on Cisco
UCM)
Note
OL-20339-01
If you have an fully qualified domain name (FQDN) configured for the Cisco UCM rather than an
IP address, you must configure and enable DNS lookup on the adaptive security appliance.
After configuring the DNS lookup, make sure that the adaptive security appliance can ping the Cisco
UCM with the configured FQDN.
You must configure DNS lookup when you have a CAPF service enabled and the Cisco UCM is not
running on the Publisher but the Publisher is configured with a FQDN instead of an IP address.
The TFTP server must reside on the same interface as the Cisco UCM.
The Cisco UCM can be on a private network on the inside but you need to have a static mapping for
the Cisco UCM on the adaptive security appliance to a public routable address.
If NAT is required for Cisco UCM, it must be configured on the adaptive security appliance, not on
the existing firewall.
lists the ports that are required to be configured on the existing firewall:
Port Configuration Requirements
Port
1024-65535
69
2443
5061
3804
All these ports are configurable on the Cisco UCM, except for TFTP. These are the default
values and should be modified if they are modified on the Cisco UCM. For example, 3804 is the
default port for the CAPF Service. This default value should be modified if it is modified on the
Cisco UCM.
Protocol
UDP
UDP
TCP
TCP
TCP
Cisco ASA 5500 Series Configuration Guide using ASDM
Prerequisites for the Phone Proxy
Description
Allow incoming SRTP
Allow incoming TFTP
Allow incoming secure
SCCP
Allow incoming secure
SIP
Allow CAPF service for
LSC provisioning
43-7

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents