Download Print this page

Cisco ASA 5506-X Configuration Manual page 228

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Skinny (SCCP) Inspection
If you are editing an existing service policy (such as the default global policy called global_policy), you
Step 5
are done. Otherwise, activate the policy map on one or more interfaces.
service-policy policymap_name {global | interface interface_name}
Example:
hostname(config)# service-policy global_policy global
The global keyword applies the policy map to all interfaces, and interface applies the policy to one
interface. Only one global policy is allowed. You can override the global policy on an interface by
applying a service policy to that interface. You can only apply one policy map to each interface.
Verifying and Monitoring SCCP Inspection
The show skinny command assists in troubleshooting SCCP (Skinny) inspection engine issues. The
following is sample output from the show skinny command under the following conditions. There are
two active Skinny sessions set up across the ASA. The first one is established between an internal Cisco
IP Phone at local address 10.0.0.11 and an external Cisco CallManager at 172.18.1.33. TCP port 2000
is the CallManager. The second one is established between another internal Cisco IP Phone at local
address 10.0.0.22 and the same Cisco CallManager.
hostname# show skinny
---------------------------------------------------------------
1
MEDIA 10.0.0.11/22948
2
MEDIA 10.0.0.22/20798
The output indicates that a call has been established between two internal Cisco IP Phones. The RTP
listening ports of the first and second phones are UDP 22948 and 20798 respectively.
The following is sample output from the show xlate debug command for these Skinny connections:
hostname# show xlate debug
2 in use, 2 most used
Flags:
NAT from inside:10.0.0.11 to outside:172.18.1.11 flags si idle 0:00:16 timeout 0:05:00
NAT from inside:10.0.0.22 to outside:172.18.1.22 flags si idle 0:00:14 timeout 0:05:00
Cisco ASA Series Firewall CLI Configuration Guide
8-36
LOCAL
10.0.0.11/52238
10.0.0.22/52232
D - DNS, d - dump, I - identity, i - inside, n - no random,
r - portmap, s - static
Chapter 8
FOREIGN
172.18.1.33/2000
172.18.1.22/20798
172.18.1.33/2000
172.18.1.11/22948
Inspection for Voice and Video Protocols
STATE
1
1

Hide quick links:

Advertisement

loading