Troubleshooting Cisco Unified Ip Phone Security - Cisco 7940 - IP Phone VoIP Administration Manual

Unified ip phone cisco unified communications manager 7.0 (sccp)
Hide thumbs Also See for 7940 - IP Phone VoIP:
Table of Contents

Advertisement

Chapter 8
Troubleshooting and Maintenance

Troubleshooting Cisco Unified IP Phone Security

Table 8-1
For information relating to the solutions for any of these issues, and for additional troubleshooting
information about security and encryption, refer to Cisco Unified Communications Manager Security
Guide.
Because third-party troubleshooting tools that sniff media and TCP packets do not work after you enable
encryption, you must use Cisco Unified Communications Manager Administration to perform the
following tasks if a problem occurs:
Table 8-1
Cisco Unified IP Phone Security Troubleshooting
Problem
LSC fails on the phone.
Device authentication error.
Phone cannot authenticate CTL file. The security token that signed the updated CTL file does not exist in the CTL file on
Phone cannot authenticate any of the
configuration files other than the
CTL file.
Phone reports TFTP authorization
failure.
Phone does not register with Cisco
Unified Communications Manager.
Phone does not interact with the
correct CAPF server to obtain the
locally-significant certificate.
Phone does not request signed
configuration files.
Cisco Unified IP Phone 7960G/7940G Administration Guide for Cisco Unified Communications Manager 7.0 (SCCP)
OL-15498-01
provides troubleshooting information for the security features on the Cisco Unified IP Phone.
Analyze TCP packets for SCCP messages that are exchanged between
Cisco Unified Communications Manager and the device
Extract the media encryption key material from SCCP messages and decrypt the media between the
devices
Possible Cause
CAPF configuration error.
CTL file does not have a Cisco Unified Communications Manager certificate or has an
incorrect certificate.
the phone.
Bad TFTP record.
The TFTP address for the phone does not exist in the CTL file.
If you created a new CTL file with a new TFTP record, the existing CTL file on the
phone may not contain a record for the new TFTP server.
The CTL file does not contain the correct information for the Cisco
Unified Communications Manager server.
The CAPF utility runs on a different workstation/server than is specified in the CTL
file.
The CAPF certificate has changed since the last update of the CTL file.
The CTL file does not contain any TFTP server entry.
The CTL file does not contain any TFTP entries with certificates
Troubleshooting Cisco Unified IP Phone Security
8-9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents