<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One way audio for phones using IP Proxy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670248#M561193</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check and make sure that the ip address range for proxy phone are not blocked in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Jun 2011 15:59:34 GMT</pubDate>
    <dc:creator>phamvinhdat</dc:creator>
    <dc:date>2011-06-06T15:59:34Z</dc:date>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670247#M561189</link>
      <description>&lt;P&gt;I've got an ASA 5505 running 8.2 configured for solely as an IP phone proxy, it is the default gateway for the cucm box and PRI router, its inside interface is directly attached to the same subnet as all internal phones as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Calls can be placed from either end, but after call is established, proxy phones does not hear audio from internal or pstn phones. The proxy phone registers with cucm with the remote internal IP of the phone that obviously cannot be reached by corp network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debugging from pri router shows the rtp traffic destination is the internal ip address of the proxy phone 192.168.0.50, why is the phone registering with its internal IP 192.168.0.50 rather than its Natted external IP 50.50.50.50 that can be reachable by cucm and other phones?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Proxy phone is a 7945, after it registers, I do not see it under &lt;SPAN style="font-family: courier new,courier;"&gt;sh phone-proxy secure-phones&lt;/SPAN&gt;, or &lt;SPAN style="font-family: courier new,courier;"&gt;sh phone-proxy signaling-sessions &lt;/SPAN&gt;while on a call.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Proxy config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;switchport access vlan 2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/6&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Ethernet0/7&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Vlan1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;nameif inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;security-level 100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ip address 10.10.33.25 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Vlan2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;nameif outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;security-level 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ip address 65.x.x.24 255.255.254.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;boot system disk0:/asa823-k8.bin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ftp mode passive&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;dns server-group DefaultDNS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;domain-name ----.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;same-security-traffic permit intra-interface&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_access_in extended permit ip host 10.10.33.10 any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_access_in extended permit ip any host 10.10.33.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_access_in extended permit ip host 10.10.33.5 any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_access_in extended permit ip any any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list outside_access_in extended permit udp any host 65.x.x.25 eq tftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list outside_access_in extended permit udp any host 65.x.x.25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list outside_access_in extended permit icmp any interface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list outside_access_in extended permit ip any host 65.x.x.25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list outside_access_in extended permit ip any host 10.10.33.5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_nat0_outbound extended permit ip host 10.10.33.10 10.10.0.0 255.255.0.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_nat0_outbound extended permit ip host 10.10.33.10 204.x.x.0 255.255.254.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_nat0_outbound extended permit ip host 10.10.33.5 10.10.0.0 255.255.0.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-list inside_nat0_outbound extended permit ip host 10.10.33.5 204.x.x.0 255.255.254.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;pager lines 24&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;logging enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;logging timestamp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;logging console informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;logging buffered notifications&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;logging asdm informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;mtu inside 1500&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;mtu outside 1500&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;asdm image disk0:/asdm-634-53.bin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no asdm history enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;arp timeout 14400&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;global (outside) 1 interface&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;nat (inside) 1 10.10.33.0 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;static (inside,outside) 65.x.x.25 10.10.33.10 netmask 255.255.255.255&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-group inside_access_in in interface inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;access-group outside_access_in in interface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;route outside 0.0.0.0 0.0.0.0 65.x.x.240 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;route inside 10.0.0.0 255.0.0.0 10.10.33.1 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;route inside 204.x.x.0 255.255.254.0 10.10.33.1 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout xlate 3:00:00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;aaa authentication ssh console LOCAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;http server enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no snmp-server location&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no snmp-server contact&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ipsec security-association lifetime seconds 28800&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint phoneproxy_trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair proxy_key&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint capf_trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint CAP-RTP-001&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint CAP-RTP-002&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint Cisco_Manufacturing_CA_Trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint CAP-RTP-001_trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no client-types&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint CAP-RTP-002_trustpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment terminal&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no client-types&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_ctl_phoneproxy_file_SAST_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_ctl_phoneproxy_file_SAST_0";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_ctl_phoneproxy_file_SAST_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_ctl_phoneproxy_file_SAST_1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_ctl_phoneproxy_file_SAST_1";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_ctl_phoneproxy_file_SAST_1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_PP_ctl_phoneproxy_file&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_PP_ctl_phoneproxy_file";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_PP_ctl_phoneproxy_file&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint cucm_tftp_server_tp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;serial-number&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair cucmtftp_kp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_asactl_SAST_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_asactl_SAST_0";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_asactl_SAST_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_asactl_SAST_1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_asactl_SAST_1";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_asactl_SAST_1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crypto ca trustpoint _internal_PP_asactl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;enrollment self&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;fqdn none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;subject-name cn="_internal_PP_asactl";ou="STG";o="Cisco Inc"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;keypair _internal_PP_asactl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crl configure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;.......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;certs emitted&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;.......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;telnet timeout 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ssh timeout 10&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ssh version 2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;console timeout 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;tls-proxy asatlsp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;server trust-point _internal_PP_asactl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ctl-file asactl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;record-entry cucm-tftp trustpoint cucm_tftp_server_tp address 65.x.x.25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no shutdown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;media-termination asdm_media_termination&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;address 10.10.33.26 interface inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;address 65.x.x.26 interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;phone-proxy asdm_phone_proxy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;media-termination asdm_media_termination&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;tftp-server address 10.10.33.10 interface inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;tls-proxy asatlsp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;cipc security-mode authenticated&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;ctl-file asactl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no disable service-settings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;threat-detection basic-threat&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;threat-detection statistics access-list&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;no threat-detection statistics tcp-intercept&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;webvpn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;username admin password xxxxxxxxxx encrypted&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map sec-sccp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match port tcp eq 2334&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match default-inspection-traffic&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map sec-sip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;match port tcp eq 5061&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map type inspect dns preset_dns_map&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;parameters&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; message-length maximum 512&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map pp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class sec-sip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect sip phone-proxy asdm_phone_proxy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class sec-sccp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect skinny phone-proxy asdm_phone_proxy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect ftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect h323 h225&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect h323 ras&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect rsh&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect rtsp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect esmtp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect sqlnet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect skinny&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect sunrpc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect xdmcp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect sip&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect netbios&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect tftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inspect ip-options&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;service-policy global_policy global&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;service-policy pp interface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;prompt hostname context&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Tarek&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670247#M561189</guid>
      <dc:creator>tarekaljallad</dc:creator>
      <dc:date>2019-03-11T20:42:41Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670248#M561193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check and make sure that the ip address range for proxy phone are not blocked in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 15:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670248#M561193</guid>
      <dc:creator>phamvinhdat</dc:creator>
      <dc:date>2011-06-06T15:59:34Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670249#M561197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; the proxy phone public IP is not blocked and can ping the ASA's outside interface, the Watchguard Firebox that is in front of the ASA is set to allow any any to the ASA IP, termination IP and NATted IP for TFTP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 16:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670249#M561197</guid>
      <dc:creator>tarekaljallad</dc:creator>
      <dc:date>2011-06-06T16:37:01Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670250#M561199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I had an issue similar to this when my ASA wasn't the default route to the internet from the LAN.&amp;nbsp; I had to do some reverse NATing to get packets from the internal phones to go back out through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 16:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670250#M561199</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2011-06-06T16:49:24Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670251#M561201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I thought the same thing, the PRI router's default route is to the ASA, and we have the same issue when calling external numbers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 16:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670251#M561201</guid>
      <dc:creator>tarekaljallad</dc:creator>
      <dc:date>2011-06-06T16:54:51Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670252#M561203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about all the phones?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 17:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670252#M561203</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2011-06-06T17:13:35Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670253#M561205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had intermittent one-way voice before on Phone Proxy. If you are 'always' getting one-way voice then you need to look at your&amp;nbsp; firewalls and routing as other folks in this post have suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For intermittent one-way voice on Phone Proxy, the one work around I found is to destroy/re-establish the RTP stream. The easiest way to do this is to place the call on hold and then pick it back up. Doing that should force the RTP stream to re-establish and two-way voice should be available. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It occured to me on some early versions of 8.2. You're config shows you are running 8.2(3) so be try running latest 8.2 code which was 8.2(5) as of this post.&amp;nbsp; That might just solve your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 17:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670253#M561205</guid>
      <dc:creator>Steven Griffin</dc:creator>
      <dc:date>2011-06-06T17:34:13Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670254#M561207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steve, is it expected though to see the internal IP address of the proxy phone registering with cm? I can't picture how phones can communicate with a proxy phone if its IP is not natted, thus making it unreachable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 18:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670254#M561207</guid>
      <dc:creator>tarekaljallad</dc:creator>
      <dc:date>2011-06-06T18:18:35Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670255#M561209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I moved this thread into the Firewalling space, since most of the phone-proxy related issues are raised here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you haven't already, please check out this document on troubleshooting and common issues with phone proxy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1226"&gt;https://supportforums.cisco.com/docs/DOC-1226&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already have per-interface MTA configured, so packet captures taken at the time you bring up a call would help determine if the voice traffic is reaching the ASA or not...we've seen bad routes or devices in the path blocking media traffic before it can reach the MTA interfaces of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet captures on ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 19:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670255#M561209</guid>
      <dc:creator>Jay Johnston</dc:creator>
      <dc:date>2011-06-06T19:31:53Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670256#M561211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Ok, did a packet capture on the ASA and saw what I expected, internal phone sends packets to real private IP of proxy phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 134: 10:20:05.889129 802.1Q vlan#1 P0 10.10.33.17.31540 &amp;gt; 192.168.1.26.27782:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 135: 10:20:05.889144 802.1Q vlan#2 P0 65.x.x.24.36960 &amp;gt; 192.168.1.26.27782:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 136: 10:20:05.890609 802.1Q vlan#2 P0 68.x.x.115.27782 &amp;gt; 65.x.x.24.36960:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 137: 10:20:05.890624 802.1Q vlan#1 P0 68.x.x.115.27782 &amp;gt; 10.10.33.17.31540:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 138: 10:20:05.908949 802.1Q vlan#2 P0 68.x.x.115.27782 &amp;gt; 65.123.205.24.36960:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 139: 10:20:05.908964 802.1Q vlan#1 P0 68.x.x.115.27782 &amp;gt; 10.10.33.17.31540:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 140: 10:20:05.910170 802.1Q vlan#1 P0 10.10.33.17.31540 &amp;gt; 192.168.1.26.27782:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 141: 10:20:05.910170 802.1Q vlan#2 P0 65.x.x.24.36960 &amp;gt; 192.168.1.26.27782:&amp;nbsp; udp 172&lt;/P&gt;&lt;P&gt; 142: 10:20:05.931180 802.1Q vlan#1 P0 10.10.33.17.31540 &amp;gt; 192.168.1.26.27782:&amp;nbsp; udp 172&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 13:45:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670256#M561211</guid>
      <dc:creator>tarekaljallad</dc:creator>
      <dc:date>2011-06-07T13:45:44Z</dc:date>
    </item>
    <item>
      <title>One way audio for phones using IP Proxy</title>
      <link>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670257#M561213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps the phone is not completely registered via phone proxy? It may be registered directly to the CUCM. What do you get when you run 'show phone-proxy secure-phones'? Also, what version are you running exactly? Did you upgrade to 8.2.5?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know you said you think there weren't any NAT/Routing issues since the ASA is the default gateway. You may want to add this config just in case. It will NAT inbound traffic to the IP of the ASA so traffic will be forced to return through the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PhoneProxyASA(config)# nat (outside) 55 0 0 outside&lt;/P&gt;&lt;P&gt;PhoneProxyASA(config)# global (inside) 55 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, have you tried reloading the ASA? And have you deleted the CTL file on the phone-proxy phone(s) after making changes to the ASA? How many Call Managers are in your cluster?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 14:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/one-way-audio-for-phones-using-ip-proxy/m-p/1670257#M561213</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-06-07T14:27:56Z</dc:date>
    </item>
  </channel>
</rss>

