cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1654
Views
0
Helpful
4
Replies

ASA Phone Proxy Troubleshooting

s.sitthichai
Level 1
Level 1

I would like to config Phone Proxy on Cisco ASA 5510 for remote IP Phone 7962G but cannot register to CUCM.

My information are

- ASA Version 8.2(1)

- UC Phone Proxy Sessions : 2

- Phone obtains an ip address from the DHCP

- Phone installed MIC

- CTL file not installed

- Phone fix ip TFTP to the global address of the tftp server as defined in the  NAT static

CUCM ----- core switch ----------- ASA ----------- internet ------------remote IP Phone

I see status messages on Phone is "Trust List Updated"

I try to debug command "debug phone-proxy" but it will display about only TFTP.

PP: 58.9.137.20/51333 requesting ITLSEPFCFBFB11B4DC.tlv from 10.1.101.2/69

PP: opened 0x5a975922

PP: 58.9.137.20/50140 requesting SEPFCFBFB11B4DC.cnf.xml.sgn from 10.1.101.2/69

PP: opened 0x5cbe2c66

PP: Received Data Block 1 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 1

PP: Acked Block #1 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 2 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 2

PP: Acked Block #2 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 3 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 3

PP: Acked Block #3 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 4 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 4

PP: Acked Block #4 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 5 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 5

PP: Acked Block #5 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 6 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 6

PP: Acked Block #6 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 7 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 7

PP: Acked Block #7 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 8 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 8

PP: Acked Block #8 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 9 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 9

PP: Acked Block #9 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 10 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 10

PP: Acked Block #10 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 11 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 11

PP: Acked Block #11 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 12 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 12

PP: Acked Block #12 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 13 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 13

PP: Acked Block #13 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 14 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 14

PP: Acked Block #14 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Received Data Block 15 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140

        Received Block 15

PP: Acked Block #15 from 58.9.137.20/50140 to 10.1.101.2/54331

PP: Modifying to encrypted mode.

PP: Modifying to TLS as the transport layer protocol.

PP: Data Block 1 forwarded from Outside-CallManager/54331 to 58.9.137.20/50140

PP: Received ACK Block 1 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 2 forwarded to 58.9.137.20/50140

PP: Received ACK Block 2 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 3 forwarded to 58.9.137.20/50140

PP: Received ACK Block 3 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 4 forwarded to 58.9.137.20/50140

PP: Received ACK Block 4 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 5 forwarded to 58.9.137.20/50140

PP: Received ACK Block 5 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 6 forwarded to 58.9.137.20/50140

PP: Received ACK Block 6 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 7 forwarded to 58.9.137.20/50140

PP: Received ACK Block 7 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 8 forwarded to 58.9.137.20/50140

PP: Received ACK Block 8 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 9 forwarded to 58.9.137.20/50140

PP: Received ACK Block 9 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 10 forwarded to 58.9.137.20/50140

PP: Received ACK Block 10 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 11 forwarded to 58.9.137.20/50140

PP: Received ACK Block 11 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 12 forwarded to 58.9.137.20/50140

PP: Received ACK Block 12 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 13 forwarded to 58.9.137.20/50140

PP: Received ACK Block 13 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 14 forwarded to 58.9.137.20/50140

PP: Received ACK Block 14 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 15 forwarded to 58.9.137.20/50140

PP: Received ACK Block 15 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: Data Block 16 forwarded to 58.9.137.20/50140

PP: Received ACK Block 16 from outside:58.9.137.20/50140 to inside:10.1.101.2

PP: TFTP session complete, all data sent

# show phone-proxy secure-phones

ASA-phone-proxy: 1 in use, 2 most used

           Interface      IP Address  Port MAC            Timeout Idle

             outside     58.9.137.20     0 fcfb.fb11.b4dc 0:05:00 0:01:59

4 Replies 4

s.sitthichai
Level 1
Level 1

I'm not sure what is the problem because I think TFTP session complete but cannot register to CUCM

Please see the attached for diagram and running-config.  Thank you for picture from here.

Phone proxy.jpg

Can anyone advise me for this case ?

Thank you very much.

Hi Sitthichai Sornsuwan ,

I have configured the same setup .

Received Data Block 2 from inside:10.1.101.2/54331 to outside:58.9.137.20/50140.

Means you are getting the response on asa . request is coming & it is getting natted.

It is very good news . Please share some details of asa configuration .

For more details you can send the mail .

Thanks & Regards

Vishal thakur

vishlthakur88@gmail.com

9871854195

Thank you very much.

But I think my problem is ASA phone proxy doesn't support CUCM 8.x

Review Cisco Networking products for a $25 gift card