11-05-2008 05:38 AM - edited 03-18-2019 09:55 PM
Hey guys,
We have CCM v4.1.3 and ASA 8.0(4) and are looking to implement (or attempt) Phone proxy/TLS proxy. Essentially we'd like to know if anyone has "successfully" deployed TLS proxy/phone proxy through the ASA v8 to CCM v4.1.3 or do we need to upgrade to a later version of CCM?
Any info, gotcha's etc much appreciated.
Pete
11-07-2008 06:53 AM
Ok we have deployed the config on to the ASA 8.0(4) hardware but the certificate install onto CCM4 is problematic. The documentation I am using for the config is using CCM6 and the options for installing the certificate are nowhere to be seen in CCM4.
Anyone configured this with CCM4 or am I wasting my time with this version of CCM?
Any help appreciated guys.
Pete
11-14-2008 07:27 AM
I'm in the same boat as you. Which documentation are you following?
11-14-2008 07:40 AM
I've been using the following white paper:
http://www.cisco.com/en/US/solutions/collateral/ns340/ns394/ns165/ns391/white_paper_c11-493584.html
It's not specific to CCM 4 but I don't have much in the way of documentation for this specific setup from what I've searched thus far.
I've configured our test CUCM6 server and now have the issue with the CTL client install asking for a usb secure token, a token we don't actually have and have never created or requested.
I'l let you know if I get any further.
Pete
11-23-2008 11:28 AM
11-29-2008 08:50 AM
So did you get it to work with this document on cm 4 1 3
did you load any cert from cm 4 1 ?
11-30-2008 02:33 AM
Got it working for CCM 5.1.2 and CCM 6.1.2
regards
11-30-2008 06:18 AM
Pete
Dis you every get this working on CM 4 1 3 and ASA 8 04
I have woking on cm 7 but not 4 1 3
12-03-2008 12:56 AM
I'm afraid not. I got most of the way on CCM6 but nowhere on v4.1.3.
This has taken a back seat at the moment whilst we deploy MPLS with Juniper kit :(
I'll return to this hopefully over the coming weeks.
Pete
12-02-2008 10:44 AM
Have this working in cm 4.1 AND VER 7
TO MAKE IT WORK ON cm VER 4.1 3 used the pem ca from CUCM ver 7
12-03-2008 06:33 PM
I am on the same situation, hopefully someone has done it on CM4.1(3).
BTW,
my ASA have an existing Ipsec VPN, will the adding of the Phone proxy works?
Thanks
12-03-2008 07:56 PM
CM 4.1.3 works with ASA 8 04 use this link http://supportwiki.cisco.com/ViewWiki/index.php/ASA_Phone_Proxy_sample_configuration_via_ASDM
and when it says to load files from cm 4 1 3
to create trustpoints
I used the same files from CUCM 7.0
Rate this post it works
step 7 from above doc
. It is necessary to load the Cisco Manufacturer CA certificates onto the firewall so that phones that use MIC certificates and the firewall can make a secure connection. Therefore, we'll create a trustpoint for each of the CA certificates CAP-RTP-001, CAP-RTP-002, and Cisco_Manufacturing_CA. These CA certificates can be downloaded from the Call Manager by doing the following (these steps might be different depending on the Call Manager version): I used the file that were on CUCM ver 7
12-03-2008 08:15 PM
Hi solokalina,
Nice to hear that! but how can I grab the files from CUCM 7.0 when we don't have any of that version.
Can a copy from others will work?
Thanks
12-11-2008 12:35 AM
Hi, I am trying to get phone proxy working with 4.2. I can find te Cisco_Manufacturing_CA but there is no CAP_RTP_001 and CAP_RTP_02 on our 4.2 CCM server. Are you saying I can use the certificates from another UCM such as Ver 6?
Thanks
David Stevens
01-06-2009 11:53 PM
Hi solokalina,
hope you can give us a workaround on how to get CA certificates from the CM ver 7. We only have CM ver 4.1(3).
Can a copy from other ver 7 be working on our current ver (4.1)?
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide