02-07-2011 11:06 AM - edited 03-20-2019 06:01 AM
We have ASA 5505 configured with phone proxy and we use ip communicator to connect to the call manager from outside. Is it possible to use iPhone with phone proxy, I tried to enter the external tftp ip address but it's not working. Any idea?
Solved! Go to Solution.
02-07-2011 11:32 AM
It's not possible with current versions, your only option for using Cisco Mobile 8.0/8.1 for iPhone when away from your network is to first connect via a VPN. The phone proxy option is out for now, but fingers crossed that it will appear in the future.
02-07-2011 11:32 AM
It's not possible with current versions, your only option for using Cisco Mobile 8.0/8.1 for iPhone when away from your network is to first connect via a VPN. The phone proxy option is out for now, but fingers crossed that it will appear in the future.
02-08-2011 08:26 AM
I hope we have that, I wish there is way to use iPhone without VPN from outside.
02-09-2011 03:57 AM
Dear, i was just exploring and found your page, i am going to setup phone proxy using ASA5510 and Callmanager 6.0, i am unable to set up ip communicator to download LSC can u help me in this regards thanks,
Regards
Bilal
02-09-2011 06:43 PM
Brother, I have no idea on Phone proxy, But I have this config from ASA 5505, they have ASA phone proxy already setup, may be you can find something out of this.
I have change the value for security reason,
"tls-proxy ASA-tls-proxy
server trust-point _internal_PP_ctl_phoneproxy_file
ctl-file ctl_phoneproxy_file
record-entry capf trustpoint capf_trustpoint_2 address "external_ip"
record-entry cucm-tftp trustpoint phoneproxy_trustpoint address "external_ip"
no shutdown
!
media-termination my_mta
address 172.16.108.2 interface inside
address "external_ip" interface OUTSIDE
!
phone-proxy ASA-phone-proxy
media-termination my_mta
tftp-server address 172.16.110.2 interface inside
tls-proxy ASA-tls-proxy
ctl-file ctl_phoneproxy_file
no disable service-settings
proxy-server address 172.16.110.2 interface inside
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
ntp server "external_ip" prefer
ntp server "external_ip"
webvpn
enable OUTSIDE
svc image disk0:/anyconnect-win-2.3.0254-k9.pkg 1
svc enable
tunnel-group-list enable
group-policy SSL-VPN-Group-Policy-1 internal
group-policy SSL-VPN-Group-Policy-1 attributes
dns-server value 172.16.8.8 172.16.8.14
vpn-idle-timeout none
vpn-tunnel-protocol svc webvpn
split-tunnel-policy tunnelspecified
split-tunnel-network-list value BC-Networks
default-domain value bakercompanies.com
webvpn
svc ask enable default svc timeout 15
group-policy pcf-vpn-policy internal
group-policy pcf-vpn-policy attributes
dns-server value 172.16.8.8 172.16.8.14
!
class-map sec_sip
match port tcp eq 5061
class-map sec_sccp
match port tcp eq 2443
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide