The PIX firewall that runs on a code previos than 7.0(1) won't be able to let those packet to pass thru, since the options are removed by default.What you can do, is to upgrade the PIX to 7.0(1) (8.0 is preffered) and configure a tcp-map that allows...
Greetings,Currently, ASA phone Proxy feature is not supported with CUCM 8.5. I guess that on this scenario your option would be to use the Phone VPN feature on the ASA.http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/unified_com...
If you are planning Hairpinning and static NAT, you are missing the global (PROTECTED) 101 interface and the same-security-traffic permit intra-interface command.If you want to use the DNS Doctoring, you are missing the following MPF commands:policy-...
On this case, you should use:global (inside) 101 interfaceAnd permit the same-security-traffic:same-security-traffic permit intra-interfaceLet me know if that helps.
Please noticed that we also have the DNS doctoring feature on the ASA to accomplish this.Find the solutions for the issue on the following document:http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968d1.shtmlLet me ...