25-85
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 25 Configuring Application Layer Protocol Inspection
TLS Proxy for Encrypted Voice Inspection
hostname(config)#
crypto ca export ldc_server identity-certificate
b.
For the embedded local CA server LOCAL-CA-SERVER, use the following command to export its
certificate, for example:
hostname(config)#
show crypto ca server certificate
Save the output to a file and import the certificate on the Cisco Unified CallManager. For more
information, see the Cisco Unified CallManager document:
http://www.cisco.com/univercd/cc/td/doc/product/voice/c_callmg/5_0/iptp_adm/504/iptpch6.htm#wp1
040848
After this step, you may use the Display Certificates function on the Cisco Unified CallManager GUI to
verify the installed certificate:
http://www.cisco.com/univercd/cc/td/doc/product/voice/c_callmg/5_0/iptp_adm/504/iptpch6.htm#wp1
040354
Step 9
Run the CTL Client application to add the server proxy certificate (ccm_proxy) to the CTL file and
install the CTL file on the security appliance. See the Cisco Unified CallManager document for
information on how to configure and use CTL Client:
http://www.cisco.com/univercd/cc/td/doc/product/voice/c_callmg/5_1/nci/p08/secuauth.htm
Note
You will need the CTL Client that is released with Cisco Unified CallManager Release 5.1 to
interoperate with the security appliance. See the
“CTL Client” section on page 25-88
for more
information regarding TLS proxy support.
Debugging TLS Proxy
You may enable TLS proxy debug flags along with SSL syslogs to debug TLS proxy connection
problems. For example, using the following commands to enable TLS proxy-related debug and syslog
output only:
hostname(config)#
debug inspect tls-proxy events
hostname(config)#
debug inspect tls-proxy errors
hostname(config)#
logging enable
hostname(config)#
logging timestamp
hostname(config)#
logging list loglist message 711001
hostname(config)#
logging list loglist message 725001-725014
hostname(config)#
logging list loglist message 717001-717038
hostname(config)#
logging buffer-size 1000000
hostname(config)#
logging buffered loglist
hostname(config)#
logging debug-trace
The following is sample output reflecting a successful TLS proxy session setup for a SIP phone:
hostname(config)#
show log
Apr 17 2007 23:13:47: %ASA-6-725001: Starting SSL handshake with client
outside:133.9.0.218/49159 for TLSv1 session.
Apr 17 2007 23:13:47: %ASA-7-711001: TLSP cbad5120: Set up proxy for Client
outside:133.9.0.218/49159 <-> Server inside:195.168.2.201/5061
Apr 17 2007 23:13:47: %ASA-7-711001: TLSP cbad5120: Using trust point 'local_ccm' with the
Client, RT proxy cbae1538
Apr 17 2007 23:13:47: %ASA-7-711001: TLSP cbad5120: Waiting for SSL handshake from Client
outside:133.9.0.218/49159.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......