CIsoc IP Phone Using AnyConnect VPN Client on ASA

Posted on 2011-02-27
Last Modified: 2012-05-11
I wonder if somebody was successful in configuring Anyconnect VPN Client on Cisco ASA in order to facilitate connections from remote Cisco IP Phones to Call Manager cluster. The solution is so purely explained on Cisco website. I spent few days already trying to make it work but I'm not getting anywhere.  Even CallManager configuration is not clear either. Thanks for help.
Question by:pchopin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Assisted Solution

orbistechnology earned 125 total points
ID: 34993772
What model Cisco phone are you using?  

Anyconnect is SSL-based VPN.  Using self-signed certificates often causes us problems.  We always use a certificate from a CA and install it on the ASA.  

We have anyconnect setup per instructions from Cisco and have no issues with current model Cisco phones, using a well-known CA certificate on the ASA.

Author Comment

ID: 34993851
I'm using Cisco IP Phones 7965 with firmware v9 and Call Manger v8. I'm kind new to VoIP so I'm struggling a bit.  Would you know where I can fine working configuration for ASA using CA? I've been trying to use self-signed certificate till now.
Thank you for help
LVL 33

Assisted Solution

MikeKane earned 375 total points
ID: 34997442
I've set this up for 2 clients.     As orbs said, you will need a CA Cert for the ASA.

Once the ASA is loaded, you will need to export the .pem for both the CA authority and the Asa cert.    These 2 pem files are uploaded to the call manager as Trusted-Phone-Cert in CM Servicability.

On the ASA, you create a new VPN profile for the phones.   Configure ip pool and auth.  The important part is setting a Group URL in the Profile's Clientless SSL section.    This URL will be used in call manager config.  

On the call manager side, you create a new Phone Profile.  Make sure the certs are loaded in CM.   Create a VPN gateway In here you add the group URL form the ASA, and also pick the 2 trusted phone certs you uploaded earlier.    Next you create a new VPN group and create a common device profile.   In the device profile, make sure to fill in the VPN Group and VPN profile you created earlier.  

Assign a phone to that new profile.

On the phone, clear the itl entry and reset.   The phone should get the ITL and CTL.   Take it outside the LAN and enable VPN.   It should prompt for ID/PW and establish a connection.
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

LVL 33

Accepted Solution

MikeKane earned 375 total points
ID: 34997451
HERe's more info:

Also, you will need the VPN phone lic. on the ASA for this to work.  

Author Comment

ID: 35002197
Thanks MikeKane. This very helpful. But I just wonder why I would need 3-rd paryt certificate?  Why can't I use self-signed certificate from ASA?  This is not clear to me.
LVL 33

Assisted Solution

MikeKane earned 375 total points
ID: 35007892
The Intermediary cert must be installed and trusted by the CUCM if it isn't already.    I'm sure that using a self signed cert can be done, but I have never done one that way so I can't give any practical advice/direction.    However, like any cert, the CM must trust the issuer of the ASA cert and have a PEM file to load up as a trust-vpn-phone cert in Serviceability on the CM.  

LVL 35

Expert Comment

by:Ernie Beek
ID: 37049239
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question