CIsoc IP Phone Using AnyConnect VPN Client on ASA

Posted on 2011-02-27
Last Modified: 2012-05-11
I wonder if somebody was successful in configuring Anyconnect VPN Client on Cisco ASA in order to facilitate connections from remote Cisco IP Phones to Call Manager cluster. The solution is so purely explained on Cisco website. I spent few days already trying to make it work but I'm not getting anywhere.  Even CallManager configuration is not clear either. Thanks for help.
Question by:pchopin

Assisted Solution

orbistechnology earned 125 total points
ID: 34993772
What model Cisco phone are you using?  

Anyconnect is SSL-based VPN.  Using self-signed certificates often causes us problems.  We always use a certificate from a CA and install it on the ASA.  

We have anyconnect setup per instructions from Cisco and have no issues with current model Cisco phones, using a well-known CA certificate on the ASA.

Author Comment

ID: 34993851
I'm using Cisco IP Phones 7965 with firmware v9 and Call Manger v8. I'm kind new to VoIP so I'm struggling a bit.  Would you know where I can fine working configuration for ASA using CA? I've been trying to use self-signed certificate till now.
Thank you for help
LVL 33

Assisted Solution

MikeKane earned 375 total points
ID: 34997442
I've set this up for 2 clients.     As orbs said, you will need a CA Cert for the ASA.

Once the ASA is loaded, you will need to export the .pem for both the CA authority and the Asa cert.    These 2 pem files are uploaded to the call manager as Trusted-Phone-Cert in CM Servicability.

On the ASA, you create a new VPN profile for the phones.   Configure ip pool and auth.  The important part is setting a Group URL in the Profile's Clientless SSL section.    This URL will be used in call manager config.  

On the call manager side, you create a new Phone Profile.  Make sure the certs are loaded in CM.   Create a VPN gateway In here you add the group URL form the ASA, and also pick the 2 trusted phone certs you uploaded earlier.    Next you create a new VPN group and create a common device profile.   In the device profile, make sure to fill in the VPN Group and VPN profile you created earlier.  

Assign a phone to that new profile.

On the phone, clear the itl entry and reset.   The phone should get the ITL and CTL.   Take it outside the LAN and enable VPN.   It should prompt for ID/PW and establish a connection.
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

LVL 33

Accepted Solution

MikeKane earned 375 total points
ID: 34997451
HERe's more info:

Also, you will need the VPN phone lic. on the ASA for this to work.  

Author Comment

ID: 35002197
Thanks MikeKane. This very helpful. But I just wonder why I would need 3-rd paryt certificate?  Why can't I use self-signed certificate from ASA?  This is not clear to me.
LVL 33

Assisted Solution

MikeKane earned 375 total points
ID: 35007892
The Intermediary cert must be installed and trusted by the CUCM if it isn't already.    I'm sure that using a self signed cert can be done, but I have never done one that way so I can't give any practical advice/direction.    However, like any cert, the CM must trust the issuer of the ASA cert and have a PEM file to load up as a trust-vpn-phone cert in Serviceability on the CM.  

LVL 35

Expert Comment

by:Ernie Beek
ID: 37049239
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Imagine a situation that you have installed SSL ( Certificate on your Cisco ASA (Cisco Adaptive Security Appliance) firewall. Installation of SSL certificate on ASA is an another topic for which you …
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now