Cisco Firewall :: Configuring VoIP On ASA 5500?

Nov 20, 2011

We have to set up voip for our network(for 50 phones not he cisco phones).
 
I need to just the route the voip traffic to gateway address of telephonic company(1.1.5.7)  where they provide us the connectivity for the setination call.
 
What sort of protocols should i have to enable in pix i saw the concepts like sip, h323, ras, skinny.
 
We are using only voip for asa and no data or other traffic should be allowed.
  
inside adrees: 10.10.10.0/24 for all voip phones
outside:121.21.22.1
telephoneic gateway: 1.1.5.7

View 1 Replies


ADVERTISEMENT

Cisco :: Configuring 2960 For VoIP?

Mar 26, 2012

We just purchased cisco 2960 for our VoIP needs and we are using polycom phones, and Phone and Computer will use same port. Since Polycom phones are capable working with CDP protocol and we are hoping to get another switch to expand VoIP network. I found easiest way of setting up each port is as following (from the cisco tutorial)

Switch#configure terminal
Switch(config)#mls qos
Switch(config)#interface fastethernet 0/1
Switch(config-if)#mls qos trust cos
Switch(config-if)#switchport voice vlan dot1p
Switch(config-if)#switchport voice vlan 10
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 20
Switch(config-if)#exit

My first question,when we are using switchport voice vlan dot1p ,I thought we instruct the switch port to use 802.1P priority tagging for voice traffic and to use the default native VLAN (VLAN 0) to carry all traffic.Do I still need to create a Vlan 20 for data and Vlan 10 for voice ?

Secondly,same tutorial adds these commands as well,Do you think for our set up, using those commands are feasible ?

Switch(config-if)#switchport priority extend trust
Switch(config-if)#priority-queue out
Switch(config-if)#spanning-tree portfast
Switch(config-if)#spanning-tree bpduguard enable
Switch(config-if)#exit

Thirdly,when we get another switch and do the same configuration for the second switch, can I use any port on Switch 1 as uplink without doing any configuration ?

View 6 Replies View Related

Cisco Switches :: Configuring ESW-520-48P For VoIP / Ring Central

Apr 26, 2011

I am looking for a Best Practices or a few places to pay attention to in the Cisco ESW-520-48P switch I have. My VoIP solution is RingCentral, and while they are Cisco phones, I've been hestitant to setup VLANs etc. the way I am used to. Plus setting up Auto QoS seems different than what I am used to with a 3750 switch.
 
Right now I've left the Smartports Wizard alone, and none of the ports are configured. There are no VLANs or QoS on the LAN currently.
 
What I was running into were calls cutting out where one side wouldn't hear the other anymore, but the call would remain connected. However, this has happened in this small 15 person office, when there is only one employee here after hours, talking on the phone. There isn't any heavy network traffic, because I have network monitoring showing me low usage (no streaming music, videos, or anything else).
 
This switch has a Gb connection to a Linksys SR2024 (the server switch), which is also set at Factory Defaults. I mention that because I recently bypassed the ESW-520-48P, and plugged one phone into that switch and the RingCentral phone worked fine for outside calls.
 
Is there something besides QoS that I should look at in the ESW-520 switch that might be causing a checkpoint of some sort, or interrupting VoIP traffic that I need to configure or disable?
 
And are there any Best Practices or scenario guides for this switch? I found the Admin Guide, but it really just explains every option in the GUI for the switch. And it seems all of my CCNA training isn't working with going in and quickly troubleshooting this switch besides knowing that something in it could be hanging it up.

View 6 Replies View Related

Cisco Switching/Routing :: Configuring Port To 6901 VoIP Phone?

May 2, 2013

We've been configuring our swtichports as follows for our 7945 and 6941 type VoIP Phones, but are having problems witht the 6901.
 
VLANS
Vlan 900 is a VoIP VLAN
Vlan 999 is a NULL VLAN and is shut down:
 interface g0/1
switchport access vlan 999    {VLAN to direct data traffic to the bit bucket becuase a PC shouldn't be connected to this port}
switchport mode access
switchport voice vlan 900
mls qos trust cos
spanning-tree portfast
                 
The 6901 phone doesn't support multiple VLANs, so our configuration above does not work unless vlan 999 is turned on (not good security wise).  We got the phones to work also by removing vlan 999 and switchport mode access.
 
switchport voice vlan 900
mls qos trust cos
spanning-tree portfast
 
solution that provides the discarding of data for the access VLAN, while supporting the VoIP vlan for this phone? 

View 3 Replies View Related

Linksys Wireless Router :: Configuring E4200 For VOIP Prioritization

Sep 8, 2011

How do I configure E4200 for VOIP priority. My vonage adapter is connected to the router by Ethernet.Also I want google voice call prioritization.

View 1 Replies View Related

Cisco Switching/Routing :: NEXUS 5500 NX-OS Configuring SNMPv3

Jan 16, 2012

IOS we used for limiting access for a group we used configuration of snmp-server views like following
 
snmp-server group backupgroup v3 priv read backupview write backupview access 20 snmp-server view backupview ccCopyTable included could not find out how to achive this config in NX-OS on Nexus5500

View 2 Replies View Related

Cisco :: Detecting Rogue AP Messages In Syslog And Configuring WLC 5500

May 7, 2013

I'm building the use case to test / detect for rogue devices on the network. I have in my enviroment Lan controller 5500 controller with AP (aironet 3500). I want to detect for rogue devices/ap connected to my network. I know before i can see this activity on the network i have to configure the controller / ap to detect this behavior. I'm doing this step.
 
Authorize AP's against AAA function to make sure that  all the AP's registering to your WLC are authorized AP's of the  network.By  enabling this feature, only those AP's whose mac-addresses are present  in the authorization list, will be able to register to the URL
 
Using Rogue detection. feature, the WLC will be able to detect any AP that is not a part of its RF group and contain it.URL
 
NOTE: from the forum I have seen other talks about the same issue and saying that if I have any APs in "Rogue Detection"  mode sitting on the trunk port  on the switch then  only, this AP will detect the  Rogue on Wired
 
I don't think i completely understand this statement, by sitting does it mean that it is passively sniffing coming in/out on trunk link?
 
Considering the above steps are accurate, after this will i be able to see rogue detection behavior in syslogs? What exactly would be the messages that would produce this behavior.

View 7 Replies View Related

Cisco Wireless :: 5500 Detecting Rogue AP Messages In Syslog / Configuring WLC

May 9, 2013

I'm building the use case to test / detect for rogue devices on the network. I have in my enviroment Lan  controller 5500 controller with AP (aironet 3500). I want to detect for  rogue devices/ap connected to my network. I know before i can see this activity on the network i have to configure the controller / ap to  detect this behavior.
 
Authorize AP's against AAA function to make sure that  all the AP's  registering to your WLC are authorized AP's of the  network.By  enabling  this feature, only those AP's whose mac-addresses are present  in the  authorization list, will be able to register to the WLC. url...
 
Using Rogue detection. feature, the WLC will be able to detect any AP that is not a part of its RF group and contain it. url...the forum I have seen other talks about the same issue and saying that  if I have any APs in "Rogue Detection"  mode sitting on the trunk port   on the switch then  only, this AP will detect the  Rogue on Wired.

View 2 Replies View Related

Cisco Firewall :: Support Of Jumbo Frames On ASA 5500 Firewall Appliance?

Feb 28, 2010

Can any ASA 5500 in particular the ASA5510 firewall support jumbo frames (i.e. greater than the default standard 1500 Bytes frames)?. I plan to use the ASAs to setup a point-to-point IPSec tunnel and need an Application frame of 4Kbytes intact and not segment it.I have done little checking on the Cisco Website and see it mention of Jumbo frames on the 5580 on 10Gig interface but didn't see mention 5510. 5580s are way over-kill and expensive for what I need is to run a mission critical one IPSec point-to-point with maximum of no more than 100Kbps so 5510 is perfect for me but not sure if it can carry the jumbo frame?
 
On the routers and switches it's the MTU settings and they are configurable per interface and I am OK and the circuit is T1 which the Telcos said it's OK since it's physical layer so the only unkown is the firewall.

View 2 Replies View Related

Cisco Firewall :: ASA 5500 - Get Firewall License To 500 Users?

Jan 25, 2012

I purchased the license P/N: ASA-CSC20-250U-1Y with Description: ASA 5500 CSC-SSM-20 250-User License Only Renewal (1-year)
 
But I had a mistake because I need support to 500 users. Now, to solve my mistake I want to know Do I can purchase another ASA-CSC20-250U-1Y to provide the 500 users suppor?
 
I mean, ¿are two (2) ASA-CSC20-250U-1Y equivalent to the 500 user license listed below?P/N, ASA-CSC20-500U-1Y  with Description: ASA 5500 CSC-SSM-20 500-User License Only Renewal (1-year)

View 1 Replies View Related

Cisco Firewall :: Voip ASA 5515 Version 9.1

May 17, 2013

im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.
 
As you see on the topology,the flow of calls happens this way:

In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.

ASA 5510 config:
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
[Code]...

View 1 Replies View Related

Cisco Firewall :: Voip ASA 5515 Version 9.1.1

Jan 8, 2012

Im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.

As you see on the topology,the flow of calls happens this way: In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.
 
ASA 5510 config:
 
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
description ***ISP SIP Network***
[Code]....

View 1 Replies View Related

Cisco Firewall :: Open Ports On ASA 5505 For VoIP?

May 5, 2013

I'm working on setting up a PBX server in our office, and I'm having trouble getting a port opened for SIP on my ASA 5505.I created static NAT rule for SIP traffic from internal server to the outside IP address.I created access rules on outside interface to forward port 5060 to internal PBX server (192.168.1.8)I also disabled sip packet inspection on the ASA.I'm still receiving a message from the PBX that the firewall is configured incorrectly. 
 
[code]....

View 5 Replies View Related

Cisco Firewall :: ASA 5510 / QOS For VOIP Traffic To And From Internet

Apr 20, 2011

We are using an ASA 5510 as our gateway to our ISP.  All of our VOIP traffic is sent to an Internet SIP provider for our outbound calls.  Our pipe to the Internet is 100Mbps metro ethernet.  I am trying to find a way to provide QoS for this traffic so that I can reserve 20Mbps of the available 100Mbps pipe for VOIP traffic.From what I've been able to figure out so far I would use a combination of priority queues and traffic policing.  However, it seems that this is nearly impossible to accomplish because I cannot control the remote device that my ASA connects to because it is the ISP device.  I could police traffic on the inside interface of the ASA.  However, lets say that a client on our network starts downloading from an Internet host and the downloaded traffic saturates my Internet connection.  I could police this incoming (from the Internet) traffic on my outside interface of the firewall.  This would drop the packets but the bandwidth would have already been used by the time it reaches my firewall.Would the fact that I'm policing incoming traffic on my outside interface cause the sender to throttle down their transmit rate because packets are being dropped?  Would this achieve my goal of guaranteeing available bandwidth for my VOIP traffic by not allowing other traffic to saturate the link?Most documents I find regarding this topic describe providing QoS for VOIP traffic traversing a VPN connection in which case you could configure both end devices.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Configure QoS And VOIP With SIP Trunking?

Sep 16, 2012

[URL] I am not savy configuring ASAs at all and I can't get it to work. We are switching to a SIP trunk phone system and I am in charge of setting up the ASA to not only make it work but also make sure that there's packet priority or QoS.I've never configured something like this and I was giving another set of instructions to make sure that this is working:

[URL]

Configuration:
My configuration is very basic:
3 interfaces - Outside/Inside/Guest
ASA Version: 7.2(3)
ASDM Version 5.2(3)
Firewall Mode: Routed
 
Solution: When I tried following the instructions on brian-kayser's blog I get an error when I'm sending the following command:

shape average
^  Invalid marker
service-policy PRIORITY-POLICY
^ Incomplete command 
 
I think it's because my version of ASA doesn't have this functionality but I don't know.

View 5 Replies View Related

Cisco Firewall :: Voip Pbx Resides On Separate LAN / Not Connected To ASA 5510

Oct 18, 2011

The Voip pbx resides on a seperate lan, not connected to the ASA.  Users from behind the ASA (inside) try to connect to the VOIP pbx using a soft phone. The Voip connection is established, however users cannot here conversations on either end.Im assuming this is possibly a Sip and Pat issue?  The ASA firewall is using a seperate Global IP for PAT.  Also I have opened ports on the outside interface for SIP udp 8081, 2088,16000-16010 and 15000-15511.  I have both SIP and H323 h225 inspection in place as well. 

View 5 Replies View Related

Cisco Firewall :: ASA 5500 Configuration For VC?

Aug 13, 2012

i have to open ports for vedio conferencing in my Firewall configuration ,

View 1 Replies View Related

Cisco Firewall :: ASA 5500 Ssl Vpn Required

Jun 14, 2011

I have two ASA 5510 with Security Plus license and Shared SSL VPN licensing enabled.

The problem is that the client get “Session could not be established: session limit of 25 reached” but ther is only 6 ssl vpn user connected with AnyConnect.The software on the firewall’s is 8.2(1)Is there any BUG in this software related to this problem?

View 1 Replies View Related

Zyxel USG50 / How To Best Allow For Unfettered VOIP Traffic Behind A Security Firewall

Mar 12, 2013

I have a customer who has a Zyxel USG50 security firewall on their network. They utilize a cloud hosted voip solution called Vocalocity that provides SIP voip service to their Cisco phones. They have about 8 phones in a small office.the problem they are having is that as it stands now, all VOIP phones in the office are dynamically assigned addresses internally. However, the VOIP phones are having a ton of issues that we believe may be related to the firewall blocking traffic somehow or not playing nicely with the service.

- Some calls are dropped altogether
- Some calls do not ring all phones
- Some phones keep ringing even after a call is picked up

While Vocalocity has admitted that they have the "ghost ringing" issue going on with other customers, the dropped calls and not all phones ringing could be firewall related. We are trying to pinpoint what may be going on.i did open up all of the ports that the VOIP provider claims are used by their service, 5060-5090. However, some 5060 packets still seem like they are being blocked in the firewall logs.How does everyone else out there setup their VOIP phones internally to have unfettered access to the internet? Do you recommend just using the DMZ functionality (which I can do on this USG device) or bypassing the firewall altogether somehow? We have some spare switches and another home level Netgear router we can use for testing.

View 8 Replies View Related

Cisco Firewall :: Monitoring SMTP On An ASA 5500?

Mar 5, 2012

I have an ASA 5500 Firewall. I need to figure out how to log all events using Port 25 to determine if there are any rogue devices on our network. I was trying to figure out how to do this via the Real-Time Monitoring (filter) but have had no success.

View 1 Replies View Related

Cisco Firewall :: Getting Email Delay On ASA 5500

Jun 6, 2012

I have an issue with a Cisco ASA 5520. It seems to block some emails incoming from some recipients. The sender's mail server clearly reports my ASA as cause of the problem (see attached image). Unfortunately I have not the logs about that event and the time frame to close this issue is very narrow.

View 5 Replies View Related

Cisco Firewall :: Shut Down AUX Port On ASA 5500?

Oct 23, 2011

Is there a way to shut down the AUX port on the ASA?

View 1 Replies View Related

Cisco Firewall :: ASA 5500 - Upgrade Image To 8.4(3)?

Apr 3, 2012

We are now using image 8.0(4) for my ASA 5510. Later on, I would like to upgrade the image to 8.4(3).May I have to know what difference for those images, what should I take care of the script?

View 1 Replies View Related

Cisco Firewall :: Stateless Filter In ASA 5500

May 21, 2011

Does ASA 5500 has stateless filter to drop packet even when 3-way handshake is finished
 
For example,
 
1: 3-way handshake is done

2:client send data to server

3:I apply a statless filter to the incoming interface to drop the packet from the client

View 3 Replies View Related

Cisco Firewall :: ASA 5500 And ICMP Unreachable

Jun 27, 2012

Is it really the case that the ASA will not generate ICMP Host Unreachable messages for sub nets connected to any of its interfaces (in breach of RFC1812) as claimed here: [URL]

I'm investigating a situation where an organization uses ASAs to control traffic between different v lans in their internal production systems as well as Internet traffic.  They are having problems with internal load balancing because the ASAs do not (as currently configured) generate Host Unreachable packets.  Can this be changed in the configuration or not?  I have to say, if it can't then I'd urge them to find something else to route between their internal sub nets.

View 5 Replies View Related

Cisco Firewall :: BOM Product Licensing Of 5500 ASA

Aug 27, 2011

I am pretty new to cisco and the learning community forums is truely one of a  kind.Actually, I work on a company which deals the Cisco products, Routers/Firewalls/Switches and stuffs. I am sure you get the picture. What confuses me is the product licensing of ASA5500. To be more specific, we are proposing certain things. And that came with the product pricing sets and all. But I amn't having a clear picture on ASA 5500 Strong Encryption License (3DES/AES). Does that come inbuilt(free) or should there be any pricing behind that!?

View 5 Replies View Related

Cisco Firewall :: ASA Version 9.0(1) / Configuring NAT On Intranet Firewall?

Dec 26, 2012

configuring NAT on intranet firewall. here is the my topology:
 
  DMZ Network  - - - - - - - - - External Firewall   - - - - - - - - - Internet
                                                          |
                                                          |    
                                                          |
  Internal Network  - - - - - - - - - Internal Firewall  
 
1) I can Ping the intneral host from external firewall, internet firewall and DMZ network

2) Both ASA's are running OS Version 9.0(1)

3) ACL used permit IP any any, on both (i.e inside and outside)
 
NAT configuration on Internal Firewall  (Identity NAT)
 
object network MGMT-SRV-INSIDE           subnet 10.10.10.0 255.255.255.192
object network MGMT-SRV-identity
subnet10.10.10.0 255.255.255.192
 object network MGMT-SRV-INSIDE           nat (Inside,Outside) static MGMT-SRV-identity

[code]....

View 1 Replies View Related

Cisco Firewall :: ASA 5500 - PPPoE Session Duration

Sep 18, 2012

How can i determine the current PPPoE session duration on ASA 5500 Systems? If i use the different CLI commands like "show vpdn session state / show vpdn session pppoe state" the output says:

State: SESSION_UP Last Chg: 593595 secs.
 
The ISP is forcing a reconnect every 86400 seconds, so the value can't be the actual duration of the pppoe session. Does it only indicate the link duration to the attached modem or interface state? Is the only way to detect interruptions of the pppoe session with debug and syslog?

View 0 Replies View Related

Cisco Firewall :: Can Configure More Than One Syslog Host On ASA 5500

May 31, 2012

I would like to send my ASA 5500 logs to more than one syslog server - is this possible?  I can't seem to find it in the documentation.

View 3 Replies View Related

Cisco Firewall :: Redirect Ip Address For Protocol With ASA 5500

Jan 5, 2012

On the inside interface and network, we have a server at, (as an example) 192.168.87.1, which acts as an email server.
 
The outside ip address of the ASA is, say, 200.0.0.1.
 
The ASA directs any imap requests from the outside interface to 192.168.87.1, which works fine from the outside. Users simply open up email, and collect emails etc.
  
When they come inside the office, their machine of course attempts to contact the ip address 200.0.0.1. the ASA knows it is outside interface, so they are unable to collect emails.
 
that any internal IMAP requests from machines on the inside to 200.0.0.1 are directed to the machine inside on 192.168.87.1?

View 5 Replies View Related

Cisco Firewall :: 5500 ADSM 6.3 Can't Open Dialogue Box

Jan 3, 2012

i'm having issues with ASDM 6.3 on my ASA 5500.When i try to add a policy under firewall --> service policy rules (Add Service Policy Rule Wizard - Rule Actions), i'm not able to add a netflow policy as I'm not presented with a dialogue box after I press "add".i've tried this from multiple computers mac os and windows.

View 9 Replies View Related

Cisco Firewall :: IPS Module Setup On 5500-X Series ASA

May 16, 2013

Since the 5500X series firewalls use a software IPS SSM that is set up differently from the old ones, I am a little confused on the initial setup.
 
[URL]
 
we see a proposed setup for L3 management of the IPS
 
interface GigabitEthernet0/0
nameif outside security-level 0
ip address 203.0.113.1 255.255.0.0

[Code].....

View 1 Replies View Related

Cisco Firewall :: ASA 5500 - Transparent And Routed Mode

Jun 26, 2012

have a Cisco ASA that I am trying to configure in a unique way, I want it to perform a variety of tasks;
 
VPN SSL
VPN Tunnels
Firewall Inside to Outside via versa
 
But the difficult task, is creating a DMZ with devices that are assigned fully routed IP addresses from our ISP directly, these are H323 and SIP devices that cannot use NAT, and must have a fully routed IP address assigned to them.
 
Obviously the problem I have with the Firewall in its default routed mode, is that it wont allow me to overlap IP addresses on the outside interface with the DMZ interface.
 
Could the Firewall be configured for Transparent mode between Outside and DMZ, but Routed mode between Outside and Inside?
 
Eth0/0: 10.0.0./24 (inside)
Eth0/1: 190.0.0.0/24 (dmz)
Eth0/2: 190.0.0.0/24 (outside)
 
[Code]....

But could the new Cisco ASA with the latest firmware and model be ale to do this with 1 physical firewall?

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved