Cisco CP-7911G-CH1 Administration Guide - Page 183

Process, Description or Detail, In case of WAN failure

Page 183 highlights

Configuring Secure SRST for SCCP and SIP Information About Configuring Secure SRST Figure 1 Interworking of Credentials Server on SRST Router, Cisco Unified Communications Manager, and Cisco Unified IP Phone Cisco Unified Communications Manager/client 1. Cisco Unified Communications Manager requests the Cisco Unified SRST certificate from the credentials server. WAN Credentials server running on secure Cisco Unified SRST router 155100 2. The credentials server responds with the certificate. 3. Cisco Unified Communications Manager inserts the certificate in the phone configuration file. IP Cisco IP phone Table 2 Establishing Secure SRST Mode Process Description or Detail Regular Mode The Cisco Unified IP Phone configures DHCP and - gets the TFTP server address. The Cisco Unified IP Phone retrieves a CTL file The CTL file contains the certificates that the phone from the TFTP server. should trust. The Cisco IP Phone opens a Transport Layer Security (TLS) protocol channel and registers to Cisco Unified Communications Manager. Cisco Unified Communications Manager exports secure Cisco Unified SRST router information and the Cisco Unified SRST router certificate to the Cisco Unified IP phone. The phone places the certificate into its configuration. Once the phone has the Cisco Unified SRST certificate, the Cisco Unified SRST router is considered secure. See Figure 1. If the Cisco Unified IP Phone is configured as The connection to the SRST router happens "authenticated" or "encrypted" and Cisco automatically, assuming there is not a secondary Unified Communications Manager is configured Cisco Unified Communications Manager and Cisco in mixed mode, the phone looks for an SRST Unified SRST is configured as the backup device. See certificate in its configuration file. If it finds an Figure 1. SRST certificate, it opens a standby TLS Cisco Unified Communications Manager should be connection to the default port. The default port is configured in mixed mode, which is its secure mode. the Cisco Unified IP Phone TCP port plus 443; that is, port 2443 on a Cisco Unified SRST router. In case of WAN failure, the Cisco Unified IP Phone starts Cisco Unified SRST registration. SRST Mode The Cisco Unified IP Phone registers with the - SRST router at the default port for secure communications. OL-13143-04 Cisco Unified SCCP and SIP SRST System Administrator Guide 183

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

Configuring Secure SRST for SCCP and SIP
Information About Configuring Secure SRST
183
Cisco Unified SCCP and SIP SRST System Administrator Guide
OL-13143-04
Figure 1
Interworking of Credentials Server on SRST Router, Cisco Unified Communications
Manager, and Cisco Unified IP Phone
Table 2
Establishing Secure SRST
Mode
Process
Description or Detail
Regular Mode
The Cisco Unified IP Phone configures DHCP and
gets the TFTP server address.
The Cisco Unified IP Phone retrieves a CTL file
from the TFTP server.
The CTL file contains the certificates that the phone
should trust.
The Cisco IP Phone opens a Transport Layer
Security (TLS) protocol channel and registers to
Cisco Unified Communications Manager.
Cisco Unified Communications Manager exports
secure Cisco Unified SRST router information and
the Cisco Unified SRST router certificate to the Cisco
Unified IP phone. The phone places the certificate
into its configuration. Once the phone has the Cisco
Unified SRST certificate, the Cisco Unified SRST
router is considered secure. See
Figure 1
.
If the Cisco Unified IP Phone is configured as
“authenticated” or “encrypted” and Cisco
Unified Communications Manager is configured
in mixed mode, the phone looks for an SRST
certificate in its configuration file. If it finds an
SRST certificate, it opens a standby TLS
connection to the default port. The default port is
the Cisco Unified IP Phone TCP port plus 443;
that is, port 2443 on a Cisco Unified SRST router.
The connection to the SRST router happens
automatically, assuming there is not a secondary
Cisco Unified Communications Manager and Cisco
Unified SRST is configured as the backup device. See
Figure 1
.
Cisco Unified Communications Manager should be
configured in mixed mode, which is its secure mode.
In case of WAN failure, the Cisco Unified IP Phone starts Cisco Unified SRST registration.
SRST Mode
The Cisco Unified IP Phone registers with the
SRST router at the default port for secure
communications.
155100
Cisco Unified
Communications
Manager/client
Cisco IP phone
Credentials server
running on secure
Cisco Unified
SRST router
2. The credentials server responds
with the certificate.
3. Cisco Unified Communications Manager inserts
the certificate in the phone configuration file.
IP
WAN
1. Cisco Unified Communications Manager
requests the Cisco Unified SRST certificate
from the credentials server.