Cisco CP-7911G-CH1 Administration Guide - Page 227

DETAILED STEPS, Verifying the Configuration, show sip-ua status registrar, show voice register global

Page 227 highlights

Configuring Secure SRST for SCCP and SIP How to Configure Secure Unified SRST DETAILED STEPS Command or Action Step 1 sip-ua Purpose Enters SIP user-agent configuration mode. Step 2 Step 3 Step 4 Step 5 Example: Router(config)# sip-ua registrar ipv4:destination-address expires seconds Example: Router(config-sip-ua)# registrar ipv4:192.168.2.10 expires 3600 Enables the gateway to register E.164 telephone numbers with primary and secondary external SIP registrars. destination-address is the IP address of the primary SIP registrar server. xfer target dial-peer Specifies that SRST should use the dial-peer as a transfer target instead of what is in the message body. Example: Router(config-sip-ua)# xfer target dial-peer crypto signaling default trustpoint string [strict-cipher] Example: Router(config-sip-ua)# crypto signaling default trustpoint 3745-SRST strict-cipher Identifies the trustpoint string keyword and argument used during the TLS handshake. The trustpoint string keyword and argument refer to the gateway's certificate generated as part of the enrollment process, using Cisco IOS public-key infrastructure (PKI) commands. The strict-cipher keyword restricts support to TLS RSA encryption with the Advanced Encryption Standard-128 (AES-128) cipher-block-chaining (CBC) Secure Hash Algorithm (SHA) (TLS_RSA_WITH_AES_128_CBC_SHA) cipher suite. To configure device-default mode, omit the strict-cipher keyword. end Ends the current configuration session and returns to privileged EXEC mode. Example: Router(config-sip-ua)# end Verifying the Configuration The following examples show a sample configuration displayed by the show sip-ua status registrar command and the show voice register global command. The show sip-ua status registrar command in privileged EXEC mode displays all SIP endpoints that are currently registered with the contact address. Router# show sip-ua status registrar Line destination expires(sec) contact transport call-id peer 3029991 192.168.2.108 388 192.168.2.108 TLS [email protected] 40004 3029993 192.168.2.103 382 192.168.2.103 TCP [email protected] 40011 OL-13143-04 Cisco Unified SCCP and SIP SRST System Administrator Guide 227

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322

Configuring Secure SRST for SCCP and SIP
How to Configure Secure Unified SRST
227
Cisco Unified SCCP and SIP SRST System Administrator Guide
OL-13143-04
DETAILED STEPS
Verifying the Configuration
The following examples show a sample configuration displayed by the
show sip-ua status registrar
command and the
show voice register global
command.
The
show sip-ua status registrar
command in privileged EXEC mode displays all SIP endpoints that
are currently registered with the contact address.
Router#
show sip-ua status registrar
Line destination expires(sec) contact
transport call-id
peer
============ =============== ============ ===============
3029991 192.168.2.108 388 192.168.2.108
40004
3029993 192.168.2.103 382 192.168.2.103
40011
Command or Action
Purpose
Step 1
sip-ua
Example:
Router(config)# sip-ua
Enters SIP user-agent configuration mode.
Step 2
registrar ipv4:
destination-address
expires
seconds
Example:
Router(config-sip-ua)# registrar
ipv4:192.168.2.10 expires 3600
Enables the gateway to register E.164 telephone numbers
with primary and secondary external SIP registrars.
destination-address
is the IP address of the primary SIP
registrar server.
Step 3
xfer target dial-peer
Example:
Router(config-sip-ua)# xfer target dial-peer
Specifies that SRST should use the dial-peer as a transfer
target instead of what is in the message body.
Step 4
crypto signaling default trustpoint
string
[strict-cipher]
Example:
Router(config-sip-ua)# crypto signaling default
trustpoint 3745-SRST strict-cipher
Identifies the
trustpoint
string
keyword and argument used
during the TLS handshake. The
trustpoint
string
keyword
and argument refer to the gateway’s certificate generated as
part of the enrollment process, using Cisco IOS public-key
infrastructure (PKI) commands. The
strict-cipher
keyword
restricts support to TLS RSA encryption with the Advanced
Encryption Standard-128 (AES-128) cipher-block-chaining
(CBC) Secure Hash Algorithm (SHA)
(TLS_RSA_WITH_AES_128_CBC_SHA) cipher suite.
To configure device-default mode, omit the
strict-cipher
keyword.
Step 5
end
Example:
Router(config-sip-ua)# end
Ends the current configuration session and returns to
privileged EXEC mode.