12-08-2006 05:38 PM - edited 02-21-2020 02:45 PM
We have a pair of ASA5520's and are running IPSEC L2L VPN tunnels to 851 routers that have Cisco 7940/7960 phones connected to them. Frequently the phones will lose registration with the CM's or reboot. Currently the fixup skinny protocol inspection is enabled for port 2000 on the ASA's.
12-10-2006 12:43 PM
Still no feedback on this...anyone?
12-11-2006 09:02 AM
Hi
I am not sure about how the phones talks to the Server, but as of my knowledge, IPSEC tunnel may have problem with mutlicast protocols, why dont you try enabling GRE tunnel over IPSEC?
it may helps
Regards
Reddy
11-20-2007 12:14 AM
Any luck fixing this? I'm having a similar issue.
11-20-2007 07:02 AM
Yes, I opened a TAC case about this last year, and the Engr and I found via packet captures that there was a bug that caused the skinny packet inspection to send packets out of order. Cisco implemented a bug fix in newer code. We have since upgraded to 7.2.3 and that solved our problem.
What version of code on you running?
Help this helps for you.
11-20-2007 07:28 AM
Interesting...so even with routing the traffic via the VPN the skinny packet inspection was an issue? I'm running 7.2.2 on the remote ASA and 12.4.11XJ on my CME router, so you might have hit the nail on the head.
I also realized last night that my IPSEC lifetime values were mismatched (defaults differ between ASA and router) and that one end was forcing a rekey every 60 min, so I adjusted them to match.
We'll see how it runs and use your fix as the next runner up. Big thanks for the reply.
11-20-2007 07:56 AM
Yes we had specific problems with VPN skinny traffic that terminated on the ASA hub firewall. I believe the fix for the skinny inspection bug was fixed after 7.2.2(8), but that was months ago. Also, your timer mismatches can be an issue as your tunnels may drop during rekeying, causing the phone to drop rtp streams and re-register.
I found with our problem that I was able to repeat the problem by having the remote phone setup a conference call. The moment the second call arrived to the phone, it reset and was a repeatable problem.
I hope this helps...
-Scott
11-20-2007 09:30 AM
Good test!
Thanks again!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide