Guest

Preview Tool

Cisco Bug: CSCtf25270 - PP: MTA can be replaced with static/dynamic route

Last Modified

Nov 08, 2016

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

8.2(1)

Description (partial)

Symptom:
1) No way audio when making a call to/from a phone registered through ASA phone-proxy

2) Syslog ID 608001 shows ASA isn't opening the media session for "NP Identity IFC" for it's MTA.  For example, outside MTA is 10.36.107.91:

This is Incorrect (Symptom of this bug)
%ASA-6-608001: Pre-allocate Skinny RTP secondary channel for outside:10.36.107.91/29928 to outside:10.36.105.67 from *****StationOpenReceiveChannelAckID message

This is Correct (Media session was allocated properly):
%ASA-6-608001: Pre-allocate Skinny RTP secondary channel for NP Identity Ifc:10.36.107.91/29928 to outside:10.36.105.67 from *****StationOpenReceiveChannelAckID message

Note: 10.36.107.91 (MTA) needs to be preallocated on the "NP Identity Ifc" and NOT another interface.

3) (s)RTP stream is arriving at the ASA, but ASA is dropping it with syslog:

%ASA-2-106006: Deny inbound UDP from 10.36.105.67/3088 to 10.36.107.91/29928 on interface outside

Conditions:
1) Per-interface-MTA configured.  Ex)

media-termination MTA
 address 10.36.107.91 interface outside
 address 172.18.124.136 interface inside

2) ASA learned about one of its media-termination addresses via a static or dynamic route after phone-proxy was configured and service-policy applied
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.