Setting up TLS and SRTP on CUBE
Cisco Unified Border Element
Verified 2026-09-30 · 63 sources · tier 2
For Voice engineers administering CUBE on Cisco IOS XE with administrative access to the connected Unified CM trunk..
This guide steps through configuring SIP TLS signaling and SRTP media on Cisco Unified Border Element (CUBE) facing a Cisco Unified Communications Manager (Unified CM) SIP trunk 17 11. It details certificate exchange, dial-peer security, SRTP crypto policies, and live verification on Cisco IOS XE 55 59.
Before you start
- Cisco's hardening guide recommends CA-signed certificates over self-signed certificates 20.
- Cisco's hardening guide notes that some older Cisco devices or peer devices may not support AEAD (GCM) SRTP ciphers 1.
- Unified CM requires mixed mode in scenarios that also cover IP phones registered in encrypted mode 25.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Two questions. One permanent page you can send to your manager.
Step 1 Confirm release and licensing
Do
TLS 1.3 support for SIP signaling requires Cisco IOS XE 17.14.1a or later 54. CN-SAN client validation and trunk-specific TLS policies require Cisco IOS XE 17.8.1a or later 4. From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 can be used only when system mode insecure is configured 50. SRTP-SRTP interworking combined with transcoding requires Cisco IOS XE 17.6.1a or later 43.
Verify
Suggested check: run show version and review feature licenses to confirm the active operating release satisfies the target TLS and SRTP capabilities.
Rollback
Suggested rollback: no configuration changes are applied in this step, so no rollback is required.
Step 2 Generate the CUBE key pair
Do
Generate a private key pair on CUBE using crypto key generate rsa general-keys label <name> exportable 32. Use an RSA modulus of 2048 bits, which Cisco's hardening guide recommends for TLS 1.2 applications 24. Alternatively, EC keys may be generated 32.
Verify
Suggested check: verify that the key pair generation succeeded without error and that the chosen label is available for binding to a trustpoint.
Rollback
Suggested rollback: remove the generated key pair from the router configuration if it is no longer required.
Step 3 Create the CUBE identity certificate
Self-signed on both sides
Do
Create a trustpoint that references the key pair with rsakeypair and configure subject-name cn=<cube-fqdn> 55. Set enrollment selfsigned on the trustpoint and execute crypto pki enroll <trustpoint> 33.
Verify
Run show crypto pki certificates to display the certificates held in the CUBE trustpoints and verify the self-signed certificate appears 58.
Rollback
Suggested rollback: remove the self-signed trustpoint and its associated certificate from the router configuration.
Signed by a certificate authority
Do
Create an identity trustpoint specifying rsakeypair, fqdn, subject-name cn=, subject-alt-name, and enrollment terminal 55. When the certificate is issued through an intermediate CA, create separate trustpoints configured with enrollment terminal pem for the root CA and the intermediate CA, and authenticate each using crypto pki authenticate, loading the root first 2. Cisco's hardening guide recommends configuring revocation-check crl or revocation-check ocsp on trustpoints and warns that revocation-check none weakens security 23. Run crypto pki enroll <trustpoint> to produce the certificate signing request (CSR) 3. After obtaining the signed certificate from the CA, install it using crypto pki import <trustpoint> certificate 3.
Verify
Run show crypto pki certificates to confirm the CA-signed router identity certificate and CA chain certificates are present and valid 58.
Rollback
Suggested rollback: remove the identity trustpoint, intermediate trustpoint, and root trustpoint from the router configuration.
Step 4 Make CUBE trust Unified CM
Self-signed on both sides
Do
To make CUBE trust a self-signed Unified CM certificate, create a trustpoint with enrollment terminal for Unified CM and paste the CallManager certificate in with crypto pki authenticate <trustpoint> 8.
Verify
Run show crypto pki certificates to verify that the Unified CM certificate is installed under the designated trustpoint 58.
Rollback
Suggested rollback: delete the Unified CM trustpoint from CUBE.
Signed by a certificate authority
Do
When the CUBE certificate is issued through an intermediate CA, separate trustpoints with enrollment terminal pem are created for the root and the intermediate, and each is loaded with crypto pki authenticate, root first 2. On Unified CM, generate a CallManager CSR in OS Administration under Security > Certificate Management, submit it to the CA, and upload the signed result as the CallManager certificate 7. If an external peer leg requires the Cisco root CA bundle, run crypto pki trustpool import clean url https://www.cisco.com/security/pki/trs/ios_core.p7b, noting that this command clears the current CA trustpool before installing the bundle 56.
Verify
Run show crypto pki certificates to verify the CA certificates 58. If a trustpool was imported, execute show crypto pki trustpool to confirm the CA bundle installation 57.
Rollback
Suggested rollback: restore the previous CallManager certificate in Unified CM OS Administration, and re-import any prior trustpool if clean was executed.
Step 5 Make Unified CM trust CUBE
Self-signed on both sides
Do
On CUBE, execute crypto pki export <trustpoint> pem terminal to display the certificate in PEM format 18. In Unified CM OS Administration under Security > Certificate Management, upload the CUBE certificate with the certificate purpose set to CallManager-Trust 15.
Verify
Suggested check: view the certificate list in Unified CM OS Administration under Security > Certificate Management and confirm the CUBE certificate is present with the CallManager-Trust purpose.
Rollback
Suggested rollback: delete the CUBE certificate entry from the CallManager-Trust store in Unified CM OS Administration.
Signed by a certificate authority
Do
Upload the root CA and subordinate CA certificates to Unified CM as CallManager-Trust via OS Administration > Security > Certificate Management > Upload Certificate/Certificate chain 14.
Verify
Suggested check: view the certificate list in Unified CM OS Administration to confirm both the root and subordinate CA certificates are present under CallManager-Trust.
Rollback
Suggested rollback: remove the uploaded CA certificates from the CallManager-Trust store in Unified CM OS Administration if no other trunks depend on them.
Step 6 Turn on TLS signaling on CUBE
Do
On Cisco IOS XE 17.14.1a and later, use transport tcp tls v1.2 minimum under sip-ua to enable TLS 1.2 and above 52. Naming a single version such as transport tcp tls v1.2 enables only that version 52. Cisco's hardening guide recommends mapping remote TLS connections to specific trustpoints 22. CUBE SIP TLS can be configured at the global, voice class tenant and dial-peer levels 47.
Verify
Execute show sip-ua connections tcp tls brief to confirm active TLS connections once signaling starts 60.
Rollback
Suggested rollback: remove the signaling configuration under sip-ua and return the transport setting to its prior state.
Step 7 Tighten the TLS policy (optional)
Do
Restrict TLS cipher suites using voice class tls-cipher, available from Cisco IOS XE 17.3.1 46. Group the trustpoint, TLS cipher class, cn-san validate {server | client | bidirectional}, and sni send into a voice class tls-profile 53. CN-SAN client validation and trunk-specific TLS policies on CUBE were introduced in Cisco IOS XE Cupertino 17.8.1a 4. A voice class tenant can carry tls-profile, session transport tcp tls and url sips, and a dial-peer uses it through voice-class sip tenant <tag> 45.
Verify
Run show sip-ua connections tcp tls detail to view the negotiated TLS version and cipher suite 60. Use the diagnostic commands debug crypto pki, debug ssl openssl, and debug ccsip to troubleshoot TLS 16.
Rollback
Suggested rollback: remove the tls-profile assignment from the tenant configuration and delete the voice class tls-profile and voice class tls-cipher blocks.
Step 8 Configure the secure trunk on Unified CM
Do
For TLS signaling on a Unified CM SIP trunk, the SIP trunk security profile sets Device Security Mode to Encrypted and both Incoming and Outgoing Transport Type to TLS 11. The Unified CM SIP trunk security profile field Secure Certificate Subject or Subject Alternate Name holds the TLS peer's certificate subject, with multiple names separated by space, comma, semicolon or colon 13. The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate 62. The default Incoming Port for TLS in a Unified CM SIP trunk security profile is 5061 10. SRTP media on a Unified CM SIP trunk is enabled by checking SRTP Allowed on the trunk; with a non-secure profile SRTP still works but the keys are exposed in signaling and traces 12. After applying the security profile to the trunk, Save and then Apply Config resets the Unified CM trunk so the change takes effect 6.
Verify
Check the SIP trunk status on the Unified CM SIP trunk page to confirm it displays Full Service 9.
Rollback
Suggested rollback: reassign the previous non-secure SIP trunk security profile, uncheck SRTP Allowed, restore the destination port, click Save, and click Apply Config to reset the trunk.
Step 9 Choose the SRTP crypto suites
End to end (pass-through)
Do
WarmTransfer's reading of the sources is that a voice class srtp-crypto list on CUBE does not decide the negotiated suite with SRTP pass-through, because CUBE relays the endpoints' crypto attributes rather than terminating SRTP 31. CUBE passes crypto attributes, including suites it does not itself support, to the other leg unchanged when triggered by an inbound INVITE containing an m= line with RTP/SAVP 30. WarmTransfer's reading of the sources is that the two endpoints must share a suite directly 31.
Verify
Suggested check: verify with the far-end endpoint administrator which SRTP crypto suites are supported, taking into account that older devices may lack AEAD cipher support.
Rollback
Suggested rollback: no configuration is applied on CUBE in this step, so no rollback is required.
Terminated at CUBE, SRTP on both legs
Do
A voice class srtp-crypto list can be applied globally under voice service voip > sip with srtp-crypto <tag>, in a voice class tenant with srtp-crypto <tag>, or on a dial-peer with voice-class sip srtp-crypto <tag> 35. CUBE offers SRTP suites in the SDP offer in the configured preference order and, when answering, selects the highest-preference configured suite that matches the peer's offer 39. From Cisco IOS XE Everest 16.5.1b, CUBE supports the SRTP suites AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80 and AES_CM_128_HMAC_SHA1_32, in that default preference order 36. CUBE SRTP configuration on a dial-peer takes precedence over the global configuration 37. Webex Calling supports only AES_CM_128_HMAC_SHA1_80 for SRTP, so a CUBE leg to Webex Calling offers that suite alone 61.
Verify
CUBE offers SRTP suites in the SDP offer in the configured preference order and selects the highest-preference configured suite that matches the peer's offer upon answering 39.
Rollback
Suggested rollback: remove the srtp-crypto assignment from the dial-peer, tenant, or global voice service voip configuration.
Terminated at CUBE, plain RTP on the far leg
Do
A voice class srtp-crypto list can be applied globally under voice service voip > sip with srtp-crypto <tag>, in a voice class tenant with srtp-crypto <tag>, or on a dial-peer with voice-class sip srtp-crypto <tag> 35. Apply the list to the secure Unified CM leg, leaving the RTP leg without srtp configuration 41.
Verify
Suggested check: inspect the dial-peer configuration to confirm voice-class sip srtp-crypto is bound solely to the secure dial-peer facing Unified CM.
Rollback
Suggested rollback: remove voice-class sip srtp-crypto <tag> from the Unified CM dial-peer.
Step 10 Secure the dial-peers
End to end (pass-through)
Do
SRTP pass-through is enabled with srtp pass-thru either on a dial-peer or globally under voice service voip 27. SRTP pass-through must be configured on both call legs; if the target leg does not support it, CUBE rejects the call with 415 Unsupported Media Type 26. When SRTP pass-through is enabled, CUBE does not support media interworking on the call 29. On the CUBE dial-peer toward Unified CM, session transport tcp tls selects TLS signaling and srtp enables secure media 17. WarmTransfer's reading of the sources is that because SRTP keys travel in the SDP crypto attributes, both legs of an SRTP call through CUBE need TLS signaling to keep the keys out of cleartext; pass-through does not remove that need 28.
Verify
Place a test call and execute show call active voice brief to confirm SRTP: on is displayed for each call leg 59. Verify that calls are not rejected with 415 Unsupported Media Type 26.
Rollback
Suggested rollback: remove srtp pass-thru from both dial-peers (or under voice service voip) simultaneously, and remove session transport tcp tls from the dial-peer.
Terminated at CUBE, SRTP on both legs
Do
On the CUBE dial-peer toward Unified CM, session transport tcp tls selects TLS signaling and srtp enables secure media 17. On the far-end dial-peer, srtp enables secure calls on the dial-peer 63. Cisco's CUBE hardening guide says SIP TLS and SRTP should be enabled on all call legs through CUBE, because security is only as strong as the weakest link 19. With srtp configured under voice service voip, CUBE's default behaviour is to disallow fallback to RTP 42. CUBE SRTP-SRTP interworking does not support asymmetric SRTP fallback, Call Progress Analysis, or GCM ciphers with extension headers 40. A voice class tenant can carry tls-profile, session transport tcp tls and url sips, and a dial-peer uses it through voice-class sip tenant <tag> 45.
Verify
Execute show call active voice brief during an active call to confirm SRTP: on is shown on each call leg 59.
Rollback
Suggested rollback: remove srtp and session transport tcp tls from both dial-peers or the tenant profile.
Terminated at CUBE, plain RTP on the far leg
Do
On the CUBE dial-peer toward Unified CM, session transport tcp tls selects TLS signaling and srtp enables secure media 17. CUBE SRTP-RTP interworking connects an SRTP leg to an RTP leg by enabling srtp only on the secure-side dial-peer, and on IOS XE platforms it needs no DSP resources 41. To allow fallback from SRTP to RTP with Unified CM, CUBE uses srtp fallback together with voice-class sip srtp negotiate cisco on the dial-peer 38.
Verify
Execute show call active voice brief during a live call to confirm SRTP: on or SRTP: off for each call leg 59.
Rollback
Suggested rollback: remove srtp, srtp fallback, and the negotiation setting from the dial-peer, and revert session transport tcp tls.
Step 11 Close the non-secure SIP transports
End to end (pass-through)
Do
If all configured trunks and call legs on CUBE use TLS, apply Cisco's hardening guide recommendation to disable non-secure SIP ports by configuring no transport udp and no transport tcp under sip-ua 21.
Verify
Execute show sip-ua connections tcp tls brief to confirm active TLS signaling connections remain online 60. Suggested check: place test calls across all configured trunks to ensure no trunk traffic is dropped.
Rollback
Suggested rollback: re-enable unencrypted transport ports by configuring transport udp and transport tcp under sip-ua 21.
Terminated at CUBE, SRTP on both legs
Do
If all configured trunks and call legs on CUBE use TLS, apply Cisco's hardening guide recommendation to disable non-secure SIP ports by configuring no transport udp and no transport tcp under sip-ua 21.
Verify
Execute show sip-ua connections tcp tls brief to confirm active TLS signaling connections remain online 60. Suggested check: place test calls across all configured trunks to ensure no trunk traffic is dropped.
Rollback
Suggested rollback: re-enable unencrypted transport ports by configuring transport udp and transport tcp under sip-ua 21.
Terminated at CUBE, plain RTP on the far leg
Do
Do not disable UDP or TCP under sip-ua if the unencrypted RTP call leg depends on unencrypted SIP signaling transports, as no transport udp and no transport tcp disable non-secure SIP ports globally on the router 21.
Verify
Suggested check: verify that non-secure signaling is retained for the plain RTP leg while TLS is maintained for the secure Unified CM leg.
Rollback
Suggested rollback: no configuration is applied in this step, so no rollback is required.
Step 12 Verify TLS end to end
Do
Execute show sip-ua connections tcp tls brief and show sip-ua connections tcp tls detail to inspect active TLS signaling sockets 60. Execute show crypto pki certificates to check the certificates held in CUBE trustpoints 58. Cisco's enterprise-CA technote uses debug crypto pki, debug ssl openssl, debug srtp and debug ccsip to troubleshoot CUBE TLS and SRTP 16.
Verify
show sip-ua connections tcp tls brief and show sip-ua connections tcp tls detail verify CUBE TLS connections, and the detail output shows the negotiated TLS version and cipher suite 60. A working secure trunk between Unified CM and CUBE shows status Full Service on the Unified CM SIP trunk page 9. The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate 62.
Rollback
Suggested rollback: diagnostic step only; no configuration rollback is needed.
Step 13 Verify SRTP on a live call
Do
show call active voice brief shows SRTP: on or SRTP: off for each call leg 59. show sip-ua calls shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg 44. Cisco's enterprise-CA technote uses debug crypto pki, debug ssl openssl, debug srtp and debug ccsip to troubleshoot CUBE TLS and SRTP 16.
Verify
show call active voice brief shows SRTP: on or SRTP: off for each call leg 59. show sip-ua calls shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg 44.
Rollback
Suggested rollback: diagnostic step only; no configuration rollback is needed.
Applicability
Applies to: Cisco Unified Border Element, Cisco Unified Communications Manager, Cisco IOS XE, and Cisco Webex Calling Local Gateway. Deployments: on-premises and multi-tenant. Sources checked 2026-09-30. Specific features and release boundaries cited across the claims include:
- TLS 1.3 support on CUBE requires Cisco IOS XE 17.14.1a or later 54.
- CN-SAN validation and per-trunk TLS policies require Cisco IOS XE 17.8.1a or later 4.
- Restricting TLS cipher suites using
voice class tls-cipheris available from Cisco IOS XE 17.3.1 46. - From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 require
system mode insecure50. - SRTP-SRTP interworking combined with transcoding is supported from Cisco IOS XE 17.6.1a 43.
- SRTP-SRTP interworking and SRTP-RTP interworking suites were introduced in Cisco IOS XE Everest 16.5.1b 36 41.
What remains uncertain
- Whether a Unified CM cluster must be in mixed mode solely for a secure SIP trunk without encrypted phones is not covered by the sources below.
- Specific throughput thresholds and hardware crypto licensing capacities for Cisco ISR 4000 or Catalyst 8000 series platforms are not covered by the sources below.
- Certificate lifecycle automation, SCEP or EST enrollment, and automated expiry monitoring on CUBE are not covered by the sources below.
See also
Configures
- Cisco unified border elementstub — Guide for enabling TLS signaling and SRTP media on CUBE toward a secure Unified CM trunk.
Referenced by
- Setting up SIPREC forking on CUBE for call recording — Leg media security decides which leg SIPREC can fork
- Troubleshooting SRTP and crypto negotiation failuresstub — Setup guide for CUBE TLS/SRTP; this topic covers what goes wrong after setup
Sources
- 1Cisco's CUBE hardening guide notes that some older Cisco devices or peer devices may not support the AEAD (GCM) SRTP ciphers.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Trim unsecure SRTP Ciphers · Checked 2026-09-30
- 2When the CUBE certificate is issued through an intermediate CA, separate trustpoints with enrollment terminal pem are created for the root and the intermediate, and each is loaded with crypto pki authenticate, root first.Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates · Configure > Configuration steps, root and intermediate CA trustpoint steps · Checked 2026-09-30
- 3For a CA-signed CUBE certificate, crypto pki enroll <trustpoint> produces the certificate signing request and crypto pki import <trustpoint> certificate installs the signed certificate.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Certificate configuration > Step 3 generate and import certificate · Checked 2026-09-30
- 4CN-SAN client validation and trunk-specific TLS policies on CUBE were introduced in Cisco IOS XE Cupertino 17.8.1a.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > feature information by release (17.8.1a row) · Checked 2026-09-30
- 5The sip-ua command crypto signaling {remote-addr <ip> <mask> | default} [tls-profile <tag> | trustpoint <name>] selects the trustpoint or TLS profile CUBE uses for TLS connections, either for all peers or for a specific remote address.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support (PDF m_sip_tls_support_cube.pdf) > configuration task, crypto signaling step · Checked 2026-09-30
- 6After applying the security profile to the trunk, Save and then Apply Config resets the Unified CM trunk so the change takes effect.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · Deployment steps > apply profile, Save, Apply Config · Checked 2026-09-30
- 7For a CA-signed Unified CM certificate, a CallManager CSR is generated in OS Administration under Security > Certificate Management and the signed result is uploaded as the CallManager certificate.Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates · Configure > CUCM configuration steps (CSR and upload) · Checked 2026-09-30
- 8To make CUBE trust a self-signed Unified CM certificate, a trustpoint with enrollment terminal is created for Unified CM and the CallManager certificate is pasted in with crypto pki authenticate <trustpoint>.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, step 6 · Checked 2026-09-30
- 9A working secure trunk between Unified CM and CUBE shows status Full Service on the Unified CM SIP trunk page.Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates · Verify · Checked 2026-09-30
- 10The default Incoming Port for TLS in a Unified CM SIP trunk security profile is 5061.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile configuration > Incoming Port · Checked 2026-09-30
- 11For TLS signaling on a Unified CM SIP trunk, the SIP trunk security profile sets Device Security Mode to Encrypted and both Incoming and Outgoing Transport Type to TLS.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile configuration > Device Security Mode, Incoming/Outgoing Transport Type · Checked 2026-09-30
- 12SRTP media on a Unified CM SIP trunk is enabled by checking SRTP Allowed on the trunk; with a non-secure profile SRTP still works but the keys are exposed in signaling and traces.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP trunk security > SRTP Allowed check box note · Checked 2026-09-30
- 13The Unified CM SIP trunk security profile field Secure Certificate Subject or Subject Alternate Name holds the TLS peer's certificate subject, with multiple names separated by space, comma, semicolon or colon.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP Trunk Security Profile configuration > Secure Certificate Subject or Subject Alternate Name · Checked 2026-09-30
- 14With enterprise CA-signed certificates, the root CA and subordinate CA certificates are uploaded to Unified CM as CallManager-Trust via OS Administration > Security > Certificate Management > Upload Certificate/Certificate chain.Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE · Configure > upload of Root CA and Subordinate CA certificates to CUCM · Checked 2026-09-30
- 15The self-signed CUBE certificate is uploaded in Unified CM OS Administration under Security > Certificate Management with certificate purpose CallManager-Trust.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, step 4 · Checked 2026-09-30
- 16Cisco's enterprise-CA technote uses debug crypto pki, debug ssl openssl, debug srtp and debug ccsip to troubleshoot CUBE TLS and SRTP.Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE · Troubleshoot · Checked 2026-09-30
- 17On the CUBE dial-peer toward Unified CM, session transport tcp tls selects TLS signaling and srtp enables secure media.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, step 8 · Checked 2026-09-30
- 18crypto pki export <trustpoint> pem terminal prints the CUBE certificate in PEM format so it can be copied to Unified CM.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, step 3 · Checked 2026-09-30
- 19Cisco's CUBE hardening guide says SIP TLS and SRTP should be enabled on all call legs through CUBE, because security is only as strong as the weakest link.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Use TCP TLS and SRTP · Checked 2026-09-30
- 20Cisco's CUBE hardening guide recommends CA-signed certificates in place of self-signed certificates.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Utilize Certificate Authority (CA) Signed Certificates · Checked 2026-09-30
- 21Cisco's CUBE hardening guide recommends disabling non-secure SIP ports with no transport udp and no transport tcp under sip-ua.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Disable Non-Secure SIP Ports · Checked 2026-09-30
- 22Cisco's CUBE hardening guide recommends mapping remote TLS connections to specific trustpoints.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Map remote TLS connections to specific trustpoints · Checked 2026-09-30
- 23Cisco's CUBE hardening guide recommends revocation-check crl or ocsp on trustpoints and warns that revocation-check none weakens security.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Enable Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) Checks · Checked 2026-09-30
- 24Cisco's CUBE hardening guide recommends an RSA modulus of 2048 bits for TLS 1.2 applications.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Utilize large cryptographic keys · Checked 2026-09-30
- 25Cisco's enterprise-CA technote lists a Unified CM cluster in mixed mode as a prerequisite for its scenario, which also covers IP phones registered in encrypted mode.Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE · Prerequisites > Requirements · Checked 2026-09-30
- 26SRTP pass-through must be configured on both call legs; if the target leg does not support it, CUBE rejects the call with 415 Unsupported Media Type.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through · SRTP-SRTP Pass-Through > Restrictions · Checked 2026-09-30
- 27SRTP pass-through is enabled with srtp pass-thru either on a dial-peer or globally under voice service voip.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through · SRTP-SRTP Pass-Through > configuration for specific dial peers; global configuration · Checked 2026-09-30
- 28Because SRTP keys travel in the SDP crypto attributes, both legs of an SRTP call through CUBE need TLS signaling to keep the keys out of cleartext; pass-through does not remove that need.inferredSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security · SIP trunk security > SRTP Allowed check box note (read with SRTP-SRTP Pass-Through > Overview) · Checked 2026-09-30
- 29When SRTP pass-through is enabled, CUBE does not support media interworking on the call.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through · SRTP-SRTP Pass-Through > Restrictions · Checked 2026-09-30
- 30SRTP pass-through is triggered only when the inbound INVITE carries an m= line with RTP/SAVP, and CUBE passes the crypto attributes, including suites it does not itself support, to the other leg unchanged.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through · SRTP-SRTP Pass-Through > Pass-Through of Unsupported Crypto Suites · Checked 2026-09-30
- 31With SRTP pass-through, a voice class srtp-crypto list on CUBE does not decide the negotiated suite, because CUBE relays the endpoints' crypto attributes rather than terminating SRTP; the two endpoints must share a suite.inferredCisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through · SRTP-SRTP Pass-Through > Pass-Through of Unsupported Crypto Suites (read with SRTP-SRTP Interworking offer/answer) · Checked 2026-09-30
- 32The CUBE certificate procedure starts by creating a private key with crypto key generate rsa general-keys label <name> exportable; EC keys are an optional alternative.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Certificate configuration > Step 1 create private key · Checked 2026-09-30
- 33A self-signed CUBE certificate is created by setting enrollment selfsigned on the trustpoint and running crypto pki enroll <trustpoint>.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, steps 1 and 2 · Checked 2026-09-30
- 34From Cisco IOS XE Everest 16.5.1b the srtp-auth command is deprecated: it is still accepted but causes no configuration change, and voice class srtp-crypto replaces it.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking · SRTP-RTP Interworking > Configure Crypto Authentication (deprecation note) · Checked 2026-09-30
- 35A voice class srtp-crypto list can be applied globally under voice service voip > sip with srtp-crypto <tag>, in a voice class tenant with srtp-crypto <tag>, or on a dial-peer with voice-class sip srtp-crypto <tag>.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Configure SRTP-SRTP Interworking · Checked 2026-09-30
- 36From Cisco IOS XE Everest 16.5.1b, CUBE supports the SRTP suites AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80 and AES_CM_128_HMAC_SHA1_32, in that default preference order.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Overview · Checked 2026-09-30
- 37CUBE SRTP configuration on a dial-peer takes precedence over the global configuration.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking · SRTP-RTP Interworking > Configure Crypto Authentication · Checked 2026-09-30
- 38To allow fallback from SRTP to RTP with Unified CM, CUBE uses srtp fallback together with voice-class sip srtp negotiate cisco on the dial-peer.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking · SRTP-RTP Interworking > Enable SRTP Fallback · Checked 2026-09-30
- 39CUBE offers SRTP suites in the SDP offer in the configured preference order and, when answering, selects the highest-preference configured suite that matches the peer's offer.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Configure SRTP-SRTP Interworking (crypto preference) · Checked 2026-09-30
- 40CUBE SRTP-SRTP interworking does not support asymmetric SRTP fallback, Call Progress Analysis, or GCM ciphers with extension headers.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Restrictions · Checked 2026-09-30
- 41CUBE SRTP-RTP interworking connects an SRTP leg to an RTP leg by enabling srtp only on the secure-side dial-peer, and on IOS XE platforms it needs no DSP resources.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking · SRTP-RTP Interworking > Overview, Prerequisites, Configure SRTP-RTP Interworking · Checked 2026-09-30
- 42With srtp configured under voice service voip, CUBE's default behaviour is to disallow fallback to RTP.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Enforce Strict SRTP · Checked 2026-09-30
- 43SRTP-SRTP interworking combined with transcoding is supported only from Cisco IOS XE 17.6.1a.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Restrictions · Checked 2026-09-30
- 44show sip-ua calls shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · SRTP-SRTP Interworking > Configuration Examples (show sip-ua calls output) · Checked 2026-09-30
- 45A voice class tenant can carry tls-profile, session transport tcp tls and url sips, and a dial-peer uses it through voice-class sip tenant <tag>.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Tenant and dial-peer configuration · Checked 2026-09-30
- 46TLS cipher suites for CUBE are restricted with voice class tls-cipher, available from Cisco IOS XE 17.3.1 according to the hardening guide.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Enforce TLS Ciphers · Checked 2026-09-30
- 47CUBE SIP TLS can be configured at the global, voice class tenant and dial-peer levels.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Overview · Checked 2026-09-30
- 48When transport tcp tls is configured under sip-ua without a version, CUBE negotiates TLS 1.2 and 1.3; from IOS XE 26.1.1, TLS 1.0 and 1.1 are excluded from that default.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Global SIP-UA configuration > TLS version modes (Default) · Checked 2026-09-30
- 49CUBE logs %SIP-2-TLS_HANDSHAKE_FAILED when a TLS handshake fails, including on certificate identity validation failure.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Syslog events · Checked 2026-09-30
- 50From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 on CUBE can be used only when system mode insecure is configured.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > feature information by release (26.1.1 row) · Checked 2026-09-30
- 51The CUBE SIP TLS chapter lists a security license as required on Cisco 4000 series ISRs and an HSEC license for high call volumes.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Restrictions · Checked 2026-09-30
- 52The sip-ua command transport tcp tls v1.2 minimum enables TLS 1.2 and above, while naming a single version without minimum enables only that version.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Global SIP-UA configuration > TLS version modes (Exclusive, Minimum) · Checked 2026-09-30
- 53A voice class tls-profile groups a trustpoint, a tls-cipher class, cn-san validate {server | client | bidirectional} and sni send for use by a tenant or crypto signaling.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > TLS profile configuration · Checked 2026-09-30
- 54TLS 1.3 support for CUBE SIP signaling was introduced in Cisco IOS XE 17.14.1a.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > feature information by release (17.14.1a row) · Checked 2026-09-30
- 55The CUBE identity trustpoint in the configuration guide names the key pair with rsakeypair and sets fqdn, subject-name cn=, subject-alt-name and enrollment terminal.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Certificate configuration > Step 2 create trustpoint · Checked 2026-09-30
- 56crypto pki trustpool import clean url https://www.cisco.com/security/pki/trs/ios_core.p7b clears the current CA trustpool and installs the Cisco root CA bundle.Configure Local Gateway on Cisco IOS XE for Webex Calling · Import Cisco Root Certificate Authority bundle · Checked 2026-09-30
- 57show crypto pki trustpool confirms that the CA bundle was imported.Configure Local Gateway on Cisco IOS XE for Webex Calling · Verification commands > Verify trustpool installation · Checked 2026-09-30
- 58show crypto pki certificates displays the certificates held in CUBE trustpoints.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Verification · Checked 2026-09-30
- 59show call active voice brief shows SRTP: on or SRTP: off for each call leg.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking · SRTP-RTP Interworking > Verify SRTP-RTP · Checked 2026-09-30
- 60show sip-ua connections tcp tls brief and show sip-ua connections tcp tls detail verify CUBE TLS connections, and the detail output shows the negotiated TLS version and cipher suite.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · SIP TLS Support > Verification · Checked 2026-09-30
- 61Webex Calling supports only AES_CM_128_HMAC_SHA1_80 for SRTP, so a CUBE leg to Webex Calling offers that suite alone.Configure Local Gateway on Cisco IOS XE for Webex Calling · SRTP media encryption > voice class srtp-crypto 100 · Checked 2026-09-30
- 62The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate.Configure SIP TLS between CUCM-CUBE/CUBE-SBC · Configure > Configuration steps, SIP trunk security profile step · Checked 2026-09-30
- 63CUBE's voice class srtp-crypto lists preferred SRTP suites (AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32) and can be applied globally under voice service voip sip, in a voice class tenant, or per dial-peer with voice-class sip srtp-crypto, with 'srtp' enabling secure calls on the dial-peer.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · Voice class srtp-crypto configuration; application at global, tenant and dial-peer levels · Checked 2026-09-30
Documents
Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through
Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE
Configure Local Gateway on Cisco IOS XE for Webex Calling
Configure SIP TLS between CUCM-CUBE/CUBE-SBC
Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security
Cite this page
APA
WarmTransfer. (2026, September 30). Setting up TLS and SRTP on CUBE. WarmTransfer. https://warmtransfer.net/guides/cube-tls-srtp-setup
BibTeX
@misc{warmtransfer-cube-tls-srtp-setup,
title = {Setting up TLS and SRTP on CUBE},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cube-tls-srtp-setup},
note = {Verified 2026-09-30}
}