# Setting up TLS and SRTP on CUBE

Systems: Cisco Unified Border Element

For Voice engineers administering CUBE on Cisco IOS XE with administrative access to the connected Unified CM trunk.

Canonical: https://warmtransfer.net/guides/cube-tls-srtp-setup

Last verified: 2026-09-30

This guide steps through configuring SIP TLS signaling and SRTP media on Cisco Unified Border Element (CUBE) facing a Cisco Unified Communications Manager (Unified CM) SIP trunk[^17][^11]. It details certificate exchange, dial-peer security, SRTP crypto policies, and live verification on Cisco IOS XE[^55][^59].

## Before you start

- Cisco's hardening guide recommends CA-signed certificates over self-signed certificates[^20].
- Cisco's hardening guide notes that some older Cisco devices or peer devices may not support AEAD (GCM) SRTP ciphers[^1].
- Unified CM requires mixed mode in scenarios that also cover IP phones registered in encrypted mode[^25].

## What changes by situation

- How will the CUBE and Unified CM certificates be signed? Self-signed on both sides; Signed by a certificate authority.
- Where is SRTP encrypted and decrypted? End to end (pass-through); Terminated at CUBE, SRTP on both legs; Terminated at CUBE, plain RTP on the far leg.

## Step 1: Confirm release and licensing

### Do
TLS 1.3 support for SIP signaling requires Cisco IOS XE 17.14.1a or later[^54]. CN-SAN client validation and trunk-specific TLS policies require Cisco IOS XE 17.8.1a or later[^4]. From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 can be used only when `system mode insecure` is configured[^50]. SRTP-SRTP interworking combined with transcoding requires Cisco IOS XE 17.6.1a or later[^43].

### Verify
Suggested check: run `show version` and review feature licenses to confirm the active operating release satisfies the target TLS and SRTP capabilities.

### Rollback
Suggested rollback: no configuration changes are applied in this step, so no rollback is required.

## Step 2: Generate the CUBE key pair

### Do
Generate a private key pair on CUBE using `crypto key generate rsa general-keys label <name> exportable`[^32]. Use an RSA modulus of 2048 bits, which Cisco's hardening guide recommends for TLS 1.2 applications[^24]. Alternatively, EC keys may be generated[^32].

### Verify
Suggested check: verify that the key pair generation succeeded without error and that the chosen label is available for binding to a trustpoint.

### Rollback
Suggested rollback: remove the generated key pair from the router configuration if it is no longer required.

## Step 3: Create the CUBE identity certificate

**Self-signed on both sides**

### Do
Create a trustpoint that references the key pair with `rsakeypair` and configure `subject-name cn=<cube-fqdn>`[^55]. Set `enrollment selfsigned` on the trustpoint and execute `crypto pki enroll <trustpoint>`[^33].

### Verify
Run `show crypto pki certificates` to display the certificates held in the CUBE trustpoints and verify the self-signed certificate appears[^58].

### Rollback
Suggested rollback: remove the self-signed trustpoint and its associated certificate from the router configuration.

**Signed by a certificate authority**

### Do
Create an identity trustpoint specifying `rsakeypair`, `fqdn`, `subject-name cn=`, `subject-alt-name`, and `enrollment terminal`[^55]. When the certificate is issued through an intermediate CA, create separate trustpoints configured with `enrollment terminal pem` for the root CA and the intermediate CA, and authenticate each using `crypto pki authenticate`, loading the root first[^2]. Cisco's hardening guide recommends configuring `revocation-check crl` or `revocation-check ocsp` on trustpoints and warns that `revocation-check none` weakens security[^23]. Run `crypto pki enroll <trustpoint>` to produce the certificate signing request (CSR)[^3]. After obtaining the signed certificate from the CA, install it using `crypto pki import <trustpoint> certificate`[^3].

### Verify
Run `show crypto pki certificates` to confirm the CA-signed router identity certificate and CA chain certificates are present and valid[^58].

### Rollback
Suggested rollback: remove the identity trustpoint, intermediate trustpoint, and root trustpoint from the router configuration.

## Step 4: Make CUBE trust Unified CM

**Self-signed on both sides**

### Do
To make CUBE trust a self-signed Unified CM certificate, create a trustpoint with `enrollment terminal` for Unified CM and paste the CallManager certificate in with `crypto pki authenticate <trustpoint>`[^8].

### Verify
Run `show crypto pki certificates` to verify that the Unified CM certificate is installed under the designated trustpoint[^58].

### Rollback
Suggested rollback: delete the Unified CM trustpoint from CUBE.

**Signed by a certificate authority**

### Do
When the CUBE certificate is issued through an intermediate CA, separate trustpoints with `enrollment terminal pem` are created for the root and the intermediate, and each is loaded with `crypto pki authenticate`, root first[^2]. On Unified CM, generate a CallManager CSR in OS Administration under Security > Certificate Management, submit it to the CA, and upload the signed result as the CallManager certificate[^7]. If an external peer leg requires the Cisco root CA bundle, run `crypto pki trustpool import clean url https://www.cisco.com/security/pki/trs/ios_core.p7b`, noting that this command clears the current CA trustpool before installing the bundle[^56].

### Verify
Run `show crypto pki certificates` to verify the CA certificates[^58]. If a trustpool was imported, execute `show crypto pki trustpool` to confirm the CA bundle installation[^57].

### Rollback
Suggested rollback: restore the previous CallManager certificate in Unified CM OS Administration, and re-import any prior trustpool if `clean` was executed.

## Step 5: Make Unified CM trust CUBE

**Self-signed on both sides**

### Do
On CUBE, execute `crypto pki export <trustpoint> pem terminal` to display the certificate in PEM format[^18]. In Unified CM OS Administration under Security > Certificate Management, upload the CUBE certificate with the certificate purpose set to CallManager-Trust[^15].

### Verify
Suggested check: view the certificate list in Unified CM OS Administration under Security > Certificate Management and confirm the CUBE certificate is present with the CallManager-Trust purpose.

### Rollback
Suggested rollback: delete the CUBE certificate entry from the CallManager-Trust store in Unified CM OS Administration.

**Signed by a certificate authority**

### Do
Upload the root CA and subordinate CA certificates to Unified CM as CallManager-Trust via OS Administration > Security > Certificate Management > Upload Certificate/Certificate chain[^14].

### Verify
Suggested check: view the certificate list in Unified CM OS Administration to confirm both the root and subordinate CA certificates are present under CallManager-Trust.

### Rollback
Suggested rollback: remove the uploaded CA certificates from the CallManager-Trust store in Unified CM OS Administration if no other trunks depend on them.

## Step 6: Turn on TLS signaling on CUBE

### Do
On Cisco IOS XE 17.14.1a and later, use `transport tcp tls v1.2 minimum` under `sip-ua` to enable TLS 1.2 and above[^52]. Naming a single version such as `transport tcp tls v1.2` enables only that version[^52]. Cisco's hardening guide recommends mapping remote TLS connections to specific trustpoints[^22]. CUBE SIP TLS can be configured at the global, voice class tenant and dial-peer levels[^47].

### Verify
Execute `show sip-ua connections tcp tls brief` to confirm active TLS connections once signaling starts[^60].

### Rollback
Suggested rollback: remove the signaling configuration under `sip-ua` and return the transport setting to its prior state.

## Step 7: Tighten the TLS policy (optional)

### Do
Restrict TLS cipher suites using `voice class tls-cipher`, available from Cisco IOS XE 17.3.1[^46]. Group the trustpoint, TLS cipher class, `cn-san validate {server | client | bidirectional}`, and `sni send` into a `voice class tls-profile`[^53]. CN-SAN client validation and trunk-specific TLS policies on CUBE were introduced in Cisco IOS XE Cupertino 17.8.1a[^4]. A voice class tenant can carry `tls-profile`, `session transport tcp tls` and `url sips`, and a dial-peer uses it through `voice-class sip tenant <tag>`[^45].

### Verify
Run `show sip-ua connections tcp tls detail` to view the negotiated TLS version and cipher suite[^60]. Use the diagnostic commands `debug crypto pki`, `debug ssl openssl`, and `debug ccsip` to troubleshoot TLS[^16].

### Rollback
Suggested rollback: remove the `tls-profile` assignment from the tenant configuration and delete the `voice class tls-profile` and `voice class tls-cipher` blocks.

## Step 8: Configure the secure trunk on Unified CM

### Do
For TLS signaling on a Unified CM SIP trunk, the SIP trunk security profile sets Device Security Mode to Encrypted and both Incoming and Outgoing Transport Type to TLS[^11]. The Unified CM SIP trunk security profile field Secure Certificate Subject or Subject Alternate Name holds the TLS peer's certificate subject, with multiple names separated by space, comma, semicolon or colon[^13]. The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate[^62]. The default Incoming Port for TLS in a Unified CM SIP trunk security profile is 5061[^10]. SRTP media on a Unified CM SIP trunk is enabled by checking SRTP Allowed on the trunk; with a non-secure profile SRTP still works but the keys are exposed in signaling and traces[^12]. After applying the security profile to the trunk, Save and then Apply Config resets the Unified CM trunk so the change takes effect[^6].

### Verify
Check the SIP trunk status on the Unified CM SIP trunk page to confirm it displays Full Service[^9].

### Rollback
Suggested rollback: reassign the previous non-secure SIP trunk security profile, uncheck SRTP Allowed, restore the destination port, click Save, and click Apply Config to reset the trunk.

## Step 9: Choose the SRTP crypto suites

**End to end (pass-through)**

### Do
WarmTransfer's reading of the sources is that a `voice class srtp-crypto` list on CUBE does not decide the negotiated suite with SRTP pass-through, because CUBE relays the endpoints' crypto attributes rather than terminating SRTP[^31]. CUBE passes crypto attributes, including suites it does not itself support, to the other leg unchanged when triggered by an inbound INVITE containing an `m=` line with `RTP/SAVP`[^30]. WarmTransfer's reading of the sources is that the two endpoints must share a suite directly[^31].

### Verify
Suggested check: verify with the far-end endpoint administrator which SRTP crypto suites are supported, taking into account that older devices may lack AEAD cipher support.

### Rollback
Suggested rollback: no configuration is applied on CUBE in this step, so no rollback is required.

**Terminated at CUBE, SRTP on both legs**

### Do
A `voice class srtp-crypto` list can be applied globally under `voice service voip` > `sip` with `srtp-crypto <tag>`, in a `voice class tenant` with `srtp-crypto <tag>`, or on a dial-peer with `voice-class sip srtp-crypto <tag>`[^35]. CUBE offers SRTP suites in the SDP offer in the configured preference order and, when answering, selects the highest-preference configured suite that matches the peer's offer[^39]. From Cisco IOS XE Everest 16.5.1b, CUBE supports the SRTP suites AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80 and AES_CM_128_HMAC_SHA1_32, in that default preference order[^36]. CUBE SRTP configuration on a dial-peer takes precedence over the global configuration[^37]. Webex Calling supports only AES_CM_128_HMAC_SHA1_80 for SRTP, so a CUBE leg to Webex Calling offers that suite alone[^61].

### Verify
CUBE offers SRTP suites in the SDP offer in the configured preference order and selects the highest-preference configured suite that matches the peer's offer upon answering[^39].

### Rollback
Suggested rollback: remove the `srtp-crypto` assignment from the dial-peer, tenant, or global `voice service voip` configuration.

**Terminated at CUBE, plain RTP on the far leg**

### Do
A `voice class srtp-crypto` list can be applied globally under `voice service voip` > `sip` with `srtp-crypto <tag>`, in a `voice class tenant` with `srtp-crypto <tag>`, or on a dial-peer with `voice-class sip srtp-crypto <tag>`[^35]. Apply the list to the secure Unified CM leg, leaving the RTP leg without `srtp` configuration[^41].

### Verify
Suggested check: inspect the dial-peer configuration to confirm `voice-class sip srtp-crypto` is bound solely to the secure dial-peer facing Unified CM.

### Rollback
Suggested rollback: remove `voice-class sip srtp-crypto <tag>` from the Unified CM dial-peer.

## Step 10: Secure the dial-peers

**End to end (pass-through)**

### Do
SRTP pass-through is enabled with `srtp pass-thru` either on a dial-peer or globally under `voice service voip`[^27]. SRTP pass-through must be configured on both call legs; if the target leg does not support it, CUBE rejects the call with 415 Unsupported Media Type[^26]. When SRTP pass-through is enabled, CUBE does not support media interworking on the call[^29]. On the CUBE dial-peer toward Unified CM, `session transport tcp tls` selects TLS signaling and `srtp` enables secure media[^17]. WarmTransfer's reading of the sources is that because SRTP keys travel in the SDP crypto attributes, both legs of an SRTP call through CUBE need TLS signaling to keep the keys out of cleartext; pass-through does not remove that need[^28].

### Verify
Place a test call and execute `show call active voice brief` to confirm `SRTP: on` is displayed for each call leg[^59]. Verify that calls are not rejected with 415 Unsupported Media Type[^26].

### Rollback
Suggested rollback: remove `srtp pass-thru` from both dial-peers (or under `voice service voip`) simultaneously, and remove `session transport tcp tls` from the dial-peer.

**Terminated at CUBE, SRTP on both legs**

### Do
On the CUBE dial-peer toward Unified CM, `session transport tcp tls` selects TLS signaling and `srtp` enables secure media[^17]. On the far-end dial-peer, `srtp` enables secure calls on the dial-peer[^63]. Cisco's CUBE hardening guide says SIP TLS and SRTP should be enabled on all call legs through CUBE, because security is only as strong as the weakest link[^19]. With `srtp` configured under `voice service voip`, CUBE's default behaviour is to disallow fallback to RTP[^42]. CUBE SRTP-SRTP interworking does not support asymmetric SRTP fallback, Call Progress Analysis, or GCM ciphers with extension headers[^40]. A `voice class tenant` can carry `tls-profile`, `session transport tcp tls` and `url sips`, and a dial-peer uses it through `voice-class sip tenant <tag>`[^45].

### Verify
Execute `show call active voice brief` during an active call to confirm `SRTP: on` is shown on each call leg[^59].

### Rollback
Suggested rollback: remove `srtp` and `session transport tcp tls` from both dial-peers or the tenant profile.

**Terminated at CUBE, plain RTP on the far leg**

### Do
On the CUBE dial-peer toward Unified CM, `session transport tcp tls` selects TLS signaling and `srtp` enables secure media[^17]. CUBE SRTP-RTP interworking connects an SRTP leg to an RTP leg by enabling `srtp` only on the secure-side dial-peer, and on IOS XE platforms it needs no DSP resources[^41]. To allow fallback from SRTP to RTP with Unified CM, CUBE uses `srtp fallback` together with `voice-class sip srtp negotiate cisco` on the dial-peer[^38].

### Verify
Execute `show call active voice brief` during a live call to confirm `SRTP: on` or `SRTP: off` for each call leg[^59].

### Rollback
Suggested rollback: remove `srtp`, `srtp fallback`, and the negotiation setting from the dial-peer, and revert `session transport tcp tls`.

## Step 11: Close the non-secure SIP transports

**End to end (pass-through)**

### Do
If all configured trunks and call legs on CUBE use TLS, apply Cisco's hardening guide recommendation to disable non-secure SIP ports by configuring `no transport udp` and `no transport tcp` under `sip-ua`[^21].

### Verify
Execute `show sip-ua connections tcp tls brief` to confirm active TLS signaling connections remain online[^60]. Suggested check: place test calls across all configured trunks to ensure no trunk traffic is dropped.

### Rollback
Suggested rollback: re-enable unencrypted transport ports by configuring `transport udp` and `transport tcp` under `sip-ua`[^21].

**Terminated at CUBE, SRTP on both legs**

### Do
If all configured trunks and call legs on CUBE use TLS, apply Cisco's hardening guide recommendation to disable non-secure SIP ports by configuring `no transport udp` and `no transport tcp` under `sip-ua`[^21].

### Verify
Execute `show sip-ua connections tcp tls brief` to confirm active TLS signaling connections remain online[^60]. Suggested check: place test calls across all configured trunks to ensure no trunk traffic is dropped.

### Rollback
Suggested rollback: re-enable unencrypted transport ports by configuring `transport udp` and `transport tcp` under `sip-ua`[^21].

**Terminated at CUBE, plain RTP on the far leg**

### Do
Do not disable UDP or TCP under `sip-ua` if the unencrypted RTP call leg depends on unencrypted SIP signaling transports, as `no transport udp` and `no transport tcp` disable non-secure SIP ports globally on the router[^21].

### Verify
Suggested check: verify that non-secure signaling is retained for the plain RTP leg while TLS is maintained for the secure Unified CM leg.

### Rollback
Suggested rollback: no configuration is applied in this step, so no rollback is required.

## Step 12: Verify TLS end to end

### Do
Execute `show sip-ua connections tcp tls brief` and `show sip-ua connections tcp tls detail` to inspect active TLS signaling sockets[^60]. Execute `show crypto pki certificates` to check the certificates held in CUBE trustpoints[^58]. Cisco's enterprise-CA technote uses `debug crypto pki`, `debug ssl openssl`, `debug srtp` and `debug ccsip` to troubleshoot CUBE TLS and SRTP[^16].

### Verify
`show sip-ua connections tcp tls brief` and `show sip-ua connections tcp tls detail` verify CUBE TLS connections, and the detail output shows the negotiated TLS version and cipher suite[^60]. A working secure trunk between Unified CM and CUBE shows status Full Service on the Unified CM SIP trunk page[^9]. The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate[^62].

### Rollback
Suggested rollback: diagnostic step only; no configuration rollback is needed.

## Step 13: Verify SRTP on a live call

### Do
`show call active voice brief` shows `SRTP: on` or `SRTP: off` for each call leg[^59]. `show sip-ua calls` shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg[^44]. Cisco's enterprise-CA technote uses `debug crypto pki`, `debug ssl openssl`, `debug srtp` and `debug ccsip` to troubleshoot CUBE TLS and SRTP[^16].

### Verify
`show call active voice brief` shows `SRTP: on` or `SRTP: off` for each call leg[^59]. `show sip-ua calls` shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg[^44].

### Rollback
Suggested rollback: diagnostic step only; no configuration rollback is needed.

## Applicability

Applies to: Cisco Unified Border Element, Cisco Unified Communications Manager, Cisco IOS XE, and Cisco Webex Calling Local Gateway. Deployments: on-premises and multi-tenant. Sources checked 2026-09-30. Specific features and release boundaries cited across the claims include:
- TLS 1.3 support on CUBE requires Cisco IOS XE 17.14.1a or later[^54].
- CN-SAN validation and per-trunk TLS policies require Cisco IOS XE 17.8.1a or later[^4].
- Restricting TLS cipher suites using `voice class tls-cipher` is available from Cisco IOS XE 17.3.1[^46].
- From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 require `system mode insecure`[^50].
- SRTP-SRTP interworking combined with transcoding is supported from Cisco IOS XE 17.6.1a[^43].
- SRTP-SRTP interworking and SRTP-RTP interworking suites were introduced in Cisco IOS XE Everest 16.5.1b[^36][^41].

## What remains uncertain

- Whether a Unified CM cluster must be in mixed mode solely for a secure SIP trunk without encrypted phones is not covered by the sources below.
- Specific throughput thresholds and hardware crypto licensing capacities for Cisco ISR 4000 or Catalyst 8000 series platforms are not covered by the sources below.
- Certificate lifecycle automation, SCEP or EST enrollment, and automated expiry monitoring on CUBE are not covered by the sources below.

## Sources

[^1]: Cisco's CUBE hardening guide notes that some older Cisco devices or peer devices may not support the AEAD (GCM) SRTP ciphers. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Trim unsecure SRTP Ciphers. Checked 2026-09-30.
[^2]: When the CUBE certificate is issued through an intermediate CA, separate trustpoints with enrollment terminal pem are created for the root and the intermediate, and each is loaded with crypto pki authenticate, root first. Source: [Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/215412-configure-sip-tls-between-cucm-cube-cube.html), Configure > Configuration steps, root and intermediate CA trustpoint steps. Checked 2026-09-30.
[^3]: For a CA-signed CUBE certificate, crypto pki enroll <trustpoint> produces the certificate signing request and crypto pki import <trustpoint> certificate installs the signed certificate. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Certificate configuration > Step 3 generate and import certificate. Checked 2026-09-30.
[^4]: CN-SAN client validation and trunk-specific TLS policies on CUBE were introduced in Cisco IOS XE Cupertino 17.8.1a. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > feature information by release (17.8.1a row). Checked 2026-09-30.
[^5]: The sip-ua command crypto signaling {remote-addr <ip> <mask> | default} [tls-profile <tag> | trustpoint <name>] selects the trustpoint or TLS profile CUBE uses for TLS connections, either for all peers or for a specific remote address. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support (PDF m_sip_tls_support_cube.pdf) > configuration task, crypto signaling step. Checked 2026-09-30.
[^6]: After applying the security profile to the trunk, Save and then Apply Config resets the Unified CM trunk so the change takes effect. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), Deployment steps > apply profile, Save, Apply Config. Checked 2026-09-30.
[^7]: For a CA-signed Unified CM certificate, a CallManager CSR is generated in OS Administration under Security > Certificate Management and the signed result is uploaded as the CallManager certificate. Source: [Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/215412-configure-sip-tls-between-cucm-cube-cube.html), Configure > CUCM configuration steps (CSR and upload). Checked 2026-09-30.
[^8]: To make CUBE trust a self-signed Unified CM certificate, a trustpoint with enrollment terminal is created for Unified CM and the CallManager certificate is pasted in with crypto pki authenticate <trustpoint>. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, step 6. Checked 2026-09-30.
[^9]: A working secure trunk between Unified CM and CUBE shows status Full Service on the Unified CM SIP trunk page. Source: [Configure SIP TLS Between CUCM-CUBE/CUBE-SBC With CA Signed Certificates](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/215412-configure-sip-tls-between-cucm-cube-cube.html), Verify. Checked 2026-09-30.
[^10]: The default Incoming Port for TLS in a Unified CM SIP trunk security profile is 5061. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), SIP Trunk Security Profile configuration > Incoming Port. Checked 2026-09-30.
[^11]: For TLS signaling on a Unified CM SIP trunk, the SIP trunk security profile sets Device Security Mode to Encrypted and both Incoming and Outgoing Transport Type to TLS. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), SIP Trunk Security Profile configuration > Device Security Mode, Incoming/Outgoing Transport Type. Checked 2026-09-30.
[^12]: SRTP media on a Unified CM SIP trunk is enabled by checking SRTP Allowed on the trunk; with a non-secure profile SRTP still works but the keys are exposed in signaling and traces. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), SIP trunk security > SRTP Allowed check box note. Checked 2026-09-30.
[^13]: The Unified CM SIP trunk security profile field Secure Certificate Subject or Subject Alternate Name holds the TLS peer's certificate subject, with multiple names separated by space, comma, semicolon or colon. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), SIP Trunk Security Profile configuration > Secure Certificate Subject or Subject Alternate Name. Checked 2026-09-30.
[^14]: With enterprise CA-signed certificates, the root CA and subordinate CA certificates are uploaded to Unified CM as CallManager-Trust via OS Administration > Security > Certificate Management > Upload Certificate/Certificate chain. Source: [Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/200614-Configure-and-Troubleshoot-Enterprise-CA.html), Configure > upload of Root CA and Subordinate CA certificates to CUCM. Checked 2026-09-30.
[^15]: The self-signed CUBE certificate is uploaded in Unified CM OS Administration under Security > Certificate Management with certificate purpose CallManager-Trust. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, step 4. Checked 2026-09-30.
[^16]: Cisco's enterprise-CA technote uses debug crypto pki, debug ssl openssl, debug srtp and debug ccsip to troubleshoot CUBE TLS and SRTP. Source: [Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/200614-Configure-and-Troubleshoot-Enterprise-CA.html), Troubleshoot. Checked 2026-09-30.
[^17]: On the CUBE dial-peer toward Unified CM, session transport tcp tls selects TLS signaling and srtp enables secure media. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, step 8. Checked 2026-09-30.
[^18]: crypto pki export <trustpoint> pem terminal prints the CUBE certificate in PEM format so it can be copied to Unified CM. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, step 3. Checked 2026-09-30.
[^19]: Cisco's CUBE hardening guide says SIP TLS and SRTP should be enabled on all call legs through CUBE, because security is only as strong as the weakest link. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Use TCP TLS and SRTP. Checked 2026-09-30.
[^20]: Cisco's CUBE hardening guide recommends CA-signed certificates in place of self-signed certificates. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Utilize Certificate Authority (CA) Signed Certificates. Checked 2026-09-30.
[^21]: Cisco's CUBE hardening guide recommends disabling non-secure SIP ports with no transport udp and no transport tcp under sip-ua. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Disable Non-Secure SIP Ports. Checked 2026-09-30.
[^22]: Cisco's CUBE hardening guide recommends mapping remote TLS connections to specific trustpoints. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Map remote TLS connections to specific trustpoints. Checked 2026-09-30.
[^23]: Cisco's CUBE hardening guide recommends revocation-check crl or ocsp on trustpoints and warns that revocation-check none weakens security. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Enable Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) Checks. Checked 2026-09-30.
[^24]: Cisco's CUBE hardening guide recommends an RSA modulus of 2048 bits for TLS 1.2 applications. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Utilize large cryptographic keys. Checked 2026-09-30.
[^25]: Cisco's enterprise-CA technote lists a Unified CM cluster in mixed mode as a prerequisite for its scenario, which also covers IP phones registered in encrypted mode. Source: [Configure and Troubleshoot Enterprise CA (Third Party CA) Signed Certificates for SIP TLS and SRTP Between CUCM, IP Phones and CUBE](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/200614-Configure-and-Troubleshoot-Enterprise-CA.html), Prerequisites > Requirements. Checked 2026-09-30.
[^26]: SRTP pass-through must be configured on both call legs; if the target leg does not support it, CUBE rejects the call with 415 Unsupported Media Type. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_voi-srtp-srtp-passthrough.html), SRTP-SRTP Pass-Through > Restrictions. Checked 2026-09-30.
[^27]: SRTP pass-through is enabled with srtp pass-thru either on a dial-peer or globally under voice service voip. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_voi-srtp-srtp-passthrough.html), SRTP-SRTP Pass-Through > configuration for specific dial peers; global configuration. Checked 2026-09-30.
[^28]: Because SRTP keys travel in the SDP crypto attributes, both legs of an SRTP call through CUBE need TLS signaling to keep the keys out of cleartext; pass-through does not remove that need (inferred). Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Trunk and Gateway SIP Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_trunk-and-gateway-sip-security_reog.html), SIP trunk security > SRTP Allowed check box note (read with SRTP-SRTP Pass-Through > Overview). Checked 2026-09-30.
[^29]: When SRTP pass-through is enabled, CUBE does not support media interworking on the call. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_voi-srtp-srtp-passthrough.html), SRTP-SRTP Pass-Through > Restrictions. Checked 2026-09-30.
[^30]: SRTP pass-through is triggered only when the inbound INVITE carries an m= line with RTP/SAVP, and CUBE passes the crypto attributes, including suites it does not itself support, to the other leg unchanged. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_voi-srtp-srtp-passthrough.html), SRTP-SRTP Pass-Through > Pass-Through of Unsupported Crypto Suites. Checked 2026-09-30.
[^31]: With SRTP pass-through, a voice class srtp-crypto list on CUBE does not decide the negotiated suite, because CUBE relays the endpoints' crypto attributes rather than terminating SRTP; the two endpoints must share a suite (inferred). Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Pass-Through](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_voi-srtp-srtp-passthrough.html), SRTP-SRTP Pass-Through > Pass-Through of Unsupported Crypto Suites (read with SRTP-SRTP Interworking offer/answer). Checked 2026-09-30.
[^32]: The CUBE certificate procedure starts by creating a private key with crypto key generate rsa general-keys label <name> exportable; EC keys are an optional alternative. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Certificate configuration > Step 1 create private key. Checked 2026-09-30.
[^33]: A self-signed CUBE certificate is created by setting enrollment selfsigned on the trustpoint and running crypto pki enroll <trustpoint>. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, steps 1 and 2. Checked 2026-09-30.
[^34]: From Cisco IOS XE Everest 16.5.1b the srtp-auth command is deprecated: it is still accepted but causes no configuration change, and voice class srtp-crypto replaces it. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-srtp-rtp-int.html), SRTP-RTP Interworking > Configure Crypto Authentication (deprecation note). Checked 2026-09-30.
[^35]: A voice class srtp-crypto list can be applied globally under voice service voip > sip with srtp-crypto <tag>, in a voice class tenant with srtp-crypto <tag>, or on a dial-peer with voice-class sip srtp-crypto <tag>. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Configure SRTP-SRTP Interworking. Checked 2026-09-30.
[^36]: From Cisco IOS XE Everest 16.5.1b, CUBE supports the SRTP suites AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80 and AES_CM_128_HMAC_SHA1_32, in that default preference order. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Overview. Checked 2026-09-30.
[^37]: CUBE SRTP configuration on a dial-peer takes precedence over the global configuration. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-srtp-rtp-int.html), SRTP-RTP Interworking > Configure Crypto Authentication. Checked 2026-09-30.
[^38]: To allow fallback from SRTP to RTP with Unified CM, CUBE uses srtp fallback together with voice-class sip srtp negotiate cisco on the dial-peer. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-srtp-rtp-int.html), SRTP-RTP Interworking > Enable SRTP Fallback. Checked 2026-09-30.
[^39]: CUBE offers SRTP suites in the SDP offer in the configured preference order and, when answering, selects the highest-preference configured suite that matches the peer's offer. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Configure SRTP-SRTP Interworking (crypto preference). Checked 2026-09-30.
[^40]: CUBE SRTP-SRTP interworking does not support asymmetric SRTP fallback, Call Progress Analysis, or GCM ciphers with extension headers. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Restrictions. Checked 2026-09-30.
[^41]: CUBE SRTP-RTP interworking connects an SRTP leg to an RTP leg by enabling srtp only on the secure-side dial-peer, and on IOS XE platforms it needs no DSP resources. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-srtp-rtp-int.html), SRTP-RTP Interworking > Overview, Prerequisites, Configure SRTP-RTP Interworking. Checked 2026-09-30.
[^42]: With srtp configured under voice service voip, CUBE's default behaviour is to disallow fallback to RTP. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Enforce Strict SRTP. Checked 2026-09-30.
[^43]: SRTP-SRTP interworking combined with transcoding is supported only from Cisco IOS XE 17.6.1a. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Restrictions. Checked 2026-09-30.
[^44]: show sip-ua calls shows each stream's Local Crypto Suite and Remote Crypto Suite, which confirms which SRTP suite was negotiated on each leg. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), SRTP-SRTP Interworking > Configuration Examples (show sip-ua calls output). Checked 2026-09-30.
[^45]: A voice class tenant can carry tls-profile, session transport tcp tls and url sips, and a dial-peer uses it through voice-class sip tenant <tag>. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Tenant and dial-peer configuration. Checked 2026-09-30.
[^46]: TLS cipher suites for CUBE are restricted with voice class tls-cipher, available from Cisco IOS XE 17.3.1 according to the hardening guide. Source: [Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html), Enforce TLS Ciphers. Checked 2026-09-30.
[^47]: CUBE SIP TLS can be configured at the global, voice class tenant and dial-peer levels. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Overview. Checked 2026-09-30.
[^48]: When transport tcp tls is configured under sip-ua without a version, CUBE negotiates TLS 1.2 and 1.3; from IOS XE 26.1.1, TLS 1.0 and 1.1 are excluded from that default. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Global SIP-UA configuration > TLS version modes (Default). Checked 2026-09-30.
[^49]: CUBE logs %SIP-2-TLS_HANDSHAKE_FAILED when a TLS handshake fails, including on certificate identity validation failure. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Syslog events. Checked 2026-09-30.
[^50]: From Cisco IOS XE 26.1.1, TLS 1.0 and TLS 1.1 on CUBE can be used only when system mode insecure is configured. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > feature information by release (26.1.1 row). Checked 2026-09-30.
[^51]: The CUBE SIP TLS chapter lists a security license as required on Cisco 4000 series ISRs and an HSEC license for high call volumes. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Restrictions. Checked 2026-09-30.
[^52]: The sip-ua command transport tcp tls v1.2 minimum enables TLS 1.2 and above, while naming a single version without minimum enables only that version. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Global SIP-UA configuration > TLS version modes (Exclusive, Minimum). Checked 2026-09-30.
[^53]: A voice class tls-profile groups a trustpoint, a tls-cipher class, cn-san validate {server | client | bidirectional} and sni send for use by a tenant or crypto signaling. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > TLS profile configuration. Checked 2026-09-30.
[^54]: TLS 1.3 support for CUBE SIP signaling was introduced in Cisco IOS XE 17.14.1a. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > feature information by release (17.14.1a row). Checked 2026-09-30.
[^55]: The CUBE identity trustpoint in the configuration guide names the key pair with rsakeypair and sets fqdn, subject-name cn=, subject-alt-name and enrollment terminal. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Certificate configuration > Step 2 create trustpoint. Checked 2026-09-30.
[^56]: crypto pki trustpool import clean url https://www.cisco.com/security/pki/trs/ios_core.p7b clears the current CA trustpool and installs the Cisco root CA bundle. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Import Cisco Root Certificate Authority bundle. Checked 2026-09-30.
[^57]: show crypto pki trustpool confirms that the CA bundle was imported. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), Verification commands > Verify trustpool installation. Checked 2026-09-30.
[^58]: show crypto pki certificates displays the certificates held in CUBE trustpoints. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Verification. Checked 2026-09-30.
[^59]: show call active voice brief shows SRTP: on or SRTP: off for each call leg. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-RTP Internetworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-srtp-rtp-int.html), SRTP-RTP Interworking > Verify SRTP-RTP. Checked 2026-09-30.
[^60]: show sip-ua connections tcp tls brief and show sip-ua connections tcp tls detail verify CUBE TLS connections, and the detail output shows the negotiated TLS version and cipher suite. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), SIP TLS Support > Verification. Checked 2026-09-30.
[^61]: Webex Calling supports only AES_CM_128_HMAC_SHA1_80 for SRTP, so a CUBE leg to Webex Calling offers that suite alone. Source: [Configure Local Gateway on Cisco IOS XE for Webex Calling](https://help.webex.com/en-us/article/jr1i3r/Configure-Local-Gateway-on-Cisco-IOS-XE-for-Webex-Calling), SRTP media encryption > voice class srtp-crypto 100. Checked 2026-09-30.
[^62]: The X.509 subject name in the Unified CM SIP trunk security profile must match the CN configured in the CUBE certificate. Source: [Configure SIP TLS between CUCM-CUBE/CUBE-SBC](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/212090-Configure-SIP-TLS-between-CUCM-CUBE-CUBE.html), Configure > Configuration steps, SIP trunk security profile step. Checked 2026-09-30.
[^63]: CUBE's voice class srtp-crypto lists preferred SRTP suites (AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32) and can be applied globally under voice service voip sip, in a voice class tenant, or per dial-peer with voice-class sip srtp-crypto, with 'srtp' enabling secure calls on the dial-peer. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), Voice class srtp-crypto configuration; application at global, tenant and dial-peer levels. Checked 2026-09-30.
