Cisco has recently added four Unified Communications Proxy features to their Adaptive Security Appliance (ASA) firewall:
•Phone proxy
•TLS proxy for encrypted voice inspection
•Mobility proxy
•Presence federation proxy
The most interesting of these features is Phone Proxy. It allows phones to securely communicate over the internet to an internal Unified Communications Manager Server. ASA Phone proxy uses industry standard protocols Security Real Time Protocol (SRTP) and Transport Layer Security (TLS) for secure remote access. A benefit of ASA Phone proxy is that it does not require Virtual Private Network (VPN) configuration. So this makes the solution easy to deploy and scalable.

ASA Phone Proxy
Requirements
Adaptive Security Appliance
ASA Operating System 8.0(4) or higher
Cisco Unified Communications Manager
The following versions of Unified Communications Manager are supported with the phone proxy:
•Cisco Unified CallManager Version 4.x
•Cisco Unified CallManager Version 5.x
•Cisco Unified Communications Manager 6.x
•Cisco Unified Communications Manager 7.x
Cisco Unified IP Phones
The following IP phones in the Cisco Unified IP Phones 7900 Series are supported with the phone proxy:
•Cisco Unified IP Phone 7975
•Cisco Unified IP Phone 7971
•Cisco Unified IP Phone 7970
•Cisco Unified IP Phone 7965
•Cisco Unified IP Phone 7962
•Cisco Unified IP Phone 7961
•Cisco Unified IP Phone 7961G-GE
•Cisco Unified IP Phone 7960 (SCCP protocol support only)
•Cisco Unified IP Phone 7945
•Cisco Unified IP Phone 7942
•Cisco Unified IP Phone 7941
•Cisco Unified IP Phone 7941G-GE
•Cisco Unified IP Phone 7940 (SCCP protocol support only)
•Cisco Unified Wireless IP Phone 7921
•CIPC for softphones (CIPC versions with Authenticated mode only)
Licensing
The UC Proxy features require a license per TLS session. The ASA comes with 2 free licenses for testing purposes. Below are the licensing requirements:

ASA Unified Communications Proxy Licenses
The licenses can be purchased in tiers of 24, 50, 100, 250, 500, 750, 1000, 2000 and 3000. Be forewarned that the licenses are not cheap. The 24 port license (ASA-UC-24=) list for $2,995.00.
As part of my proof-of-concept, I setup a 7960 and 7970 Cisco IP phone in my home office. I reconfigured my ASA in the data center was and able to get both IP phones to register to my backbone Cisco Unified Communications Manager running version 6.0.1. I was also able to make and receive calls over my SIP trunk to the Public Switch Phone Network (PSTN). Overall, I really like the solution.
If you are interested in learning more or would like help with your own implementation visit our Consulting Page at: http://www.voip-tutor.com/consulting.htm