<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you are using EAP-TLS, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticating-cisco-ip-phones-using-ise-and-802-1x/m-p/2913475#M36478</link>
    <description>&lt;P&gt;If you are using EAP-TLS, your authentication rules, need to select a certificate profile and an identity store, for EAP-TLS it will use the cert profile for auhthentication. It will still try to get AD groups for the CN/SAN name of your MIC/LSC cert, but it shouldn't fail authentication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This thread also has some info :&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/10952961/8021x-phone-authentication-eap-tls-mic-only&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2016 20:18:51 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2016-04-27T20:18:51Z</dc:date>
    <item>
      <title>Authenticating Cisco IP Phones using ISE and 802.1X</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-cisco-ip-phones-using-ise-and-802-1x/m-p/2913474#M36477</link>
      <description>&lt;P&gt;I have seen a few others ask similar questions but no answers seem to have been posted.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How do you configure ISE 2.0 to authenticate a Cisco IP Phone that has the MIC and LSC certificates installed? I have already done the export of certificates from CUCM and import into ISE, but I just cannot get the Authentication Rule/s right. The phone is enabled for 802.1X and certificate, and switch is doing it's job as I see the RADIUS logs both in ISE and the switch showing the failures.&lt;/P&gt;
&lt;P&gt;What identity store does a Cisco IP Phone use to authenticate itself against in ISE? Surely every phone doesn't need to be added into ISE ahead of time (hundreds or thousands)? The failure I get is ISE unable to match the user in any identity store.&lt;/P&gt;
&lt;P&gt;There doesn't seem to be any guides available to help here other than old ACS guides.&lt;/P&gt;
&lt;P&gt;I see there are prebuilt Authorization rules in ISE for Cisco IP Phones but I can't get far enough for the device to authenticate let alone hit the Authorization rule.&lt;/P&gt;
&lt;P&gt;Can anyone help?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-cisco-ip-phones-using-ise-and-802-1x/m-p/2913474#M36477</guid>
      <dc:creator>Bobby Stojceski</dc:creator>
      <dc:date>2019-03-11T06:42:36Z</dc:date>
    </item>
    <item>
      <title>If you are using EAP-TLS,</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticating-cisco-ip-phones-using-ise-and-802-1x/m-p/2913475#M36478</link>
      <description>&lt;P&gt;If you are using EAP-TLS, your authentication rules, need to select a certificate profile and an identity store, for EAP-TLS it will use the cert profile for auhthentication. It will still try to get AD groups for the CN/SAN name of your MIC/LSC cert, but it shouldn't fail authentication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This thread also has some info :&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/10952961/8021x-phone-authentication-eap-tls-mic-only&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 20:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticating-cisco-ip-phones-using-ise-and-802-1x/m-p/2913475#M36478</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-04-27T20:18:51Z</dc:date>
    </item>
  </channel>
</rss>

