<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1X NPS SERVER / CISCO 7800 SERIES in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315213#M566493</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to deploy 802.1X infrastructure for the first time.&lt;/P&gt;&lt;P&gt;I have one network with two VLAN one for the data and one for the voice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configure my NPS with EAP-TLS and certificate for the authentification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate are auto enroll via GPO for all the computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is working well for Wifi, Switch except one thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IP Phones only authentificate if one supplicant computer is connect behind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to know the best practice to auth the IP Phones too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switches are netgear ... not my choice but it's the switches &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never use this kind of ip phones. The easy way to allow and the less secure is to do a NPS Mac auth bypass ? to allow this equipements ? What about install certificate on this equipement ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Sun, 28 Mar 2021 20:15:00 GMT</pubDate>
    <dc:creator>yvanderunes802438600</dc:creator>
    <dc:date>2021-03-28T20:15:00Z</dc:date>
    <item>
      <title>802.1X NPS SERVER / CISCO 7800 SERIES</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315213#M566493</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to deploy 802.1X infrastructure for the first time.&lt;/P&gt;&lt;P&gt;I have one network with two VLAN one for the data and one for the voice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configure my NPS with EAP-TLS and certificate for the authentification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate are auto enroll via GPO for all the computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is working well for Wifi, Switch except one thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The IP Phones only authentificate if one supplicant computer is connect behind.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to know the best practice to auth the IP Phones too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switches are netgear ... not my choice but it's the switches &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never use this kind of ip phones. The easy way to allow and the less secure is to do a NPS Mac auth bypass ? to allow this equipements ? What about install certificate on this equipement ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 20:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315213#M566493</guid>
      <dc:creator>yvanderunes802438600</dc:creator>
      <dc:date>2021-03-28T20:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X NPS SERVER / CISCO 7800 SERIES</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315230#M566495</link>
      <description>&lt;P&gt;Depends on the phone, some phones support Certificate, some are not, So best practice MAB - rather complicating things.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping since you posted in the cisco community NPS is ISE or MS NPS(NPAS)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the voice and Data deployment guide ISE point of you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 22:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315230#M566495</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-03-28T22:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X NPS SERVER / CISCO 7800 SERIES</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315357#M566499</link>
      <description>&lt;P&gt;Thank you for your answer. I'm using Microsoft NPS services.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 09:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315357#M566499</guid>
      <dc:creator>yvanderunes802438600</dc:creator>
      <dc:date>2021-03-29T09:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X NPS SERVER / CISCO 7800 SERIES</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315400#M566500</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/988107"&gt;@yvanderunes802438600&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;please take a look at the link:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/7800-series/english/admin-guide/pa2d_b_7800-series-admin-guide-cucm/pa2d_b_7800-series-admin-guide-cucm_chapter_01001.html" target="_blank" rel="noopener"&gt;7800 Series Phone Security&lt;/A&gt;. for more information on the &lt;STRONG&gt;Cisco IP Phone 7800 Series&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Note: the &lt;STRONG&gt;IP Phone 7800 Series&lt;/STRONG&gt; can be connect to the &lt;STRONG&gt;Cisco Communication Manager Call Control&lt;/STRONG&gt; or with a &lt;STRONG&gt;Third-Party Call Control&lt;/STRONG&gt;, please double check what is your case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315400#M566500</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-29T11:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X NPS SERVER / CISCO 7800 SERIES</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315532#M566508</link>
      <description>&lt;P&gt;Thank you for the advice. I found this link :&amp;nbsp;&lt;A href="https://social.technet.microsoft.com/Forums/en-US/6d78c698-a087-48cb-bc73-9566aa61bf10/using-nps-with-cisco-ip-phones?forum=winserverNAP" target="_blank"&gt;https://social.technet.microsoft.com/Forums/en-US/6d78c698-a087-48cb-bc73-9566aa61bf10/using-nps-with-cisco-ip-phones?forum=winserverNAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to follow indication to do auth ip phones with the MIC certificate cisco and map after on username.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 15:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-nps-server-cisco-7800-series/m-p/4315532#M566508</guid>
      <dc:creator>yvanderunes802438600</dc:creator>
      <dc:date>2021-03-29T15:46:04Z</dc:date>
    </item>
  </channel>
</rss>

