cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
844
Views
0
Helpful
5
Replies

intregation Cisco Unified communication manager 7 with ACS cisco Segure

eljose_lol
Level 1
Level 1

Hi All!

Can do CCM V7 be integrated with ACS for autentication IP Phones?

1 Accepted Solution

Accepted Solutions

There is a model-specific configuration parameter that allows you to enable/disable 802.1x support on the Device Configuration page.

What do you want the phone to use to authenticate itself? Unless you want users to be authenticating the phone with their user credentials the document I referenced is your place to start. You'll need to get certificates deployed to the phones so they can provide that to the switch for authentication.

View solution in original post

5 Replies 5

Jonathan Schulenberg
Hall of Fame
Hall of Fame

Yes. You can place the cluster in mixed mode, have CAPF generate LSC certificates to the phones as a subordinate CA to your internal root CA, and then have the phones perform 802.1x authentication. This is not a trivial task though. Here's the document to get you started: Cisco Unified Communications Manager Security Guide, Release 7.1(2)

Note that you can also use the MIC (that term will make sense after reading the security guide) to provide limited network access for a phone without an LSC. The intention here is to provide the phone enough access to enroll in an LSC through CUCM CAPF and then re-authenticate to the switch for full network access with it's LSC.

Hi Jonathan

In my case i need to phones authentication via 802.1x with ACS. Where i can do this in the CCM?

thanks

There is a model-specific configuration parameter that allows you to enable/disable 802.1x support on the Device Configuration page.

What do you want the phone to use to authenticate itself? Unless you want users to be authenticating the phone with their user credentials the document I referenced is your place to start. You'll need to get certificates deployed to the phones so they can provide that to the switch for authentication.

ok, and how to get certificates deployed to the phones so they can provide that to the switch for authentication?

+5 thanks a lot, keep in contact,

Getting certificates on the phone is no small task. The security guide is your best reference. Here are the high-level steps from memory:

  1. Order a pair of hardware tokens (part KEY-CCM-ADMIN-K9=). You must have at least two! These are the private keys that you will use for signing the Certificate Trust List (CTL).
  2. Activate the server-side services (CAPF and CTL).
  3. Configure the CTL Client
  4. Instruct phones to install an LSC.

Table 7-2 outlines the steps/order for you in far greater detail. Again, I recommend doing this in a lab and reading the entire security guide first. This is easy to mess up.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: