cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

660
Views
15
Helpful
4
Replies

802.1X NPS SERVER / CISCO 7800 SERIES

Hi there,

 

I'm trying to deploy 802.1X infrastructure for the first time.

I have one network with two VLAN one for the data and one for the voice.

 

I configure my NPS with EAP-TLS and certificate for the authentification.

 

The certificate are auto enroll via GPO for all the computer.

 

Everything is working well for Wifi, Switch except one thing.

 

The IP Phones only authentificate if one supplicant computer is connect behind.

 

I want to know the best practice to auth the IP Phones too.

 

The switches are netgear ... not my choice but it's the switches

 

I never use this kind of ip phones. The easy way to allow and the less secure is to do a NPS Mac auth bypass ? to allow this equipements ? What about install certificate on this equipement ?

 

Regards

4 REPLIES 4
balaji.bandi
VIP Expert

Depends on the phone, some phones support Certificate, some are not, So best practice MAB - rather complicating things.

 

Hoping since you posted in the cisco community NPS is ISE or MS NPS(NPAS)?

 

here is the voice and Data deployment guide ISE point of you :

 

https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515

BB

***** Rate All Helpful Responses *****

How to Ask The Community for Help

Thank you for your answer. I'm using Microsoft NPS services. 

Marcelo Morais
Advocate

Hi @yvanderunes802438600

 please take a look at the link: 7800 Series Phone Security. for more information on the Cisco IP Phone 7800 Series.

Note: the IP Phone 7800 Series can be connect to the Cisco Communication Manager Call Control or with a Third-Party Call Control, please double check what is your case.

 

Hope this helps !!!

 

Thank you for the advice. I found this link : https://social.technet.microsoft.com/Forums/en-US/6d78c698-a087-48cb-bc73-9566aa61bf10/using-nps-with-cisco-ip-phones?forum=winserverNAP

 

I'm going to follow indication to do auth ip phones with the MIC certificate cisco and map after on username.

Content for Community-Ad