This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
I'm trying to deploy 802.1X infrastructure for the first time.
I have one network with two VLAN one for the data and one for the voice.
I configure my NPS with EAP-TLS and certificate for the authentification.
The certificate are auto enroll via GPO for all the computer.
Everything is working well for Wifi, Switch except one thing.
The IP Phones only authentificate if one supplicant computer is connect behind.
I want to know the best practice to auth the IP Phones too.
The switches are netgear ... not my choice but it's the switches
I never use this kind of ip phones. The easy way to allow and the less secure is to do a NPS Mac auth bypass ? to allow this equipements ? What about install certificate on this equipement ?
Depends on the phone, some phones support Certificate, some are not, So best practice MAB - rather complicating things.
Hoping since you posted in the cisco community NPS is ISE or MS NPS(NPAS)?
here is the voice and Data deployment guide ISE point of you :
please take a look at the link: 7800 Series Phone Security. for more information on the Cisco IP Phone 7800 Series.
Note: the IP Phone 7800 Series can be connect to the Cisco Communication Manager Call Control or with a Third-Party Call Control, please double check what is your case.
Hope this helps !!!
Thank you for the advice. I found this link : https://social.technet.microsoft.com/Forums/en-US/6d78c698-a087-48cb-bc73-9566aa61bf10/using-nps-with-cisco-ip-phones?forum=winserverNAP
I'm going to follow indication to do auth ip phones with the MIC certificate cisco and map after on username.