03-28-2021 01:15 PM
Hi there,
I'm trying to deploy 802.1X infrastructure for the first time.
I have one network with two VLAN one for the data and one for the voice.
I configure my NPS with EAP-TLS and certificate for the authentification.
The certificate are auto enroll via GPO for all the computer.
Everything is working well for Wifi, Switch except one thing.
The IP Phones only authentificate if one supplicant computer is connect behind.
I want to know the best practice to auth the IP Phones too.
The switches are netgear ... not my choice but it's the switches
I never use this kind of ip phones. The easy way to allow and the less secure is to do a NPS Mac auth bypass ? to allow this equipements ? What about install certificate on this equipement ?
Regards
03-28-2021 03:43 PM
Depends on the phone, some phones support Certificate, some are not, So best practice MAB - rather complicating things.
Hoping since you posted in the cisco community NPS is ISE or MS NPS(NPAS)?
here is the voice and Data deployment guide ISE point of you :
03-29-2021 02:15 AM
Thank you for your answer. I'm using Microsoft NPS services.
03-29-2021 04:23 AM
please take a look at the link: 7800 Series Phone Security. for more information on the Cisco IP Phone 7800 Series.
Note: the IP Phone 7800 Series can be connect to the Cisco Communication Manager Call Control or with a Third-Party Call Control, please double check what is your case.
Hope this helps !!!
03-29-2021 08:46 AM
Thank you for the advice. I found this link : https://social.technet.microsoft.com/Forums/en-US/6d78c698-a087-48cb-bc73-9566aa61bf10/using-nps-with-cisco-ip-phones?forum=winserverNAP
I'm going to follow indication to do auth ip phones with the MIC certificate cisco and map after on username.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide