IP phones cannot display authentication proxy prompt. Therefore it cannot be authenticated using auth-proxy. One solution to this is to use CBAC. If the IP phone is talking to an MGCP call manager, then open the SKINNY protocol (UDP 2000) and TFTP in the inbound ACL. IP inspection will dynamically open holes for RTP streams when a phone call is made. By opening only UDP 2000, access control is not diluted much and IP phone works without doing auth-proxy. Same for a SIP phone open UDP 5060.
Important Authentication Proxy Diagnostics Commands
show ip auth-proxy cache-displays the existing sessions.
show ip auth-proxy config-displays the current configuration.
clear ip auth-proxy cache [*/]-clears auth-proxy sessions.
debug ip auth-proxy [options]-enables auth-proxy debugs.