Page 28
Chapter
Understanding Security Features for Cisco Unified IP Phones
Supporting 802.1X Authentication on Cisco Unified IP Phones
These sections provide information about 802.1X support on the Cisco Unified IP Phones:
•Overview, page 1-16
•Required Network Components, page 1-16
•Best Practices—Requirements and Recommendations, page 1-16
Overview
Cisco Unified IP phones and Cisco Catalyst switches have traditionally used Cisco Discovery Protocol (CDP) to identify each other and determine parameters such as VLAN allocation and inline power requirements. However, CDP is not used to identify any locally attached PCs; therefore, Cisco Unified IP Phones provide an EAPOL pass-through mechanism, whereby a PC locally attached to the IP phone, may pass through EAPOL messages to the 802.1X authenticator in the LAN switch. This prevents the IP phone from having to act as the authenticator, yet allows the LAN switch to authenticate a data end point prior to accessing the network.
In conjunction with the EAPOL pass-through mechanism, Cisco Unified IP Phones provide a proxy EAPOL-Logoff mechanism. In the event that the locally attached PC is disconnected from the IP phone, the LAN switch would not see the physical link fail, because the link between the LAN switch and the IP phone is maintained. To avoid compromising network integrity, the IP phone sends an EAPOL-Logoff message to the switch, on behalf of the downstream PC, which triggers the LAN switch to clear the authentication entry for the downstream PC.
The Cisco Unified IP phones also contain an 802.1X supplicant, in addition to the EAPOL pass-through mechanism. This supplicant allows network administrators to control the connectivity of IP phones to the LAN switch ports. The current release of the phone 802.1X supplicant uses the EAP-FAST, EAP-TLS, and EAP-MD5 options for network authentication.
Required Network Components
Support for 802.1X authentication on Cisco Unified IP Phones requires several components, including:
•Cisco Unified IP Phone—The phone acts as the 802.1X supplicant, which initiates the request to access the network.
•Cisco Secure Access Control Server (ACS) (or other third-party authentication server)—The authentication server and the phone must both be configured with a shared secret that is used to authenticate the phone.
•Cisco Catalyst Switch (or other third-party switch)—The switch must support 802.1X, so it can act as the authenticator and pass the messages between the phone and the authentication server. When the exchange is completed, the switch then grants or denies the phone access to the network.
Best Practices—Requirements and Recommendations
•Enable 802.1X Authentication—If you want to use the 802.1X standard to authenticate Cisco Unified IP Phones, be sure that you have properly configured the other components before enabling it on the phone. See the “802.1X Authentication and Status” section on page 4-8for more information.
| Cisco Unified IP Phone 8941 and 8945 Administration Guide for Cisco Unified Communications Manager 8.5 (SCCP and SIP) |
1-16 | OL-20851-01 |
Contents
Americas Headquarters
Text Part Number OL-20851-01
Page
N T E N T S
Power Outage
802.1X Authentication and Status
Troubleshooting and Maintenance
Cable Specifications C-2 Network and Access Port Pinouts C-2
Viii
Overview
Audience
Organization
Chapter Description
Cisco Unified Communications Manager Administration
Related Documentation
Cisco Unified IP Phone 8900 Series
Cisco Unified Communications Manager Business Edition
Document Conventions
Cisco Product Security Overview
Convention Description
Boldface font
Important Safety Instructions
An Overview of the Cisco Unified IP Phone
Understanding the Cisco Unified IP Phones 8941
Features on the Cisco Unified IP Phone 8941
What Networking Protocols are Used?
Networking Protocol Purpose Usage Notes
Dynamic Host Configuration Protocol chapter
Authentication on Cisco Unified IP Phones section
CDP
Dhcp
Nologieswhitepaper0900aecd804cd46d.shtml
See the LLDP-MED and Cisco Discovery Protocol
SIP
Communications Manager Security Guide
Chapter in the Cisco Unified Communications
Manager System Guide
Related Topics
Configuring Telephony Features
Feature Overview
Related Topic
Understanding Security Features for Cisco Unified IP Phones
Providing Users with Feature Information
Topic Reference
Refer to the Troubleshooting Guide for Cisco Unified
Communications Manager
Overview of Supported Security Features
Feature Description
Access section on
Security Profiles section on page 1-13for more information
Configuration Menu section on
Understanding Security Profiles
Identifying Encrypted Phone Calls
Unified IP Phones section on page 1-16for more information
Establishing and Identifying Secure Audio Conference Calls
Initiator’s Phone
Feature Used
Results of Action
Supporting 802.1X Authentication on Cisco Unified IP Phones
Overview
Security Restrictions
Configuring Cisco Unified IP Phones in Cisco Unified CM
Purpose For More Information
Communications Manager Administration Guide, Cisco
Communications Manager Administration Guide
Cisco Communications Manager
Task Purpose For More Information
Communications Manager Administration Guide, End
Unified Communications Manager
Installing Cisco Unified IP Phones
See the Providing Power to the Cisco Unified IP Phone
See the Installing the Cisco Unified IP Phone section
See the Footstand section on
Refer to Cisco Unified IP Phone 8941 and 8945 User
Guide for Cisco Unified Communications Manager
User Guide Administration and System Guides
Terminology Differences
A P T E R
Related Topic
Providing Power to the Cisco Unified IP Phone
Understanding the Phone Startup Process, Network Setup Menu,
Power Outage
Power Guidelines
Power Type Guidelines
Understanding Phone Configuration Files
Obtaining Additional Information about Power
Resolving Startup Problems,
Understanding the Phone Startup Process
Purpose Related Topics
Adding Phones to the Cisco Unified CM Database
Refer to the Cisco Unified Communications Manager
Adding Phones to the Cisco Unified CM Database
Adding Phones with Auto-Registration
Requires MAC Method Address?
Taps
Adding Phones with Auto-Registration and Taps
Adding Phones with Cisco Unified CM Administration
Adding Phones with BAT
Determining the MAC Address for a Cisco Unified IP Phone
OL-20851-01
Before You Begin
Network Requirements
Network and Access Ports
Cisco Unified Communications Manager Configuration
Network and Access Ports, Handset, Speakerphone, Headset,
Speakerphone
Handset
Headset
Audio Quality Subjective to the User
Installing the Cisco Unified IP Phone
See the Network and Access Ports section on
See the Headset section on page 3-3for supported
See the Adding Phones to the Cisco Unified CM
Cisco Unified IP Phone 8941 and 8945 Cable Connections
Reducing Power Consumption on the Phone
Footstand
Chapter Footstand
Higher Viewing Angle
Lower Viewing Angle
Verifying the Phone Startup Process
Hold Mute Speaker
Configuring Security on the Cisco Unified IP Phone
Configuring Startup Network Settings
Before You Begin
Procedure
Configuring Settings on the Cisco Unified IP Phone
Configuration Menus on the Cisco Unified IP Phone
Select Administrator Settings
Displaying a Configuration Menu
Unlocking and Locking Options, Editing Values,
Unlocking and Locking Options
Network Setup Menu, IPv4 Setup Menu Options,
Editing Values
Option Description To Change
Network Setup Menu
Select
PC Vlan
Configuration
Device Phone Phone
IPv4 Setup Menu Options
Related Topics
Security Configuration Menu
802.1X Authentication and Status
Device Phone Phone Configuration
Trust List Menu
Choose Applications Administrator
Settings Security Config
Authentication Device Authentication
Settings Security Setup
OL-20851-01
Configuring Features, Templates, Services, and Users
Choose System Service Parameter and select
Feature Description Configuration Reference
Set Builtin Bridge Enable to On
Configuration Device Device Settings
Configuration System Enterprise Phone
Common Phone Profile
Features and Services Guide, Cisco Call
Features and Services Guide, Call Display
Administration Guide, Directory Number
Forward Maximum Hop Count service parameter
Services Guide, Call Park and Directed Call
Services Guide, Monitoring and Recording
Understanding Directory Numbers
Park
System Guide, Understanding Directory
Numbers
Unified Communications Manager Features
Services Guide
Services Guide, Cisco Web Dialer
CMC
Services Guide, Immediate Divert
Services Guide, Do Not Disturb
Manager Features and Services Guide, Hold
Feature, see the Cisco Unified Communications
Administration Guide, Hunt Group
Communications Manager Feature
Services Guide, Intercom
Refer to Cisco Unified Communications
Manager System Guide, Cisco Unified IP
Administration Guide, Message Waiting
Features and Services Guide, Malicious
Services Guide, Music On Hold
Features and Services Guide Barge
Administration Guide, Phone Button
Features and Services Guide, Quality
Unified IP Phone 8941 and 8945 User Guide
Overview of Supported Security Features
Administration Guide, Conference
Bridge Configuration
Creating Custom Phone Rings section
Services
Administration Guide, Time Period
Bridge Configuration chapter
Administration Guide, Cisco Voice-Mail
Port Configuration
Join and Direct Transfer Policy
Configuring Corporate Directories
Configuring Corporate and Personal Directories
Configuring Personal Directory
Modifying Phone Button Templates
Synchronizer
For PAB, enter the following URL
Supported as a
Configuring Softkey Templates
DND
Setting Up Services
Adding Users to Cisco Unified Communications Manager
Managing the User Options Web Pages
Giving Users Access to the User Options Web Pages
Click Add Selected
Enter the appropriate search criteria and click Find
Click Device Association
Click Save Selected/Changes
Chapter Managing the User Options Web Pages
Chapter Managing the User Options Web Pages
Customizing and Modifying Configuration Files
Customizing the Cisco Unified IP Phone
Creating Custom Phone Rings
DistinctiveRingList File Format Requirements
Configuring a Custom Phone Ring
PCM File Requirements for Custom Ring Types
Configuring the Idle Display
Field Description
OL-20851-01
Model Information Screen
Model Information Screen, Status Menu,
Status Messages Screen
Status Menu
Select Status Messages
Phones with Cisco Unified CM Administration
Network Setup Menu section on page 4-4for
Address. See the Network Setup Menu section
Message Description Possible Explanation and Action
Network Setup Menu section on
Menu section on page 4-4for details
Setup Menu section on page 4-4for details on
Network Statistics Screen
Select Status Network Statistics
Dhcp Disabled
Dhcp Reboot
Dhcp Waiting Coldboot Timeout
SET Dhcp Coldboot
Call Statistics Screen
Select Call Statistics
Voice Quality Metrics
MOS LQK
Security Configuration
Select Administrator Settings Select Security Setup
Monitoring the Cisco Unified IP Phone Remotely
Accessing the Web Page for a Phone
Http//IPaddress
Device Information
Disabling and Enabling Web Page Access
Choose Device Phone
Network Setup
UDI
Description
Description
Network Statistics
Lldp
Device Logs
Streaming Statistics
Stream
Streaming Statistics
Configuring Settings on the Cisco Unified IP Phone chapter
Troubleshooting and Maintenance
Resolving Startup Problems
Chapter Resolving Startup Problems
Identifying Error Messages
Verifying DNS Settings
Choose Tools Control Center Feature Services
Symptom Cisco Unified IP Phone Unable to Obtain IP Address
Cisco Unified IP Phone Resets Unexpectedly
Verifying Dhcp Settings
Verifying the Physical Connection
Identifying Intermittent Network Outages
Checking Static IP Address Settings
Verifying the Voice Vlan Configuration
Verifying that the Phones Have Not Been Intentionally Reset
Eliminating DNS or Other Connectivity Errors
Checking Power Connection
Troubleshooting Cisco Unified IP Phone Security
Problem Possible Cause
General Troubleshooting Tips
Summary Explanation
Locking Options section on page 4-3 for details
Halfduxcollisionexceedthreshold
Resetting or Restoring the Cisco Unified IP Phone
Performing a Basic Reset
Performing a Factory Reset
Operation Performing Explanation
Monitoring the Voice Quality of Calls
Troubleshooting Tips
Metric Change Condition
Where to Go for More Troubleshooting Information
Cleaning the Cisco Unified IP Phone
Chapter Cleaning the Cisco Unified IP Phone
Providing Information to Users Via a Website
How Users Access a Voice Messaging System
How Users Configure Personal Directory Entries
Installing the Synchronizer
Configuring the Synchronizer
Programs Cisco Systems TabSync
Installing the Cisco Unified CM Locale Installer
Support for International Call Logging
OL-20851-01
Physical and Operating Environment Specifications
Specification Value or Range
Cable Specifications
Network and Access Port Pinouts
Network Port Connector
Pin Number Function
Access Port Connector
OL-20851-01
Basic Phone Administration Steps
Example User Information for these Procedures
Adding a User to Cisco Unified CM
Adding a User From an External Ldap Directory
Choose System Ldap Ldap Directory
Click Perform Full Sync Now
Proceed to the section Configuring the Phone, page D-3
Configuring the Phone
Example doe
Appendix Configuring the Phone
Appendix Configuring the Phone
Choose User Management End User
Performing Final End User Configuration Steps
Click Device Associations
Protocol Features
Sccp SIP
Appendix
EFT Draft Cisco Confidential
Tool
Numerics
IN-2
IN-3
IN-4
LLDP-MED
IN-5
MIC
Cast CDP Dhcp Http Rtcp RTP Sccp SIP Srtp TCP Tftp TLS UDP
IN-7
Srst Srtp
IN-8
IN-9
Vlan