Configuration · guide

Setting up 802.1X authentication for Cisco IP phones

Cisco Unified CM

Verified 2026-10-02 · 72 sources · tier 2 · 2 disputed

For UC and network engineers who run an on-premises Unified CM cluster and own, or work with the owner of, the access switches and the RADIUS policy..

The 802.1X supplicant in Cisco IP Phones on Unified CM uses EAP-FAST and EAP-TLS, and EAP-TLS requires a client certificate for authentication and network access 57 23. In multidomain authentication, a Catalyst switch identifies an authenticated device as a voice device only if the RADIUS server returns device-traffic-class=voice, and otherwise treats it as a data device 22.

Before you start

  • List the phone models and firmware in scope, because the menus differ between 8800 phones and 9800 or 8875 phones 2 5.
  • Out of the box, Cisco IP Phones are capable of 802.1X but are not enabled for it 47.
  • Confirm the Unified CM release: the end of software maintenance releases for Unified CM Version 14 was 7 April 2026 64, and the last date of support for Cisco Unified CM Version 14 is 30 April 2027 65.
  • WarmTransfer's reading of the sources is that, as of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, so new deployments and upgrades would normally target 15SU4a or later 66.
  • If some phones also use Wi-Fi, note that on the 8800 series an LSC cannot be used as the user certificate for EAP-TLS with WLAN authentication 4, while from PhoneOS 3.2 9800-series phones can use one 54.
  • Each Cisco IP Phone contains a unique manufacturing installed certificate (MIC) used for device authentication 41, signed by the Cisco Manufacturing CA 45.
  • In Unified CM 15, phone LSCs are signed by CAPF, by an Online CA, or by an Offline CA 36.
  • WarmTransfer's reading of the sources is that, for a new wired 802.1X deployment on Unified CM, an LSC is the certificate Cisco's guidance points to for EAP-TLS, with MIC-based EAP-TLS a lower-assurance option 34.
  • For the port decision, multidomain authentication allows 1 data device and 1 voice device on a port, each authenticated individually 39.
  • On Catalyst 9300 switches running IOS XE 17.18.x, voice VLAN is supported only on access ports, not on trunk ports, and the 9500X and 9600X models do not support the Voice VLAN feature 67.
  • See also Cisco IP phone registration and TFTP and ITL and CTL.
  • See also Troubleshooting IP phones that do not get a voice VLAN or DHCP options.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

Which certificate will the phones present for EAP-TLS?
Which RADIUS server authenticates the phones?
What is connected to each phone's switch port?

Three questions. One permanent page you can send to your manager.

Step 1 Confirm scope, versions and phone capability

Do

  • Confirm the cluster is not relying on Unified CM Version 14 software maintenance, which ended on 7 April 2026 64.
  • Version 15 is the latest Unified CM major release listed on Cisco's support pages, released on 16 October 2023 with status Available 68.
  • Confirm the phones will use EAP-TLS, which the phone supplicant uses alongside EAP-FAST 57, and that each phone will have a client certificate for it 23.

Verify

  • Suggested check: you hold a list of every phone model and firmware version in scope, together with the call-control release the cluster runs.

Step 2 Prepare and issue the phone certificates

LSC issued by the Unified CM CAPF in its default mode

Do

  • Leave CAPF in its default mode, the Cisco Authority Proxy Function, which issues CAPF-signed LSCs 12.
  • Set the CAPF service parameter Duration Of Certificate Validity, which sets how many days a CAPF-issued certificate is valid and accepts 1 to 1825 15.
  • Activate or restart the CAPF services on the Unified CM publisher node after the CAPF system settings are configured 13.
  • Before an LSC is set up on an 8800 phone, the CTL or ITL file must contain the CAPF certificate, the CAPF certificate must be installed in OS Administration, and CAPF must be running and configured 35.
  • Choose the authentication mode the phones will use for the LSC operation: By Null String, By Authentication String or By Existing Certificate 9.
  • In each phone's Certification Authority Proxy Function Information pane, set Certificate Operation, Authentication Mode, Authentication String, Key Order, RSA Key Size or EC Key Size, and Operation Completes By 14.
  • For an LSC Install/Upgrade, set Operation Completes By at least 1 hour in the future, then Save and Apply Config 50.
  • For many phones, apply CAPF settings through Bulk Administration (Update Phones > Query) or, for LDAP-synchronised devices, through a Universal Device Template 10.
  • With Bulk Administration, the Authentication Mode you choose must match the phone security profile's authentication mode or the operation cannot complete 8.
  • Schedule any change to a phone security profile's Authentication Mode, because its Save and Apply Config can restart every phone that uses that profile 55.
  • Sources disagree on whether mixed mode is needed: a current Cisco tech note states that on releases with Security By Default (8.0(1) and later) the LSC install procedure applies whether or not the cluster is in mixed mode 33, while an undated Cisco security-center page states that an LSC must be installed using USB tokens and the CTL client on a Unified CM running in mixed (secure) mode 56.
  • As a local alternative, request the LSC on an 8800 phone from Applications > Admin Settings > Security Setup > LSC by entering the CAPF authentication code 3, or on a 9800 or 8875 phone from Settings > Network and Service > Security settings > LSC by entering the authentication string 6.

Verify

  • A successful installation shows the phone's LSC Status as Installed and Certificate Operation Status as Upgrade Success in Unified CM 38.
  • On 9800 and 8875 phones, the LSC menu shows Installed on success 6.

Rollback

  • Suggested rollback: clear any pending certificate operation on the phone records, return the certificate validity parameter to its previous value, and deactivate the certificate proxy service if it was not in use before.

LSC signed by your enterprise CA through CAPF (Online CA or Offline CA mode)

Do

  • Choose Online CA, where CSRs are signed automatically, or Offline CA, where CSRs are downloaded, signed externally and uploaded manually 12.
  • Cisco describes the Offline CA LSC process as more time-consuming than using an Online CA 48.
  • Online CA mode does not support CAPF operations with ECDSA key sizes 49.
  • Set the CAPF service parameter Duration Of Certificate Validity, which accepts 1 to 1825 days 15.
  • Activate or restart the CAPF services on the Unified CM publisher node after the CAPF system settings are configured 13.
  • Before an LSC is set up on an 8800 phone, the CTL or ITL file must contain the CAPF certificate, the CAPF certificate must be installed in OS Administration, and CAPF must be running and configured 35.
  • Choose the authentication mode the phones will use for the LSC operation: By Null String, By Authentication String or By Existing Certificate 9.
  • In each phone's Certification Authority Proxy Function Information pane, set Certificate Operation, Authentication Mode, Authentication String, Key Order, RSA Key Size or EC Key Size, and Operation Completes By 14.
  • For an LSC Install/Upgrade, set Operation Completes By at least 1 hour in the future, then Save and Apply Config 50.
  • For many phones, apply CAPF settings through Bulk Administration (Update Phones > Query) or, for LDAP-synchronised devices, through a Universal Device Template 10.
  • With Bulk Administration, the Authentication Mode you choose must match the phone security profile's authentication mode or the operation cannot complete 8.
  • Schedule any change to a phone security profile's Authentication Mode, because its Save and Apply Config can restart every phone that uses that profile 55.
  • With Offline CA, download the CSRs, have them signed externally and upload the signed certificates 12.
  • Sources disagree on whether mixed mode is needed: a current Cisco tech note states that on releases with Security By Default (8.0(1) and later) the LSC install procedure applies whether or not the cluster is in mixed mode 33, while an undated Cisco security-center page states that an LSC must be installed using USB tokens and the CTL client on a Unified CM running in mixed (secure) mode 56.
  • As a local alternative, request the LSC on an 8800 phone from Applications > Admin Settings > Security Setup > LSC 3, or on a 9800 or 8875 phone from Settings > Network and Service > Security settings > LSC 6.

Verify

  • A successful installation shows the phone's LSC Status as Installed and Certificate Operation Status as Upgrade Success in Unified CM 38.

Rollback

  • Suggested rollback: clear any pending certificate operation on the phone records, switch the certificate proxy service back to its previous mode, and restart that service.

Factory Manufacturing Installed Certificate (MIC) with no LSC

Do

  • MICs are signed by the Cisco Manufacturing CA and are installed automatically on supported phones 45.
  • Record that the deployment relies on MICs, which the Unified CM 15 Security Guide recommends using only for LSC installation 43.
  • Cisco states that customers who use MICs for TLS authentication or any other purpose do so at their own risk, and that Cisco assumes no liability if MICs are compromised 46.
  • Cisco's 802.1X design guide says that because the administrator controls LSC enrollment, LSCs are a more tightly controlled and trusted credential than MICs 37.

Verify

  • Suggested check: the change record states that phones will present their factory certificates and names who accepted that risk.

Step 3 Export the trust anchors

LSC issued by the Unified CM CAPF in its default mode

Do

  • Download the CAPF certificate at Cisco Unified OS Administration > Security > Certificate Management by finding it and clicking Download 63.
  • Cisco's design guide states that the root certificates for LSCs can be exported from Unified CM and imported into the AAA server so it can validate phone certificates 24.

Verify

  • Suggested check: the subject of the downloaded certificate matches the issuer shown on a sample phone's locally significant certificate.

LSC signed by your enterprise CA through CAPF (Online CA or Offline CA mode)

Do

  • Cisco's design guide states that the root certificates for LSCs can be exported from Unified CM and imported into the AAA server so it can validate phone certificates 24.
  • Where the CA chain is held on Unified CM, download each certificate at Cisco Unified OS Administration > Security > Certificate Management by finding it and clicking Download 63.

Verify

  • Suggested check: you hold every CA certificate in the chain that signed the phones' certificates, root and intermediates alike.

Factory Manufacturing Installed Certificate (MIC) with no LSC

Do

  • Cisco's design guide states that the root certificates for MICs can be exported from Unified CM and imported into the AAA server so it can validate phone certificates 24.
  • Download each certificate at Cisco Unified OS Administration > Security > Certificate Management by finding it and clicking Download 63.
  • The Unified CM 15 Security Guide names the MIC root certificates as CAP-RTP-001, CAP-RTP-002, Cisco_Manufacturing_CA, Cisco_Root_CA_2048, Cisco_Manufacturing_CA_SHA2, Cisco_Root_CA_M2 and ACT2_SUDI_CA 44.

Verify

  • Suggested check: the issuer of a sample phone's factory certificate matches one of the certificates you exported.

Step 4 Configure RADIUS trust and EAP-TLS

Cisco ISE

Do

  • Import each CA certificate you exported at Administration > System > Certificates > Certificate Management > Trusted Certificates, with the usage Trust for client authentication and Syslog checked so it can validate EAP clients 31.
  • Create a Certificate Authentication Profile at Administration > Identity Management > External Identity Sources > Certificate Authentication Profile to tell ISE which certificate field holds the identity 27.
  • Confirm EAP-TLS is enabled under Policy > Policy Elements > Results > Authentication > Allowed Protocols 25.
  • In ISE 3.3, the Default Allowed Protocol Service for the default policy set allows PAP/ASCII, EAP-MD5, EAP-TLS, PEAP, EAP-FAST and EAP-TTLS 28.

Verify

  • Suggested check: each imported certificate appears in the trusted certificate store with client-authentication trust enabled.

Rollback

  • Suggested rollback: delete the imported trusted certificates and the certificate authentication profile you created.

Another RADIUS server

Do

  • Import the exported CA certificates into the server as trusted roots, since Cisco's design guide states the root certificates can be imported into the AAA server so it can validate phone certificates 24.
  • Enable EAP-TLS for the switch clients, since the phone supplicant uses EAP-FAST and EAP-TLS for network authentication 57.

Verify

  • Suggested check: a test authentication from one phone reaches the server and its certificate chain validates.

Rollback

  • Suggested rollback: remove the trusted roots and the EAP-TLS policy you added.

Step 5 Authorise phones into the voice domain

Cisco ISE

Do

  • Manage the authorization profile at Policy > Policy Elements > Results > Authorization > Authorization Profiles 26.
  • Make the profile return device-traffic-class=voice, because without it a Catalyst switch treats the authenticated device as a data device 22.
  • Write the authorization rule on certificate attributes, which Cisco's design guide recommends so individual phones need not be entered in a database 17.
  • ISE 3.3 ships a predefined rule, Profiled Cisco IP Phones, that matches the endpoint identity group Profiled:Cisco-IP-Phone and returns the Cisco_IP_Phones authorization profile, so review whether it should remain alongside your certificate rule 30.

Verify

  • At Operations > RADIUS > Live Logs, a successful EAP-TLS authentication shows event 5200 Authentication succeeded 29.

Rollback

  • Suggested rollback: disable the new authorization rule.

Another RADIUS server

Do

  • We infer that a non-ISE RADIUS server authenticating Cisco phones behind an MDA port must be configured to return the Cisco AV pair device-traffic-class=voice in its Access-Accept for the phone to reach the voice VLAN 51.
  • Without device-traffic-class=voice, a Catalyst switch treats the authenticated device as a data device 22.
  • Authorise on certificate attributes, which Cisco's design guide recommends so individual phones need not be entered in a database 17.

Verify

  • On the switch, show access-session and show authentication sessions display the 802.1X and MAB session state of the phone's port 60.

Rollback

  • Suggested rollback: remove the authorization policy you added.

Step 6 Configure the switch ports

Phone plus a PC on the phone's PC port (multi-domain authentication)

Do

  • Configure the interface with authentication (or access-session) host-mode multi-domain, dot1x pae authenticator, authentication (or access-session) port-control auto and, as an optional fallback, mab 59.
  • Because the host mode is multi-domain, configure the voice VLAN on the port with switchport voice vlan 40.
  • Cisco's phone guide says to keep the voice VLAN when the switch supports multidomain authentication 53.
  • Keep CDP enabled on the port, because Catalyst 9300 voice VLAN needs it to configure a Cisco IP phone 69.
  • Expect a second device of the same class on the port to cause a security violation 39.
  • Optionally add authentication event server dead action authorize voice, which enables critical voice VLAN and keeps voice devices on the voice VLAN when the RADIUS server is unreachable 18.
  • Cisco IP Phones can send a CDP message telling the switch that the PC port link is down, so the switch can clear the data device's session immediately 16.
  • Schedule the change, because Cisco documents that enabling 802.1X on a Catalyst 9300 access port with a voice VLAN and a connected Cisco IP phone causes the phone to lose connectivity for up to 30 seconds 70.

Verify

  • Run show interfaces interface-id switchport, which displays the voice VLAN configuration of the port 71.
  • Suggested check: the running interface configuration shows multi-domain host mode alongside the voice VLAN.

Rollback

  • Suggested rollback: restore the interface configuration you saved before the change.
  • On Catalyst 9300, 802.1X is globally disabled by default and ports default to force-authorized in single-host mode 58.

Phone only with the PC port unused

Do

  • Configure the interface with dot1x pae authenticator, authentication (or access-session) port-control auto and, as an optional fallback, mab 59.
  • If you use multi-domain host mode, configure the voice VLAN with switchport voice vlan 40.
  • Cisco's phone guide says to keep the voice VLAN when the switch supports multidomain authentication, and otherwise to disable the voice VLAN and consider assigning the port to the native VLAN 53.
  • Optionally add authentication event server dead action authorize voice, which enables critical voice VLAN and keeps voice devices on the voice VLAN when the RADIUS server is unreachable 18.
  • Schedule the change, because Cisco documents that enabling 802.1X on a Catalyst 9300 access port with a voice VLAN and a connected Cisco IP phone causes the phone to lose connectivity for up to 30 seconds 70.

Verify

  • Run show interfaces interface-id switchport, which displays the voice VLAN configuration of the port 71.
  • Suggested check: the running interface configuration shows 802.1X enabled with the host mode you chose.

Rollback

  • Suggested rollback: restore the interface configuration you saved before the change.
  • On Catalyst 9300, 802.1X is globally disabled by default and ports default to force-authorized in single-host mode 58.

Step 7 Plan the bootstrap and the enforcement phases

Do

  • Give new phones initial access, because a new phone needs network access to download its 802.1X configuration before it can authenticate, and Cisco's design guide addresses this with MAB or low-impact mode 7.
  • Roll out through the 3 phased deployment modes Cisco's design guide describes: monitor mode, low-impact mode and high-security mode 19.

Verify

  • Suggested check: while ports are in monitor mode, test phones authenticate successfully before you move any port to enforcement.

Rollback

  • Suggested rollback: move the affected ports back to monitor mode.

Step 8 Enable 802.1X on the phones

Do

  • Enable 802.1X centrally, since Unified CM can enable phones for 802.1X through the configuration file the phone downloads 62.
  • On an 8800 phone, the setting is at Applications > Admin settings > Security setup > 802.1X Authentication, with the Device Authentication option 2.
  • On 9800 and 8875 phones, 802.1X is turned on at Settings > Network and service > Security settings > 802.1X Authentication 5.
  • With Device Authentication enabled the phone uses 802.1X to request network access, and with it disabled the phone uses CDP to acquire its VLAN and network access 20.

Verify

  • The phone's 802.1X transaction status reads Authenticated when the phone is authenticated 52.

Rollback

  • Suggested rollback: turn 802.1X off again in the phone configuration and apply the change to the affected phones.

Step 9 Verify end to end

Do

  • On the phone, read the 802.1X status: Disconnected when 802.1X is not configured, Held while authentication is in progress, and Authenticated when the phone is authenticated 52.
  • On the switch, run show access-session or show authentication sessions to see the 802.1X and MAB session state 60.
  • With ISE, check Operations > RADIUS > Live Logs for event 5200 Authentication succeeded 29.

Verify

  • Suggested check: the phone shows as authenticated, the switch session sits in the voice domain, and the phone registers to call control and places a test call.

Step 10 Troubleshoot authentication failures

Do

  • Phone stays Held: that status means authentication is still in progress 52, so check the switch session with show access-session or show authentication sessions 60.
  • Phone fails 802.1X on an 8800: Cisco's procedure is to verify that the required components are configured and that the shared secret on the phone matches the one on the authentication server 72.
  • Phone authenticates but lands in the data VLAN: without device-traffic-class=voice from the RADIUS server, the switch treats the device as a data device 22.
  • LSC never installs: Cisco lists an expired or past Operation Completes By time and a mismatch between the CAPF certificate in the phone's ITL file and the current CAPF certificate as causes 32, and a Bulk Administration authentication mode that differs from the phone security profile's stops the operation 8.
  • New phones never get a configuration: a new phone needs network access to download its 802.1X configuration, which Cisco's design guide provides through MAB or low-impact mode 7.
  • Violation on an MDA port: a second device of the same class is present 39.

Verify

  • Suggested check: the failing phone reaches the authenticated state and registers.

Rollback

  • Suggested rollback: put the affected port back in monitor mode while you investigate.

Applicability

Applies to: Cisco IP Phone 8800 Series, Cisco Desk Phone 9800 Series, Cisco TrustSec, Cisco Unified CM, Cisco Catalyst 9300, Cisco ISE, Cisco IP Phone, Cisco Unified Communications Manager, and Cisco Catalyst 9300 Series Switches. Deployments: on-premises. Sources checked 2026-10-02.

  • The MIC root certificate names and the recommendation to use MICs only for LSC installation come from the Unified CM 15 Security Guide 44 43.
  • The switch defaults and commands are documented for Catalyst 9300 on IOS XE 17.18.x 58 18.
  • The default allowed protocols and the Profiled Cisco IP Phones rule are documented for ISE 3.3 28 30.
  • LSC use for WLAN EAP-TLS on 9800-series phones starts at PhoneOS 3.2 54.

What remains uncertain

  • How to remove an LSC that is already installed on a phone is not covered by the sources below.
  • Which of the MIC root certificates chains a given phone model's MIC is not covered by the sources below.
  • The exact Unified CM configuration field that enables 802.1X centrally is not covered by the sources below.
  • The name of the ISE authorization profile setting that returns device-traffic-class=voice is not covered by the sources below.
  • Menus and procedures for RADIUS servers other than ISE are not covered by the sources below.
  • Revocation checking of phone certificates by the RADIUS server is not covered by the sources below.
  • Whether other switch platforms and releases behave as documented here is not covered by the sources below.
  • The full wireless 802.1X procedure for phones is not covered by the sources below.

See also

Depends on

  • Cisco unified cm — CAPF; LSC enrollment and phone configuration run on Unified CM; version and support-status claims are reused from that topic.

Referenced by

Sources

  1. 1
    802.1X with an LSC does not by itself require changing the phone's Device Security Mode, because the LSC is used toward the RADIUS server while Device Security Mode governs signalling to Unified CM.inferred
    Configure LSC on IP Phone with CUCM · Background Information (LSC install independent of mixed mode) · Checked 2026-10-02
  2. 2
    On an 8800 phone 802.1X is set at Applications > Admin settings > Security setup > 802.1X Authentication with the Device Authentication option.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Enable 802.1X Authentication · Checked 2026-10-02
  3. 3
    On an 8800 phone an LSC can be requested locally from Applications > Admin Settings > Security Setup > LSC by entering the CAPF authentication code.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Set Up a Locally Significant Certificate > Procedure · Checked 2026-10-02
  4. 4
    On the 8800 series an LSC cannot be used as the user certificate for EAP-TLS with WLAN authentication.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Set Up a Locally Significant Certificate (note) · Checked 2026-10-02
  5. 5
    On 9800 and 8875 phones 802.1X is turned on at Settings > Network and service > Security settings > 802.1X Authentication.
    Cisco IP Phone security on 9800/8875 (Unified CM) · Enable 802.1X authentication · Checked 2026-10-02
  6. 6
    On 9800 and 8875 phones an LSC is requested from Settings > Network and Service > Security settings > LSC by entering the authentication string, and the phone shows Installed on success.
    Cisco IP Phone security on 9800/8875 (Unified CM) · Set up a Locally Significant Certificate · Checked 2026-10-02
  7. 7
    A new phone needs network access to download its 802.1X configuration before it can authenticate, and Cisco's design guide addresses this with MAB or low-impact mode to give the phone enough initial access.
    IP Telephony for 802.1X Design Guide · Enabling 802.1X On Phones (bootstrapping) · Checked 2026-10-02
  8. 8
    When CAPF settings are applied with Bulk Administration, the Authentication Mode chosen must match the phone security profile's authentication mode or the operation cannot complete.
    Configure LSC on IP Phone with CUCM · Configure > Bulk Administration note · Checked 2026-10-02
  9. 9
    The CAPF authentication modes a phone can use to authenticate for an LSC operation are By Null String, By Authentication String and By Existing Certificate.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF · Configure CAPF > CAPF Settings / Authentication Mode · Checked 2026-10-02
  10. 10
    CAPF settings can be applied to many phones through Bulk Administration (Update Phones > Query) or, for LDAP-synchronised devices, through a Universal Device Template.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > Configure CAPF Settings (Bulk Administration; Universal Device Template) · Checked 2026-10-02
  11. 11
    The CAPF service on Unified CM issues LSCs to supported Cisco IP Phones, authenticates phones in mixed mode, upgrades existing LSCs, and retrieves phone certificates for viewing and troubleshooting.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > CAPF overview · Checked 2026-10-02
  12. 12
    CAPF can run as the Cisco Authority Proxy Function (the default, issuing CAPF-signed LSCs), with an Online CA that signs CSRs automatically, or with an Offline CA where CSRs are downloaded, signed externally and uploaded manually.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function · Certificate Authority Proxy Function > CAPF operating modes · Checked 2026-10-02
  13. 13
    The CAPF services are activated on the Unified CM publisher node after the CAPF system settings are configured.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF · Configure CAPF > Activate or Restart CAPF Services · Checked 2026-10-02
  14. 14
    The Certification Authority Proxy Function Information pane of a phone's configuration has the fields Certificate Operation, Authentication Mode, Authentication String, Key Order, RSA Key Size, EC Key Size and Operation Completes By.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF · Configure CAPF > Configure CAPF Settings for a Phone · Checked 2026-10-02
  15. 15
    The CAPF service parameter Duration Of Certificate Validity sets how many days a CAPF-issued certificate is valid and accepts 1 to 1825.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF · Configure CAPF > CAPF service parameters, Duration Of Certificate Validity · Checked 2026-10-02
  16. 16
    Cisco IP Phones can send a CDP message telling the switch that the PC port link is down, so the switch can clear the data device's session immediately.
    IP Telephony for 802.1X Design Guide · Link State Problem > CDP Enhancement for Second Port Disconnect · Checked 2026-10-02
  17. 17
    Cisco's design guide recommends authorising phones on certificate attributes so individual phones need not be entered in a database.
    IP Telephony for 802.1X Design Guide · Using Certificates (authorization) · Checked 2026-10-02
  18. 18
    The command authentication event server dead action authorize voice enables critical voice VLAN, which keeps voice devices on the voice VLAN when the RADIUS server is unreachable.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Critical Voice VLAN · Checked 2026-10-02
  19. 19
    Cisco's design guide describes three phased 802.1X deployment modes: monitor mode, low-impact mode and high-security mode.
    IP Telephony for 802.1X Design Guide · Deployment Scenarios (Monitor Mode; Low-Impact Mode; High-Security Mode) · Checked 2026-10-02
  20. 20
    With Device Authentication enabled the phone uses 802.1X to request network access; with it disabled the phone uses CDP to acquire its VLAN and network access.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > 802.1X Authentication Settings · Checked 2026-10-02
  21. 21
    Cisco's 802.1X design guide lists EAP-TLS and EAP-FAST as certificate-capable methods for phones, EAP-MD5 for password-based authentication, and MAB as the fallback for phones that cannot do 802.1X.
    IP Telephony for 802.1X Design Guide · Authentication Methods · Checked 2026-10-02
  22. 22
    In multidomain authentication a Catalyst switch identifies an authenticated device as a voice device only if the RADIUS server returns device-traffic-class=voice; without it the device is treated as a data device.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Multidomain Authentication · Checked 2026-10-02
  23. 23
    EAP-TLS on Cisco IP Phones requires a client certificate for authentication and network access.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Supported Security Features table, EAP-TLS row · Checked 2026-10-02
  24. 24
    The root certificates for both LSCs and MICs can be exported from Unified CM and imported into the AAA server so it can validate phone certificates.
    IP Telephony for 802.1X Design Guide · Using Certificates · Checked 2026-10-02
  25. 25
    EAP-TLS is enabled in ISE under Policy > Policy Elements > Results > Authentication > Allowed Protocols.
    Configure EAP-TLS Authentication with ISE · Configure > Allowed Protocols · Checked 2026-10-02
  26. 26
    ISE authorization profiles are managed at Policy > Policy Elements > Results > Authorization > Authorization Profiles.
    Cisco Identity Services Engine Administrator Guide, Release 3.3 - Segmentation · Segmentation > Authorization Profiles · Checked 2026-10-02
  27. 27
    An ISE Certificate Authentication Profile, created at Administration > Identity Management > External Identity Sources > Certificate Authentication Profile, tells ISE which certificate field holds the identity.
    Configure EAP-TLS Authentication with ISE · Configure > Certificate Authentication Profile · Checked 2026-10-02
  28. 28
    In ISE 3.3 the Default Allowed Protocol Service for the default policy set allows PAP/ASCII, EAP-MD5, EAP-TLS, PEAP, EAP-FAST and EAP-TTLS.
    Cisco Identity Services Engine Administrator Guide, Release 3.3 - Segmentation · Segmentation > Policy Sets > Default policy set · Checked 2026-10-02
  29. 29
    EAP-TLS results are checked in ISE at Operations > RADIUS > Live Logs, where a success shows event 5200 Authentication succeeded.
    Configure EAP-TLS Authentication with ISE · Verify · Checked 2026-10-02
  30. 30
    ISE 3.3 ships a predefined authorization rule Profiled Cisco IP Phones that matches the endpoint identity group Profiled:Cisco-IP-Phone and returns the Cisco_IP_Phones authorization profile.
    Cisco Identity Services Engine Administrator Guide, Release 3.3 - Segmentation · Segmentation > Default Authorization Policies (predefined rules table) · Checked 2026-10-02
  31. 31
    In ISE a CA certificate is imported at Administration > System > Certificates > Certificate Management > Trusted Certificates, with the usage Trust for client authentication and Syslog checked so it can validate EAP clients.
    Configure EAP-TLS Authentication with ISE · Configure > Import the root certificate into ISE Trusted Certificates · Checked 2026-10-02
  32. 32
    Cisco lists an expired or past Operation Completes By time and a mismatch between the CAPF certificate in the phone's ITL file and the current CAPF certificate as causes of LSC installation failure.
    Configure LSC on IP Phone with CUCM · Troubleshoot · Checked 2026-10-02
  33. 33
    A current Cisco tech note states that on Unified CM releases with Security By Default (8.0(1) and later) the LSC install procedure applies whether or not the cluster is in mixed mode.disputed
    Configure LSC on IP Phone with CUCM · Configure LSC on IP Phone with CUCM > Background Information · Checked 2026-10-02
  34. 34
    For a new wired 802.1X deployment on Unified CM, an LSC is the certificate Cisco's guidance points to for EAP-TLS, with MIC-based EAP-TLS a lower-assurance option.inferred
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Phone Certificate Types (combined with design guide Using Certificates) · Checked 2026-10-02
  35. 35
    Before an LSC is set up on an 8800 phone, the CTL or ITL file must contain the CAPF certificate, the CAPF certificate must be installed in OS Administration, and CAPF must be running and configured.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Set Up a Locally Significant Certificate > Before you begin · Checked 2026-10-02
  36. 36
    In Unified CM 15, phone LSCs are signed by CAPF, by an Online CA, or by an Offline CA.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Phone Certificate Types > Locally Significant Certificates (LSC) · Checked 2026-10-02
  37. 37
    Cisco's 802.1X design guide says that because the administrator controls LSC enrollment, LSCs are a more tightly controlled and trusted credential than MICs.
    IP Telephony for 802.1X Design Guide · Using Certificates > Self-Signed CAPF vs. CA-Signed CAPF · Checked 2026-10-02
  38. 38
    A successful LSC installation shows the phone's LSC Status as Installed and Certificate Operation Status as Upgrade Success in Unified CM.
    Configure LSC on IP Phone with CUCM · Verify · Checked 2026-10-02
  39. 39
    Multidomain authentication allows one data device and one voice device on a port, each authenticated individually; a second device of the same class causes a security violation.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Multidomain Authentication · Checked 2026-10-02
  40. 40
    When a port's host mode is multi-domain, the voice VLAN must be configured on the port with switchport voice vlan <vlan-id>.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Multidomain Authentication / Configuring the Host Mode · Checked 2026-10-02
  41. 41
    Each Cisco IP Phone contains a unique manufacturing installed certificate (MIC) that is used for device authentication.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > Supported Security Features table, Manufacturing installed certificate row · Checked 2026-10-02
  42. 42
    Cisco's 802.1X design guide notes that a MIC proves a device is a Cisco phone but not that it is a corporate-owned asset, whereas an LSC issued by your own CAPF does.
    IP Telephony for 802.1X Design Guide · Using Certificates > certificate types comparison · Checked 2026-10-02
  43. 43
    The Unified CM 15 Security Guide recommends using MICs only for LSC installation.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Phone Certificate Types · Checked 2026-10-02
  44. 44
    The Unified CM 15 Security Guide names the MIC root certificates as CAP-RTP-001, CAP-RTP-002, Cisco_Manufacturing_CA, Cisco_Root_CA_2048, Cisco_Manufacturing_CA_SHA2, Cisco_Root_CA_M2 and ACT2_SUDI_CA.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Phone Certificate Types > Locally Significant Certificates (LSC) · Checked 2026-10-02
  45. 45
    MICs are signed by the Cisco Manufacturing CA, are installed automatically on supported phones, and authenticate the phone to CAPF for LSC installation.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Phone Certificate Types > Manufacturing Installed Certificate (MIC) · Checked 2026-10-02
  46. 46
    Cisco states that customers who use MICs for TLS authentication or any other purpose do so at their own risk, and that Cisco assumes no liability if MICs are compromised.
    Cisco IP Phone Certificates and Secure Communications · MIC section (risk statement) · Checked 2026-10-02
  47. 47
    Out of the box, Cisco IP Phones are capable of 802.1X but are not enabled for it.
    IP Telephony for 802.1X Design Guide · Enabling 802.1X On Phones · Checked 2026-10-02
  48. 48
    Cisco describes the Offline CA LSC process as more time-consuming than using an Online CA.
  49. 49
    Online CA mode does not support CAPF operations with ECDSA key sizes.
  50. 50
    For an LSC Install/Upgrade, the Operation Completes By date and time should be at least one hour in the future, and the change is saved and then applied with Apply Config.
    Configure LSC on IP Phone with CUCM · Configure > Phone Configuration CAPF Information · Checked 2026-10-02
  51. 51
    A non-ISE RADIUS server authenticating Cisco phones behind an MDA port must be configured to return the Cisco AV pair device-traffic-class=voice in its Access-Accept for the phone to reach the voice VLAN.inferred
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Multidomain Authentication · Checked 2026-10-02
  52. 52
    The phone's 802.1X transaction status reads Disconnected when 802.1X is not configured, Authenticated when the phone is authenticated, and Held while authentication is in progress.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > 802.1X Authentication Status · Checked 2026-10-02
  53. 53
    Cisco's phone guide says to keep the voice VLAN when the switch supports multidomain authentication, and otherwise to disable the voice VLAN and consider assigning the port to the native VLAN.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security · Cisco IP Phone Security > 802.1X Authentication > Network Requirements for 802.1X Support · Checked 2026-10-02
  54. 54
    From PhoneOS 3.2, 9800-series phones can use an LSC as the user certificate for EAP-TLS with WLAN authentication.
    Cisco IP Phone security on 9800/8875 (Unified CM) · Supported security features / LSC · Checked 2026-10-02
  55. 55
    Changing a phone security profile's Authentication Mode requires Save and Apply Config, which can restart every phone that uses that profile.
    Configure LSC on IP Phone with CUCM · Configure > Phone Security Profile note · Checked 2026-10-02
  56. 56
    An undated Cisco security-center page states that an LSC must be installed using USB tokens and the CTL client, with the CTL provider and CAPF services enabled on a Unified CM running in mixed (secure) mode.disputed
    Cisco IP Phone Certificates and Secure Communications · LSC section · Checked 2026-10-02
  57. 57
    The 802.1X supplicant in Cisco IP Phones on Unified CM uses EAP-FAST and EAP-TLS for network authentication.
  58. 58
    On Catalyst 9300 802.1X is globally disabled by default and ports default to force-authorized in single-host mode.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Default 802.1x Authentication Configuration · Checked 2026-10-02
  59. 59
    The interface commands for an 802.1X phone port include authentication (or access-session) host-mode multi-domain, dot1x pae authenticator, mab as an optional fallback, and authentication (or access-session) port-control auto.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > How to Configure 802.1x Port-Based Authentication · Checked 2026-10-02
  60. 60
    show access-session and show authentication sessions display the 802.1X and MAB session state on a Catalyst switch port.
    Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication · Configuring IEEE 802.1x Port-Based Authentication > Monitoring 802.1x Statistics and Status · Checked 2026-10-02
  61. 61
    The Unified CM 15 CAPF task flow says that after a phone installs its LSC, the Device Security Mode can be set to Authenticated or Encrypted.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF · Configure CAPF > Configure CAPF Settings for a Phone (follow-up) · Checked 2026-10-02
  62. 62
    Unified CM can centrally enable phones for 802.1X through the configuration file the phone downloads.
    IP Telephony for 802.1X Design Guide · Solution Components > Touchless Configuration · Checked 2026-10-02
  63. 63
    A certificate is downloaded from Unified CM at Cisco Unified OS Administration > Security > Certificate Management by finding it and clicking Download.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates · Certificates > Download Certificates · Checked 2026-10-02
  64. 64
    The end of software maintenance releases for Unified CM Version 14 was 7 April 2026.
  65. 65
    Cisco Unified CM Version 14 is Not Orderable and its last date of support is 30 April 2027.
  66. 66
    As of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, and Version 14 has passed its end of software maintenance, so new deployments and upgrades would normally target 15SU4a or later.inferred
    ReadMe for Cisco Unified Communications Manager Release 15SU4a · Document header (Last Updated July 29 2026); combined with cisco-eol-v14-onprem-calling-apps Table 1 · Checked 2026-09-30
  67. 67
    On Catalyst 9300 switches running IOS XE 17.18.x, voice VLAN is supported only on access ports, not on trunk ports. The 9500X and 9600X models do not support the Voice VLAN feature.
    VLAN Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Voice VLANs · Prerequisites for Voice VLANs; Restrictions for Voice VLANs · Checked 2026-10-02
  68. 68
    Version 15 is the latest Cisco Unified Communications Manager major release listed on Cisco's support pages; it was released on 16 October 2023 and its status is Available.
    Cisco Unified Communications Manager (CallManager) - Support · Product status and Latest release fields; Supported versions list · Checked 2026-09-30
  69. 69
    For Catalyst 9300 voice VLAN to configure a Cisco IP phone, CDP must be enabled on the switch port the phone connects to. CDP is enabled globally by default.
  70. 70
    Cisco documents that enabling IEEE 802.1X on a Catalyst 9300 access port that has a voice VLAN and a connected Cisco IP phone causes the phone to lose connectivity to the switch for up to 30 seconds.
  71. 71
    On Catalyst 9300 switches, 'show interfaces interface-id switchport' displays the voice VLAN configuration of a port.
  72. 72
    Cisco's procedure for 802.1X authentication problems on 8800 phones is to verify that the required components are configured and that the shared secret configured on the phone matches the one on the authentication server.
    Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting Procedures > Identify 802.1X Authentication Problems · Checked 2026-10-02

Documents

tier 2 current vendor documentation

Cisco Identity Services Engine Administrator Guide, Release 3.3 - Segmentation

Cisco Systems · 2026-09-29 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security

Cisco · 2025-11-06 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting

Cisco Systems · 2025-11-06 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco IP Phone Certificates and Secure Communications

Cisco Systems · accessed 2026-10-02

tier 2 current vendor documentation

Cisco IP Phone security on 9800/8875 (Unified CM)

Cisco Systems · 2026-08-06 · accessed 2026-10-02

tier 2 current vendor documentation

Cisco Unified Communications Manager (CallManager) - Support

Cisco Systems · accessed 2026-09-30

tier 2 current vendor documentation

Configure EAP-TLS Authentication with ISE

Cisco Systems · 2023-07-13 · accessed 2026-10-02

tier 2 current vendor documentation

Configure LSC on IP Phone with CUCM

Cisco Systems · 2026-07-09 · accessed 2026-10-02

tier 2 current vendor documentation

IP Telephony for 802.1X Design Guide

Cisco Systems · 2014-07-02 · accessed 2026-10-02

tier 2 current vendor documentation

ReadMe for Cisco Unified Communications Manager Release 15SU4a

Cisco Systems · 2026-07-29 · accessed 2026-09-30

tier 2 current vendor documentation

Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication

Cisco Systems · 2025-07-31 · accessed 2026-10-02

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificate Authority Proxy Function

Cisco Systems · 2026-09-22 · accessed 2026-09-30

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Certificates

Cisco Systems · 2026-09-22 · accessed 2026-09-25

tier 2 current vendor documentation

System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure CAPF

Cisco Systems · accessed 2026-10-02

tier 2 current vendor documentation

VLAN Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Voice VLANs

Cisco Systems · 2025-07-31 · accessed 2026-10-02

Cite this page

APA

WarmTransfer. (2026, October 2). Setting up 802.1X authentication for Cisco IP phones. WarmTransfer. https://warmtransfer.net/guides/cisco-phone-8021x-setup

BibTeX

@misc{warmtransfer-cisco-phone-8021x-setup,
  title  = {Setting up 802.1X authentication for Cisco IP phones},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cisco-phone-8021x-setup},
  note   = {Verified 2026-10-02}
}