Source record · tier 2 current vendor documentation
IP Telephony for 802.1X Design Guide
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html
- Published
- 2014-07-02
- Updated
- unknown
- Accessed
- 2026-10-02
- HTTP status
- 200
- License
- Cisco copyright; no-redistribution; short excerpts and locators only
Source notes citing this source
- A new phone needs network access to download its 802.1X configuration before it can authenticate, and Cisco's design guide addresses this with MAB or low-impact mode to give the phone enough initial access. in context
- Cisco IP Phones can send a CDP message telling the switch that the PC port link is down, so the switch can clear the data device's session immediately. in context
- Cisco's design guide recommends authorising phones on certificate attributes so individual phones need not be entered in a database. in context
- Cisco's design guide describes three phased 802.1X deployment modes: monitor mode, low-impact mode and high-security mode. in context
- Cisco's 802.1X design guide lists EAP-TLS and EAP-FAST as certificate-capable methods for phones, EAP-MD5 for password-based authentication, and MAB as the fallback for phones that cannot do 802.1X. in context
- The root certificates for both LSCs and MICs can be exported from Unified CM and imported into the AAA server so it can validate phone certificates. in context
- Cisco's 802.1X design guide says that because the administrator controls LSC enrollment, LSCs are a more tightly controlled and trusted credential than MICs. in context
- Cisco's 802.1X design guide notes that a MIC proves a device is a Cisco phone but not that it is a corporate-owned asset, whereas an LSC issued by your own CAPF does. in context
- Out of the box, Cisco IP Phones are capable of 802.1X but are not enabled for it. in context
- Unified CM can centrally enable phones for 802.1X through the configuration file the phone downloads. in context
Cite this source record
APA
WarmTransfer. (2014, July 2). IP Telephony for 802.1X Design Guide. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-dig-ip-telephony-8021x
BibTeX
@misc{warmtransfer-cisco-dig-ip-telephony-8021x,
title = {IP Telephony for 802.1X Design Guide},
author = {{WarmTransfer}},
year = {2014},
url = {https://warmtransfer.net/knowledge/sources/cisco-dig-ip-telephony-8021x},
note = {Cisco Systems, accessed 2026-10-02}
}