EasyManuals Logo

Cisco 7925G Administration Guide

Cisco 7925G
274 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #60 background imageLoading...
Page #60 background image
Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST)
Authentication
This client server security architecture encrypts EAP transactions within a Transport Level Security
(TLS) tunnel between the AP and the RADIUS server such as the Cisco Access Control Server (ACS).
The TLS tunnel uses Protected Access Credentials (PAC) for authentication between the client (phone)
and the RADIUS server. The server sends an Authority ID (AID) to the client (phone), which in turn
selects the appropriate PAC. The client (phone) returns a PAC-Opaque to the RADIUS server. The
server decrypts the PAC with its master-key. The server and client now have the PAC key and a TLS
tunnel is created. EAP-FAST supports automatic PAC provisioning, but you must enable it on the
RADIUS server.
In the Cisco ACS, by default, the PAC expires in one week. If the phone has
an expired PAC, authentication with the RADIUS server takes longer while
the phone gets a new PAC. To avoid the PAC provisioning delays, set the PAC
expiration period to 90 days or longer on the ACS or RADIUS server.
Note
Extended Authentication Protocol Transport Level Security (EAP-TLS) Authentication
EAP-TLS/RFC 2716 uses the TLS protocol (RFC 2246), which is the latest IETF version of the SSL
security protocol. TLS provides a way to use certificates for both user and server authentication, and
for dynamic session key generation.
Microsoft Windows XP provides support for 802.1x, allowing EAP authentication protocols (including
EAP-TLS) to be used for authentication. The authentication used in EAP-TLS is mutual: the server
authenticates the user and the user authenticates the server. Mutual authentication is required in a
WLAN. EAP-TLS provides excellent security but requires client certificate management.
EAP-TLS uses Public Key Infrastructure (PKI) with the following conditions:
A Wireless LAN client (user machine) requires a valid certificate to authenticate to the WLAN
network.
An authentication server (typically a RADIUS server) requires a server certificate to validate its
identity to the clients.
A Certificate Authority (CA) server infrastructure issues certificates to the authentication server
and the clients.
Protected Extensible Authentication Protocol (PEAP) Authentication
PEAP uses server-side public key certificates to authenticate clients by creating an encrypted SSL/TLS
tunnel between the client and the authentication server. This functionality is disabled by default and
you enable it using Cisco Unified Communications Manager Administration.
The Cisco Unified Wireless IP Phone can optionally validate the server certificate during the
authentication over an 802.11 wireless link.
Lightweight Extensible Authentication Protocol (LEAP)
Cisco proprietary password-based mutual authentication scheme between the client (phone) and a
RADIUS server. Cisco Unified Wireless IP Phones can use LEAP for authentication with the wireless
network.
Cisco Unified Wireless IP Phone 7925G, 7925G-EX, and 7926G Administration Guide
40
VoIP Wireless Network
Authentication Methods

Table of Contents

Other manuals for Cisco 7925G

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 7925G and is the answer not in the manual?

Cisco 7925G Specifications

General IconGeneral
Keypad number of keys12
Display diagonal2 \
Display resolution176 x 220 pixels
Call waitingYes
Lines quantity6 lines
Voice codecsG.711a, G.722, G.729a, iLBC
Security algorithms128-bit WEP, SSL/TLS, WPA
Supported network protocolsDHCP, TFTP, DNS, SCCP, SRST
Input voltage100 - 240 V
Dimensions (WxDxH)52 x 20 x 127 mm
Minimum system requirementsCisco Unified Communications Manager 4.1, 4.2, 4.3, 5.1, 6.0, 6.1, 7.0 + Cisco Unified Communications Manager Express 4.3 +
Input frequency50/60 Hz
Storage temperature (T-T)-30 - 60 °C
Operating temperature (T-T)0 - 40 °C
Operating relative humidity (H-H)10 - 95 %
Product typeIP Phone
Product colorGray
SafetyUL 60950, CSA 22.2 No.60950, EN 60950, IEC 60950, AS/NZS 60950, IEC 60529 (IP 54)
Certification47 CFR 15 B ICES-003 B EN 55022 B AS/NZS CISPR 22 B CISPR 22 B VCCI B EN 61000-3-2 EN 61000-3-3 KN 22 EN 55024 EN 50082-1 EN 61000-6-1 EN 300386 EN 60601-1-2 KN
Compliance industry standardsIEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.1X, IEEE 802.11e
Weight and Dimensions IconWeight and Dimensions
Weight138 g

Related product manuals