9-13
Cisco Unified IP Phone 7961G/7961G-GE and 7941G/7941G-GE for Cisco Unified Communications Manager 6.0
OL-11953-01
Chapter 9 Troubleshooting and Maintenance
Troubleshooting Cisco Unified IP Phone Security
Phone cannot authenticate any of the
configuration files other than the
CTL file.
Bad TFTP record.
Phone reports TFTP authorization
failure.
• The TFTP address for the phone does not exist in the CTL
file.
• If you created a new CTL file with a new TFTP record, the
existing CTL file on the phone may not contain a record for
the new TFTP server.
Phone does not register with Cisco
Unified Communications Manager.
The CTL file does not contain the correct information for the
Cisco Unified Communications Manager server.
Phone does not request signed
configuration files.
The CTL file does not contain any TFTP entries with
certificates.
802.1X Enabled on Phone but Not Authenticating
Phone cannot obtain a
DHCP-assigned IP address
These errors typically indicate that 802.1X is enabled on the
phone, but the phone is unable to authenticate.
1. Verify that you have properly configured the required
components “Supporting 802.1X Authentication on Cisco
Unified IP Phones” section on page 1-23.
2. Confirm that the shared secret is configured on the phone
(see the “Security Configuration Menu” section on
page 4-37 for more information).
–
If the shared secret is configured, verify that you have
the same shared secret entered on the authentication
server.
–
If the shared secret is not configured, enter it and ensure
that it matches the one on the authentication server.
Phone does not register with
Cisco Unified Communications
Manager
Phone status display as
“Configuring IP” or “Registering”
802.1X Authentication Status
displays as “Held” (see the “802.1X
Authentication and Status” section
on page 4-48).
Status menu displays 802.1x status
as “Failed” (see the “Call Statistics
Screen” section on page 7-17).
802.1X Not Enabled
Table 9-1 Cisco Unified IP Phone Security Troubleshooting (continued)
Problem Possible Cause