EasyManuals Logo

Cisco 8861 Deployment Guide

Cisco 8861
207 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #28 background imageLoading...
Page #28 background image
Cisco IP Phone 8861 and 8865 Wireless LAN Deployment Guide
28
Encrypted configuration files
Settings Access (can limit user access to configuration menus)
Extensible Authentication Protocol - Flexible Authentication via Secure Tunneling (EAP-FAST)
Extensible Authentication Protocol - Flexible Authentication via Secure Tunneling (EAP-FAST) encrypts EAP transactions
within a Transport Level Security (TLS) tunnel between the access point and the Remote Authentication Dial-in User Service
(RADIUS) server such as the Cisco Access Control Server (ACS) or Cisco Identity Services Engine (ISE).
The TLS tunnel uses Protected Access Credentials (PACs) for authentication between the client (the Cisco IP Phone 8861 and
8865) and the RADIUS server. The server sends an Authority ID (AID) to the client, which in turn selects the appropriate PAC.
The client returns a PAC-Opaque to the RADIUS server. The server decrypts the PAC with its master-key. Both endpoints now
have the PAC key and a TLS tunnel is created. EAP-FAST supports automatic PAC provisioning, but it must enable don the
RADIUS server.
To enable EAP-FAST, a certificate must be installed on to the RADIUS server.
The Cisco IP Phone 8861 and 8865 currently support automatic provisioning of the PAC only, so enable Allow anonymous in-
band PAC provisioning on the RADIUS server as shown below.
Both EAP-GTC and EAP-MSCHAPv2 must be enabled when Allow anonymous in-band PAC provisioning is enabled.
EAP-FAST requires that a user account be created on the authentication server.
If anonymous PAC provisioning is not allowed in the production wireless LAN environment then a staging RADIUS server can
be setup for initial PAC provisioning of the Cisco IP Phone 8861 and 8865.
This requires that the staging RADIUS server be setup as a slave EAP-FAST server and components are replicated from the
product master EAP-FAST server, which include user and group database and EAP-FAST master key and policy info.

Table of Contents

Other manuals for Cisco 8861

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 8861 and is the answer not in the manual?

Cisco 8861 Specifications

General IconGeneral
Resolution800 x 480 pixels
AudioWideband audio
Ethernet Ports2 x 10/100/1000
SpeakerphoneFull-duplex
Display5-inch color display
Lines5
PoEYes (802.3af)
ProtocolsSIP, SDP, SRTP
Wi-Fi802.11a/b/g/n/ac
Headset JackYes
CodecsG.711, G.722, G.729, iLBC
USB Port2 x USB 2.0
USB Ports2 x USB 2.0
Supported LanguagesMultiple (English, French, Spanish, etc.)

Related product manuals