Polycom CX5500 Unified Conference Station Administrator’s Guide 1.1.0
Polycom, Inc. 190
The CX5500 system supports the following EAP authentication methods:
● EAP-TLS (requires Device and CA certificates)
● EAP-PEAPv0/MSCHAPv2 (requires CA certificates)
● EAP-PEAPv0/GTC (requires CA certificates)
● EAP-TTLS/MSCHAPv2 (requires CA certificates)
● EAP-TTLS/GTC (requires CA certificates)
● EAP-FAST (optional Protected Access Credential (PAC) file, if not using in-band provisioning)
● EAP-MD5
To set up an EAP method that requires a Device or CA certificate, you need to configure TLS Platform
Profile 1 or TLS Platform Profile 2 to use with 802.1X. You can use the parameters in the table Set
802.1X Authentication Parameters to configure 802.1X Authentication. For more information see TLS
Profiles.
Web Info: EAP Authentication Protocol
For more information, see RFC 3748: Extensible Authentication Protocol.
Set 802.1X Authentication Parameters
Central Provisioning Server
Enable or disable the 802.1X feature
device.cfg > device.net.dot1x.enabled
Specify the identity (username) for authentication
device.cfg > device.net.dot1x.identity
Specify the 802.1X EAP method
device.cfg > device.net.dot1x.method
Specify the password for authentication
device.cfg > device.net.dot1x.password
To enable EAP In-Band Provisioning for EAP-FAST
device.cfg > device.net.dot1x.eapFastInBandProv
Specify a PAC file for EAP-FAST (optional)
device.cfg > device.pacfile.data
Specify the optional password for the EAP-FAST PAC file
device.cfg > device.pacfile.password
Web Configuration Utility
To enable and configure the 802.1X feature, navigate to Settings > Network > Ethernet and expand the Ethernet
802.1X menu.
Local Phone User Interface
To enable 802.1X authentication, navigate to the Ethernet Menu (Settings > Advanced > Admin Settings >
Network Configuration > Ethernet Menu) and select 802.1X Auth.
To configure the 802.1X feature, navigate to the Ethernet Menu and select 802.1X Menu (802.1X Auth must be
set to enable first).