Phone Network
47
l EAP-PEAP/MSCHAPv2 (requires CA certificates)
l EAP-TTLS/EAP-MSCHAPv2 (requires CA certificates)
l EAP-PEAP/GTC (requires CA certificates)
l EAP-TTLS/EAP-GTC (requires CA certificates)
l EAP-FAST (supports EAP In-Band provisioning, requires CA certificates if the provisioning method is Authenticated
Provisioning)
For more information on 802.1x authentication, refer to Yealink 802.1X Authentication.
Topic
802.1x Authentication Configuration
802.1x Authentication Configuration
The following table lists the parameters you can use to configure 802.1x authentication.
Parameter
static.network.802_1x.mode
[1]
<y0000000000xx>.cfg
Description It configures the 802.1x authentication method.
Permitted
Values
0-EAP-None, no authentication
1-EAP-MD5
2-EAP-TLS
3-EAP-MSCHAPv2
4-EAP-TTLS/EAP-MSCHAPv2
5-EAP-PEAP/GTC
6-EAP-TTLS/EAP-GTC
7-EAP-FAST
Default 0
Web UI Network->Advanced->802.1x->802.1x Mode
Phone UI Settings->Advanced Settings (default password: admin) ->Network->802.1x->802.1x Mode
Parameter
static.network.802_1x.eap_fast_provision_mode
[1]
<y0000000000xx>.cfg
Description
It configures the EAP In-Band provisioning method for EAP-FAST.
Note: It works only if “static.network.802_1x.mode” is set to 7 (EAP-FAST).
Permitted
Values
0-Unauthenticated Provisioning, EAP In-Band provisioning is enabled by server unauthenticated PAC
(Protected Access Credential) provisioning using the anonymous Diffie-Hellman key exchange.
1-Authenticated Provisioning, EAP In-Band provisioning is enabled by server authenticated PAC pro-
visioning using certificate based server authentication.
Default 0
Web UI Network->Advanced->802.1x->Provisioning Mode
Parameter
static.network.802_1x.anonymous_identity
[1]
<y0000000000xx>.cfg
Description
It configures the anonymous identity (user name) for 802.1X authentication.
It is used for constructing a secure tunnel for 802.1X authentication.