
400HD Series IP Phones
Administrator's Manual
158
Document #: LTRT-11973
7.4 Configuring 802.1x
802.1X is an IEEE Standard for Port-based Network Access Control (PNAC). It's part of the
IEEE 802.1 group of networking protocols. It provides an authentication mechanism for
devices wishing to connect to a LAN or WLAN.
The employee's PC negotiates 802.1X. Messages are sent transparent to the enterprise
switch. The phone is uninvolved in the negotiation; however, if an employee's PC is
disconnected, their phone notifies the switch. If an employee's PC is disconnected from the
phone, a PROXY-EAP-LOGOFF mechanism lets the phone immediately log off the port from
the authentication server to prevent anyone else from connecting to it.
The phone performs like this:
Phone and PC connected to phone's PC port successfully perform 802.1X
authentication. The authentication server records the phone and PC as authorized.
If the PC is disconnected from the phone's PC port, the phone sends an EAPoL-
Logoff message for the PC. The authentication server then records the PC as
unauthorized.
If the PC reconnects to the phone's PC port, the authentication server requests the PC
to perform 802.1X authentication again.
Note:
Before you can connect to a 802.1x server, you need to make sure the same
certificate and Trusted Root CA are loaded to the phone
and
to the 802.1x.
Summary of Contents for 405HD
Page 2: ......