
Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide
18
The TLS tunnel uses Protected Access Credentials (PACs) for authentication between the client (phone) and the RADIUS
server. The server sends an Authority ID (AID) to the client (Cisco Unified IP Phone 9971), which in turn selects the
appropriate PAC. The client (phone) returns a PAC-Opaque to the RADIUS server. The server decrypts the PAC with its
master-key. Both endpoints now have the PAC key and a TLS tunnel is created. EAP-FAST supports automatic PAC
provisioning, but it must enabled on the RADIUS server.
To enable EAP-FAST, a certificate must be installed on to the RADIUS server.
The Cisco Unified IP Phone 9971 currently supports automatic provisioning of the PAC only, so enable
Allow anonymous in-
band PAC provisioning
on the RADIUS server as shown below.
Both EAP-GTC and EAP-MSCHAPv2 must be enabled when
Allow anonymous in-band PAC provisioning
is enabled.
EAP-FAST requires that a user account be created on the authentication server.
If anonymous PAC provisioning is not allowed in the production wireless LAN environment then a staging Cisco ACS can be
setup for initial PAC provisioning of the Cisco Unified IP Phone 9971.
This requires that the staging ACS server be setup as a slave EAP-FAST server and components are replicated from the product
master EAP-FAST server, which include user and group database and EAP-FAST master key and policy info.
Ensure the production master EAP-FAST ACS server is setup to send the EAP-FAST master keys and policies to the staging
slave EAP-FAST ACS server, which will then allow the Cisco Unified IP Phone 9971 to use the provisioned PAC in the
production environment where
Allow anonymous in-band PAC provisioning
is disabled.
When it is time to renew the PAC, then authenticated in-band PAC provisioning will be used, so ensure that
Allow
authenticated in-band PAC provisioning
is enabled.
Ensure that the Cisco Unified IP Phone 9971 has connected to the network during the grace period to ensure it can use its
existing PAC created either using the active or retired master key in order to get issued a new PAC.
Is recommended to only have the staging wireless LAN pointed to the staging ACS server and to disable the staging access
point radios when not being used.
Summary of Contents for UNIFIED 9971
Page 38: ...Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide 38 ...
Page 45: ...Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide 45 ...
Page 79: ...Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide 79 ...
Page 80: ...Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide 80 ...
Page 81: ...Cisco Unified IP Phone 9971 Wireless LAN Deployment Guide 81 ...