802.1x, IP Phones, MAB and AD password policy

I am currently working on an 802.1x pilot. I have successfully deployed certificates for PCs and users and I'm able to assign VLAN etc in a reliable fashion.
I would like to enable MAC Authentication Bypass on the voice VLAN for IP phones. The problem is, when I create a user with the phones MAC address as a user name, or AD Domain policy does not allow the password to also be the mac address. Disabling this policy temporarily for adding these users is not a credible solution for us. I'd rather not use third party software that allows for diversity in AD password policy.
I've seen it implied that the switch (3560 in my case) can be configured to send the Radius secret rather than the device MAC address as the device's password, is this true? If so, how?
Thanks!

With MAC-Auth-Bypass, the end station (phone in your case) doesn't interact with the auth method at all. The switch authenticates the MAC after being learned by the switch on behalf of the end-station.
This is a limitation in Windows Server today. This can be controlled through a GPO in Server 2008. Another option(s) is to store the "phone user accounts" directly on the AAA server or another database that allows the ability for this.
Also, to authenticate a phone at all, and to support PCs, you need to configure Multi-Domain-Authentication (MDA) on the 3560. See here:
<http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a00808abf2d.shtml#MDA>
Hope this helps,

Similar Messages

  • How do I view a video that was sent to me through imessage to my iphone 5S?It was sent by another iphone user.I clicked the link and entered my phone number and the password provided but it still won't open.What should I do?

    How do I view a video that was sent to me through imessage to my iphone 5S?It was sent by another iphone user.I clicked the link and entered my phone number and the password provided but it still won't open.What should I do?

    Is this your issue >  http://support.apple.com/kb/HT5818
    If so...
    The Apple ID and Password that was Originally used to Activate the iDevice is required
    If you do not have that information you will not be able to use the Device.

  • HT204053 SOMEONE STOLD MY INFORMATION OFF MY PHONE, SPYING AND GOT PASSWORD! WHAT CAN BE DONE? THE OTHER USER IS ON MY SAME APPLE ACCOUNT

    SOMEONE STOLD MY INFORMATION OFF MY PHONE, SPYING AND GOT PASSWORD! WHAT CAN BE DONE? THE OTHER USER IS ON THE SAME APPLE ACCOUNT AND TOOK SCREEN SHOTS OF TEXT, PHOTOS MOST LIKELY SAVED IT TO AN APP. ON THE PHONE & OR EMAILED IT TO SELF.

    You need to get control of your Apple ID. Change the password.
    Manage your Apple ID -
    https://appleid.apple.com/cgi-bin/WebObjects/MyAppleId.woa/
    If you can't change the password because this person ahs changed the password to something that you don't know then contact the Account Security Team to get control of your account.
    Apple ID security issues -
    Call Apple Care for your country and ask for the Account Security Team. They can assist you with your issue.
    http://support.apple.com/kb/HT5699
    The very last thing that you want is to have Apple close down the Apple ID, especially if you have bough t a lot of content through this account in the past.

  • Recovery of deleted data from Phone memory and Unlock Password Protected Data

    I have lost password of my blackberry (Curver 8520) protected data and by mistake I have also deleted some contacts, sms and memos from phone memory of blackberry set. Can any one help me to get recover my password and deleted data or is their any recovery tool which can be useful for it?

    Hi Kaushalbca
    Welcome to BlackBerry Support Community Forums
    By " BlackBerry Protected Data " do you mean BlackBerry ID password which we use for BlackBerry Protect ? If so , you can reset your password by following this KB Article : 
    KB26361  :How to change or reset a BlackBerry ID password.
    After reset , you can use BlackBerry protect to restore your deleted data ( If you have a backup of those deleted data ) , You can also restore your data if you ever did a backup using Desktop Software . To restore data refer to those KB Articles :
    KB25063  : How to use BlackBerry Protect to restore data to a BlackBerry smartphone
    KB10339 : How to use BlackBerry Desktop Software to restore data to a BlackBerry smartphone from a backup file
    Click " Like " if you want to Thank someone.
    If Problem Resolves mark the post(s) as " Solution ", so that other can make use of it.

  • TA38605 When my phone rings and  is password locked I am unable to decline a call.  As soon as I unlock my phone it answers the call whether I want to or not. How do I fix this? Because I do not want to answer a blocked number.

    Iphone4s - because I use pass lock I cannot decline a call such as a blocked number.  If I can't see who is calling then I don't want to answer it.  But due to having my phone on lock - i can see its a blocked number but there is no option to decline.  If i unlock my phone it automatically answers the call.  Does anyone else have this problem or is there a solution I don't knnow about?

    In the locked screen you can press the sleep/wake button once to silence to the call and twice to send it to voicemail.

  • API to generate password using Siteminder API and the password policy

    Is there any API in siteminder to generate a password using the Password policies defined ?

    Hello Jim,
    The way you are going about your coding sounds correct.  Per your second question, MAX installs when you update the computer drivers.  To do this go to ni.com/drivers, search for DAQmx, and then download the most current version of DAQmx that is compatible with your computers.  By installing a newer version of DAQmx MAX will automatically be updated.  
    Regards,  
    Marcus
    Marcus M.
    PXI Product Support Engineer
    National Instruments

  • How do I enable default failure audit and password policy checking?

    Hi,
    I am trying to install DPM 2012 R2, and on the requirements for SQL is : Use the following SQL Server settings:
    default failure audit, and enable password policy checking
    I have tried looking for them, but I can't find them.
    How do I apply these settings?
    Thanks .

    Hi,
    I am trying to install DPM 2012 R2, and on the requirements for SQL is : Use the following SQL Server settings:
    default failure audit, and enable password policy checking
    I have tried looking for them, but I can't find them.
    How do I apply these settings?
    Thanks .
    Simple way to enable login default failure audit is Right Click On SQL server instance in SQL Server management studio and select Properties then below page will occur. There are 2 options in Login auditing select appropriate one
    for enabling policy please refer below links
    Enforce windows password policy on SQL Server logins
    Password Policy FAQ
    Please mark this reply as answer if it solved your issue or vote as helpful if it helped so that other forum members can benefit from it.
    My TechNet Wiki Articles

  • Questions on Password Policy

    Hi All,
    I have couple of questions on password policy behavior upon OAM-EBS integration.
    Currently "Applications SSO Auto Link User" options is set to "Disable" in my env.
    Please confirm if following is the right understanding.
    1.     Upon OAM-EBS integration, user whose EBS account is linked with OID cannot change their password from EBS console. EBS password policy (Password expiry etc) will be overridden by OID policy.
    2.     EBS user`s whose account is not linked with OID can change the password and EBS password policy will be applicable for that user.
    3.     To have the user use EBS password policy he must be unlinked by setting up USER_GUID attribute to null in FND_USER table.
    Thanks in advance.
    -Sam

    Sam,
    Your understanding is correct -- Please see these docs.
    Integrating Oracle E-Business Suite Release 11i with Oracle Internet Directory and Oracle Single Sign-On [ID 261914.1]
    USE: EBS Technology Stack OID and SSO [ID 1461466.2]
    How To Temporarily Stop User Synchronization From OID To FND User [ID 1120413.1]
    Troubleshooting Oracle Access Manager and Oracle E-Business Suite AccessGate [ID 1077460.1]
    Integrating Oracle E-Business Suite with Oracle Access Manager 10g using Oracle E-Business Suite AccessGate [ID 975182.1]
    Thanks,
    Hussein

  • OAM : Which identity server is used by Password Policy?

    Hi,
    The OAM setup has two identity servers (ois1, ois2), two webpass (wp1, wp2) on two web servers. wp1 is pointing to ois1 only and wp2 is pointing to ois2.
    We have two sets of Policy manager, Access server and WebGate. wg1 is pointing to aaa1 and wg2 is pointing to aaa2.
    Now, when a user tries to access a OAM webgate protected page and the password policy gets applied, do the identity server comes into picture? if yes, which identity server is used here, ois1 or ois2?
    I want to use ois1 for all the requests coming to webserver with wg1. How do I do it?
    Thanks in advance.

    Hi Colin,
    Thanks for your reply.
    The reason I put this question was - in a scenario when I dont have Access Server (any access component), then also Password Polices work. So, I understand identity server is used here. When we have access side components, what makes OAM not to use identity server at all. Or is it the feature of OAM - when the accessed resource is ptotected by WebGate the Password policies are taken care of by Access Server, otherwise by identity server or is it because of the 'obReadPasswdMode' and 'obWritePasswdMode' in the authentication scheme?
    I stopped my identity server and I saw the password policy working - so I know the behavior; still asking the above question for my better understanding of OAM.
    Thanks for your help!

  • MAB and 802.1x issues with IP-phone

    I'm trying to use 802.1x to authenticate clients on my network with dynamic VLAN assignment from RADIUS. We have IP-Phones(powered by PoE) that only supports EAP-MD5, and we would rather use MAB(it also uses LLDP-MED for some settings) to authenticate the phones using the MAC-range from the phones vendor. The following scenario works perfect:
    Connect the phone and let it boot up(takes a while) and authenticate with MAB.
    Connect a computer in the phones data-port and let it authenticate with 802.1x(or fail and reach guest-vlan)
    However, the following scenario doesn't work:
    The computer is already connected to the phone
    The phone is then connected to the switch
    What happends now is that the computer is authenticated using 802.1x before the phone boots up and get's authenticated with MAB. When the phone is ready, it's authenticated with MAB and everything works. However, after a short period(let's say a minute), using `debug authentication all`, we see a "NEW LL MAC: phones mac" message(which is weird since the mac has already been MAB-authenticated), and then we are unable to contact the phone using ping. When I check `show mac address-table` it has now moved the mac from `Port Gi 0/12` to `Port Drop`. However, if I check `show mab interface Gi 0/12` or `show authentication sessions` it lists the phones-mac as `mab auth sucess `.
    Can anyone explain why the first scenario works, and not the second?
    The switch is a 3560E PoE 24p with IOS 12.2.58SE2. Sample of the switch-config:
    network-policy profile 1
    voice vlan 90
    interface GigabitEthernet0/12
    switchport mode access
    network-policy 1
    authentication control-direction in
    authentication event fail retry 1 action authorize vlan 60
    authentication event server dead action authorize vlan 60
    authentication event no-response action authorize vlan 60
    authentication event server alive action reinitialize
    authentication host-mode multi-domain
    authentication order mab dot1x
    authentication priority mab dot1x
    authentication port-control auto
    authentication periodic
    authentication violation replace
    mab
    dot1x pae authenticator
    dot1x timeout tx-period 5
    dot1x max-reauth-req 1
    spanning-tree portfast
    Btw, when we tried authenticating the phones using 802.1x too (EAP-MD5), there are NO problems in any of the scenarios. However, we want to use MAB instead of 802.1x to avoid the requirement of configuring the phones with a username and password. The RADIUS response was the same when using 802.1x as it is with MAB for the phones (including device-traffic-class=voice AV-pair).

    Hey. Yes, as specified in the last sentence in my post, the phone is placed in the Voice Domain, and both RADIUS and LLDP-MED (network policy profile 1) specifies voice vlan as 90.
    The weird thing is that everything works fine if both use 802.1x, and that there is only a problem when phone(using MAB) already has the computer connected to it, when the phone is turned on(connected to PoE-switch). It must be because the computer boots up and authenticates first I think.
    The phones are Snom 821.

  • What is the difference between the passcode on my iPhone 5 and a password?  I am locked out of my phone.

    What is the difference between the passcode on my iPhone 5 and a password?  I am locked out of my phone.

    Not entirely sure what you are asking, but a passcode to unlock an iOS device is normally 4 digits long (so is a 4 digit code), though you can make it alphanumeric and longer (so effectively becomes a password).
    If you don't know the passcode to unlock your phone or it's showing the disabled screen then there are instructions on this page for how to reset a device : http://support.apple.com/kb/HT1212 - you should then be able to restore/resync your content to it.

  • Got new email address. Changed the address on itunes on my computer but can not change Apple id on my phone. keeps asking for password to old Apple ID. How do I get my new apple ID on my phone so I can purchas and update phone?

    Got a new email address, changed my account on itunes to new email address. which changed my apple id and password. Works fine on computer but My phone is still asking me to sign in with old apple id. I can not figure out how to change apple id on my phone. I have sync'd my phone twice and still hasnt changed account info on phone. Any Ideas on what I need to do?

    Start with the Settings app
    Settings > iTunes and App Store > tap on your Apple ID and then tap on Sign Out
    Then sign in with your correct Apple ID and password.

  • HT204053 I did not know my kids had set up an Itunes account for me with one user name and password.  then i got an i phone and set it up with a different email address and new password.  how can i get my accounts to merge so i can have all of my music on

    I did not know my kids had set up an Itunes account for me with one user name and password.  then i got an i phone and set it up with a different email address and new password.  how can i get my accounts to merge so i can have all of my music on my iphone

    Quote: "You cannot merge two or more Apple IDs into a single one. You can, however, use one Apple ID for iCloud services and another Apple ID for store purchases (including iTunes in the Cloud and iTunes Match). See “Using one Apple ID for iCloud and a different Apple ID for Store Purchases” above for details." See also Apple ID & iCloud FAQ: http://support.apple.com/kb/HT4895?viewlocale=en_US&locale=en_US
    You can set up your iCloud account on your iOS device under: "Settings > iCloud" and a other account for store purchases under "Settings > iTunes & App Stores". Unfortunately merging accounts is not possible but you could transfer all of your music manually via iTunes from your Mac or PC.

  • I lost my recovery key changed phone numbers and dont remember password why canty i go to security questions

         I lost my recovery key to my applied I changed my phone number and forgot change number to account.  I do not remember password, I was needing to know I cant change phone number somehow or be ask security question to reset password.
                                                                                                          I would so greatly appreciate help

    Apple ID support may be able to help: Apple ID: Contacting Apple for help with Apple ID account security

  • HT1414 My iPhone has crashed during a sync and now I can't restore from backup as it is asking for password to load the backup yet neither the lock code for the phone or my iTunes Password are working... I have no other password to all upon and need the r

    My iPhone has crashed during a sync and now I can't restore from backup as it is asking for password to load the backup yet neither the lock code for the phone or my iTunes Password are working... I have no other password to call upon and need the restore to retrieve info onto my phone, I am a real novice to this...... please help, !!!!

    If anyone else is looking for a solution to this same problem, I was able to get it working looking through several older discussions.
    The solution was to use the password that I had on my iTunes account the very first time I set up the iPhone about a year ago.  I changed my iTunes password about 10 months ago;  but apparently, the backups continue to use the password that existed when the phone was first set up.
    A couple of troubling things with this are that 1) I didn't apply a password when I did the backup this afternoon so I don't understand why it was required when I did the restore a few hours later. and 2) it makes zero sense why iTunes would not be smart enough to use the current accout password when requiring the password to restore from a backup made with no password. 
    I thought iTunes and Apple were smarter than that.  With so many posts stating exactly the same problem, it is clear that this is bug in the software. 
    Best,
    Craig

Maybe you are looking for

  • Error Message sending a job to compressor and Blu-Ray

    I am having trouble with a job in FCP 7 and sending it to compressor.  it runs and about 20 minutes until completion I get a failed message.  "Failed: Quicktime Error: 0"  on my m2v file.  What could be causing this issue? I also get a quicktime erro

  • PHP/MySQL - Nav links pass variable to another page? Or?

    I'm a PHP/MySQL beginner. I'm digging through books and tutorials as best I can, but finding myself a little lost in the sheer volume of information. If someone can point me in the right direction for this task, I'd really appreciate it. I have a dat

  • HTML Editor is not showing

    I installed the Studio Ent.8 and create a new project but when I need to open the html design window, I could not found where is the opetion. in View->Editor menu there is only one option i.e. source. Please let me know, whats wrong with me.

  • Error message :"Error occurred in the data selection"

    Hi All , When I am exracting a Delta from source I am getting this error mesage Error occurred in the data selection" can any one let me know how to slove  this, Thanks in Advance. rao

  • Cant find my pics from photostream in my icloud

    The memory on my iphone 4 is running low, so i want to get the photos from my photostream out. I thought they automatically loaded into my icloud account but when i go there i do not see a folder for pictures. Anynone know what i am doing wrong?