Cisco ip phone and wired user authenticate form ISE

Hi dears,
I configurate wired users from Cisco ISE. The authentication protocol is Eap-fast, the external device is DC. The wired user authenticate from ISE normally. I use labminutes web sites for configuration video.
Now the customer also want the cisco phone is authenticate from ISE. the physical connection is that: the cable connect to phone from switch. and one cable is connec from phone to pc.(standard physiacl connection.)
I create new authentication policy and use mab, and  new authorization police.
The problem is : the phone is authenticate is normally but the wired user want to authenticate but it can not authenticate.
Can someone provide me a best practice configuration on ise and switch for phone and wired user authentication. or please say the source of problem.
Thanks.

interface GigabitEthernet1/0/48
 switchport access vlan 10
 switchport mode access
 switchport voice vlan 14
 ip access-group ACL-ALLOW in
 authentication event fail action next-method
 authentication event server dead action authorize vlan 20
 authentication event server alive action reinitialize
 authentication host-mode multi-auth
 authentication open
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 authentication violation restrict
 mab
 dot1x pae authenticator
 dot1x timeout tx-period 10
 spanning-tree portfast
do you need ISE configuration??

Similar Messages

  • Recording for Cisco IP Phones and Cisco C90 Codec

    Hello
    We are looking for a solution that is capable to record both Cisco IP Phones and Cisco Codec C90.
    We are using CUCM 9.X for IP Phones and VCS 7.X for Cisco Codecs.
    Is their any third party solution available for both the requirements or do i have to go with TCS and any other third party recording solution.
    Thanks & Regards
    Aniket Patil

    My reply may be too late to be of any help to you, but for the benefit of others:
    Be sure you understand the different types of PoE out there. The Linksys PoE switch only supports the newer IEEE 802.3af PoE standard.
    The 7940, 7960, 7905 and other older Cisco phones only support Cisco pre-standard PoE and thus will not work with the 802.3af Linksys Switch.
    To use this switch, you will need to make sure you are using the newer 7070, 7961, 7941 phones with support both pre-standard and 802.3af PoE.
    All the best,
    John

  • Cisco WLC 2504 and ways to authenticate users

    Hi All,
         What is the ways to make user authenticate to WLC 2504 and what is the best and simple way and what is the differences btw each method _i mean for example need radius server or something else to be exist_ ?
         and any one can give me case study for this issue
    System consist of Cisco 2504 and Cisco LAP 1140
    Thanks

    To implement radius based authentication is the best practice for the small & enterprise environment.
    Information About RADIUS
    Remote Authentication Dial-In User Service (RADIUS) is a client/server protocol that provides centralized security for users attempting to gain management access to a network. It serves as a backend database similar to local and TACACS+ and provides authentication and accounting services:
    •Authentication—The process of verifying users when they attempt to log into the controller.
    Users must enter a valid username and password in order for the controller to authenticate users to the RADIUS server. If multiple databases are configured, you can specify the sequence in which the backend database must be tired.
    •Accounting—The process of recording user actions and changes.
    Whenever a user successfully executes an action, the RADIUS accounting server logs the changed attributes, the user ID of the person who made the change, the remote host where the user is logged in, the date and time when the command was executed, the authorization level of the user, and a description of the action performed and the values provided. If the RADIUS accounting server becomes unreachable, users are able to continue their sessions uninterrupted.
    RADIUS uses User Datagram Protocol (UDP) for its transport. It maintains a database and listens on UDP port 1812 for incoming authentication requests and UDP port 1813 for incoming accounting requests. The controller, which requires access control, acts as the client and requests AAA services from the server. The traffic between the controller and the server is encrypted by an algorithm defined in the protocol and a shared secret key configured on both devices.
    You can configure multiple RADIUS accounting and authentication servers.For example, you may want to have one central RADIUS authentication server but several RADIUS accounting servers in different regions. If you configure multiple servers of the same type and the first one fails or becomes unreachable, the controller automatically tries the second one, then the third one if necessary, and so on. 
    For more Information : http://www.cisco.com/en/US/docs/wireless/controller/7.2/configuration/guide/cg_security_sol.html#wp2149947

  • 6921 Phone and Multiple Users

    We are a school system deploying a new Unified Communications Manager with Unity Voicemail.  We will be placing 6921 phones in our classrooms.  Some of these clasrooms are shared by two teachers and the plan is to give each teacher a unique extension number and voicemail mailbox.  In the shared rooms, this amounts to using both lines on the 6921 and having two mailboxes.
    The system is not in and live yet, but we are trying to work through some of the issues we know we'll encounter.  One problem that we are trying to solve is how to indicate the presence of new voicemail messages for each user in the room.  We are hearing from our vendor that they do not know of a way to indicate message waiting for both lines on a 6921.  Unfortunately they have no experience with the 6921 phones, so they are basing this on guesswork.  They cannot verify this as their lab is running UCM 6.x.  We are installing 7.1, but have rights to upgrade to 8.0 if necessary.
    We are hoping that the phone can indicate distinct message waiting for each line in some fashion.  The documentation seems to indicate that this might be possible.  We are even OK if the message waiting indicator lights for a message in either mailbox and the users would need to pick up their line and check for a stutter dial tone, but we do not know if this will work either.  What we want to avoid is a situation where only one (or neither)  extension activates the message waiting indicator and one (or both) users would need to periodically check their voicemail mailbox, or pick up the phone to check for stutter dial tone.
    Has anyone deployed 6921s in this fashion and know if there is a way to have distinct message waiting indicators for both lines on a 6921?  If so, how does it work?  Is it a distinct light, or a distinct message on the display?
    Any help would be appreciated.
    Thank you,
    Mark

    Hi Mark -
    Here's something that might help you - http://www.cisco.com/en/US/docs/voice_ip_comm/cuipph/6921_6941_6961/8_0/english/user/guide/book/6921enu801.pdf
    It is the Unified IP Phone Guide which discusses the 6921 phone.  It discusses phone features that can be configured in CUCM for the phones - the two I think you are interested in: (1) Visual Message Waiting and (2) Audible Message Waiting.  The AMWI is the stutter dial tone you referenced, heard when the user presses the line button to go off-hook.  Although I don't have personal experience with the 69XX phone series yet, I do have experience with dual-line phones like the 794X.  For your shared phone with two lines, both configured for a voicemail profile, here is something that will probably apply to the 6921:  The Messages button on the phone is the voicemail speed-dial (Easy message access) for the primary line on the phone.  For voicemail users on the second line, for the same functionality, users will press the second line to go off-hook and then press the Messages button.  Unity voicemail will recognize the calling number as a subscriber and prompt for password/PIN.  Also, check out the System Policy in CUCM for the directory number configuration, which allows the Visual MWI to be set for secondary lines (Light and prompt), otherwise the typical default is just to light and prompt for the primary line.
    Sincerely,
    Ginger

  • Query re dect phone and wired phone on same line

    Quite long winded but wonder if someone could help please.
    I had a dect phone plugged into the master socket. Due to working from home and need for better functionality than the dect phones could give me I bought a Converse 2300 wired phone and plugged it into the master socket.
    I then moved to dect base unit to an extension socket in another room.
    The dect phone when plugged into the master socket always showed caller ID.
    The Converse which is now plugged into the master socket also shows caller ID.
    However, I'm having a couple of problems with the dect phone I've relocated to the extension socket.
    Firstly, I get a dial tone on the dect phone but when I try to dial a number I hear the key tones but it then just goes back to the dial tone rather than actually dialling the number.
    Secondly, caller ID is not displayed on an incoming call on the relocated dect phone - instead the screen just says 'External'. Called ID is however displayed on the wired Converse phone.
    I suspect there's a setting somewhere on one of the phones but I can't for the life of me work it out. Or do dect and wired phones not work together on the same line?
    Any advice would be much appreciated!
    Thanks in advance.

    Hi, it sounds like there could be a wiring fault with the extension socket, there would not he any settingsbon a phone that would solve the problem. Is there broadband on the line? If so try changing the ADSL filter.
    (If I have helped you in any way to say "Thank You" please click on the star next to the message. Thank You)
    If I have solved your Issue please click the "Mark as accepted solution" button.

  • Hi, I have sold a phone and the user cannot get past ever Apple ID and password but the password isn't working.?

    Hi,
    I have sold an iPhone 4S, I thought it was fully erased but it wasn't, it had find my iPhone on and the user is being prompted to enter apple ID and password. I went onto Apple account and removed device from find my iPhone and erased. Still says the same thing to the buyer. I have changed my password for Apple ID and then called them and they have entered the password but it doesn't work. Tried the old one that doesn't work either. \
    Any ideas.
    Very grateful to hear from anyone.

    There is never a reason to give someone your Apple ID password.  Period.
    If you've removed the device from the Find My iPhone section of www.icloud.com, then it's not activation locked.  They need to restore the device as new and set it up with their own information.
    Immediately change your Apple ID password and also update your security questions.  You may also want to change the primary email address of your Apple ID.
    iCloud: Activation Lock - Apple Support
    Apple ID: Changing your password - Apple Support
    Change your Apple ID - Apple Support

  • Cisco 6921 Phones and CUCM 6.1

    We have bought some new 6921 Phones and want to know if I can use them on my CUCM 6.1.2.1000-13
    Are there instuctions?
    The phone does not appear in the Device Default list.
    Thank You
    Matt

    Hello,
    Already replied in another thread. Anyway, CallManager and CallManager Express (e.g. IOS gateways) support CDRs.
    Hope it helps, please rate if it does.
    Kind regards,
    - Adrian.

  • Ip phone and pc VLAN security issue - ISE 1.0

    Hello there.
    We are about to implement IP phones to our current network and during testing I have found 2 issues.
    1- ip phone connects to a protected port using ISE mab authentication for the data network.
    The voice VLAN is set up static on the port. The pc VLAN is given by ISE profiling.
    Then the issue is that once the pc connects to the VLAN it belongs to from the ip phone it leaves open that vlan on that port which means that if I connect another pc it will get the original VLAN the port had open up the connection with. This is a big security issue as computers that should not be allowed on specific VLAN can access them this way.
    2- once the connection is up and running on the port for both the phone and the pc, there is re-authentication Happening every minute to ISE. The Authentication logs are getting so many messages for just one port. So once we convert from 2 ip phones to 500, that is definitely going to generate a lot of unnecessary traffic.
    Let me know your thoughts...thanks
    Port config info....below
    interface GigabitEthernet0/2
    description Extra port by Camilos Desk
    switchport mode access
    switchport voice vlan 220
    srr-queue bandwidth share 1 30 35 5
    priority-queue out
    authentication event fail action next-method
    authentication event server alive action reinitialize
    authentication host-mode multi-auth
    authentication open
    authentication order mab dot1x
    authentication port-control auto
    authentication periodic
    authentication timer reauthenticate server
    mab
    mls qos trust cos
    snmp trap mac-notification change added
    auto qos trust
    spanning-tree portfast
    end

    On # 1
    You have the make sure that
    "authentication host-mode multi-domain" command is under each port
    This will allow one voice vlan and only one PC vlan at any given time. If you disconnect a PC and connect onother PC mac address to it, the phone will reinitialize to accept or reject the new mac based on its profile.
    On #2
    I have not found a solution. But what I have found after deployment is that it has happend only on 2 VOIP phones, out of 70 that we have as of now. So it might to be related to ISE.
    On the other hand we are not using Cisco phones but mitel. So this might be a whole issueon itself.
    Hope this helps.

  • Cisco ip phones and cme help

    Hi,
    Ina company which uses cisco call manager express with ip phones 7931, 7945 ,7975, 7911,7962…….
    1- i want the configuration in which the user dial a pin code befor doing an outside call...?
    2- i want to change the defalt configuration for the ip phones of days backlight not active to thursday and friday and the backlight in duration to 1:30.?
    i did the followings commands but it doesn`t take an effect.
    Router(config)# telephony-service
    Router(config-telephony)# service phone daysBacklightNotActive 6
    Router(config-telephony)# service phone backlightOnDuration 1:30
    Router(config-telephony)# service phone backlightIdleTimeout 01:00
    Router(config-telephony)# create cnf-files
    Router(config-telephony)# reset all
    3- i have ringtones files in the flash (sh flash attached) , i want all the ringtones appear on all the ip phones when i press settings then user prefrences and then rings- i can only see two ring tones.
    thanks for your help

    My reply may be too late to be of any help to you, but for the benefit of others:
    Be sure you understand the different types of PoE out there. The Linksys PoE switch only supports the newer IEEE 802.3af PoE standard.
    The 7940, 7960, 7905 and other older Cisco phones only support Cisco pre-standard PoE and thus will not work with the 802.3af Linksys Switch.
    To use this switch, you will need to make sure you are using the newer 7070, 7961, 7941 phones with support both pre-standard and 802.3af PoE.
    All the best,
    John

  • Transfer VOIP Calls Between Cisco Desk Phone and Cisco Jabber For IPhone 9.5

    Does anyone know how to transfer an active voip call from a Cisco IP Desk Phone to Cisco Jabber for IPhone?  I can transfer a call from Cisco Jabber for IPhone to my Cisco IP Desk Phone no problem.  I put the call on hold and then click "Resume" on my Cisco IP Desk Phone.  However I cannot do the same but the other way around.  If I put the call on hold on my Cisco IP Desk Phone, I see "no active call" on my Jabber client.  The only information I could find slighlty relevant was using the Mobility Key/Remote Destination Profile feature however this defeats the object as this will forward to an external number, e.g. mobile and I just want to transfer the call within the VOIP environment between the two devices that are using the same directory number.
    I am using Cisco Call Manager 9.1(2), Cisco Presence 9.1 and Cisco Jabber for IPhone 9.5.
    Any help would be greatly appreciated.
    Kind Regards,
    Paul Parker.

    Did you ever find an answer to this ?
    I am seeing the same behavior and trying so see if I can put calls on hold and pick them up both ways also.
    The only answer I seem to have found is to use park instead
    That would/should work but I would just prefer to hold/unhold
    Just not sure why we would not be able to hold/unhold on what is essentially a "shared" line
    Does anyone have this working for them ?

  • How to configure SGE2000P with CISCO 7900 phones and data VLAN

    Hello all
    I am having problem setting up SGE2000P switches to work with my default data VLAN and additional voice VLAN. I am configuring it to pick IP address for phones from voice VLAN which is working fine but when I connect a PC on phone port it is also picking up an IP from Voice VLAN while default VLAN is data with different scope of IP.
    Is there any good discussion or documents out there to help me resolve this issue before I pack these switches and purchase ESW 500 series. I have ESW 500 at another client and they are working fine out of the box but this guy is giving me hard time.
    Any suggestions help will be appreciated
    Mo

    HI Muhammed,
    I suggest you contact the Small Business Support Center for some help:
    http://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html
    Regards,
    Cindy Toy
    Cisco Small Business Community Manager
    for Cisco Small Business Products
    www.cisco.com/go/smallbizsupport
    twitter: CiscoSBsupport

  • Cisco CP7821 phone and CME10.0

    We have a brand new CME system and we have 2 CP7821 phone for common area's but i cant seem to find anything on how to get them to work. in fact when under telephony-service i run the "load ?" and that model is not even listed as a option. how then to i get those phones working?

    You may be able to add them as a generic SIP endpoint.  I don't have one of these phones in front of me but it should work as along as you can configure a SIP username/password on them.

  • Cisco spa phone and '*' in the number

    Hello.
    I am set the phone dial plan (x.), but if i am enter the number ex:'45*' then phone show message "invalid number".
    How am i call to the number with "*" in middle?

    Try this Dial-Plan:
    (xx*|x.)
    Regards.

  • Cisco IP Phone 802.1x authentication with NPS

    Hi All,
    I would like to configure 802.1x authentication on both my Cisco ip phones and windows clients using NPS. So far i have tested the clients and it works however I am not finding any information on if NPS supports 802.1x on ip phones. Has anyone done a similar
    deployment using NPS. So far I am only seeing cisco ACS server being used as the policy server.

    Hi,
    Based on my research, it seems that you may enounter issues related to username(Basically Mircosoft only allows a 20 character user name, while the user name of the phone exceeds the 20 character limit and causes it to fail.) and certificate schema when
    configuring 802.1x authentication for Cisco IP phones.
    Best regards,
    Susie
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Opening a Crystal Report in B1 8.8 in a User Defined Form representing UDO

    Hi Experts,
    Is it possible to open a Crystal Report from a User Defined Form representing my UDO?
    I had developed a 'Vendor Quotation' UDO and its  User Defined Form
    I wanted to show the report while clicking the Preview menu in SAP B1 8.8 toolbar.
    I have created the Crystal report and used the record selection as {@OVQT.DocEntry} = {DocKey@}
    Please help
    Also, is it possible to add Print layout and assign a default Print layout to this User Defined Form?
    Thanks in advance
    Regards
    Arun

    Hi,
    I also face the same problem. I make a master type using UDO. But i want to print it.
    In my opinion ( i haven't tried this way ). If we make a UDO ( master or document type ) , we will find the docentry and object field in our UDT. Both of these will connect between SAP form and Crystal report. In crystal report we select the tmsp_doclinetypelayout. It is a store procedure which will connect between SAP form and CR. Before that try to modify this SP by adding the udo object.
    Fyi, if i'm not mistake dockey is connected to docentry SAP form.
    Thanks
    regards
    bodhi86

Maybe you are looking for

  • How can I obtain an specific message raised by a database trigger

    Dear friends, if I have a database trigger and I want to show an error message which was raised from a database trigger to a form, I can do it by raising an application error inside database trigger, and by showing DBMS_ERROR_TEXT inside ON-ERROR tri

  • Issues with capturing clips.

    when i capture clips witht he hidef 1080i60 apple codec it cuts each clip at the scene. instead of one 62 minute clip. how can i change this.

  • Reg : SAP Query  in LDB

    Hello , I would like to know more about how infosets are used in LDB's. I was recently testing a LDB of Hedge Mgmt. i selected seveal param's  and found that the order of fields in the query really makes a  diff. LDB's are very senstive to ordering ?

  • Output doesnt show??

    //import java.text.*; //import java.util.Locale; public class Firm      private Employee[] empObj;      //private double raisedPay;      //Firm constructor      public Firm(Employee[] empObj)           //this.empObj = new Employee[empObj.length];    

  • What Tree Data Structures does Java Include?

    Hello, I have been reading about several tree data structures like a binary search tree, self-balancing bst, minimum spanning tree, red-black tree, AVL tree, etc... Are there data structures in Java represent the various trees, or is implementation o