Cisco CP-7975G Administration Guide - Page 211

Problem, Possible Cause, 1X Enabled on Phone but Not Authenticating, 1X Not Enabled

Page 211 highlights

Chapter 9 Troubleshooting and Maintenance Troubleshooting Cisco Unified IP Phone Security Table 9-1 Cisco Unified IP Phone Security Troubleshooting (continued) Problem Possible Cause Phone cannot authenticate CTL file. The security token that signed the updated CTL file does not exist in the CTL file on the phone. Phone cannot authenticate any of the configuration The configuration file may not be signed by the files other than ITL file. corresponding certificate in the phone's Trust List. Phone does not register with Cisco Unified Communications Manager. The CTL file does not contain the correct information for the Cisco Unified Communications Manager server. Phone does not request signed configuration files. The CTL file does not contain any TFTP entries with certificates. 802.1X Enabled on Phone but Not Authenticating Phone cannot obtain a DHCP-assigned IP address. These errors typically indicate that 802.1X Phone does not register with Cisco Unified Communications Manager. authentication is enabled on the phone, but the phone is unable to authenticate. Phone status display as "Configuring IP" or "Registering". 802.1X Authentication Status displays as "Held" (see 802.1X Authentication and Status, page 4-42 for more details). Status menu displays 802.1X status as "Failed" (see Status Menu, page 7-3 for more details). 1. Verify that you have properly configured the required components (see Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-19 for more information). 2. Confirm that the shared secret is configured on the phone (see 802.1X Authentication and Status, page 4-42 for more information). - If the shared secret is configured, verify that you have the same shared secret entered on the authentication server. - If the shared secret is not configured, enter it, and ensure that it matches the one on the authentication server. 802.1X Not Enabled Phone cannot obtain a DHCP-assigned IP address These errors typically indicate that 802.1X Phone does not register with Cisco Unified Communications Manager Phone status display as "Configuring IP" or authentication is not enabled on the phone. To enable it, see 802.1X Authentication and Status, page 4-42. "Registering" 802.1X Authentication Status displays as "Disabled" Status menu displays DHCP status as timing out OL-23092-01 Cisco Unified IP Phone Administration Guide for Cisco Unified Communications Manager 8.5 9-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266

9-9
Cisco Unified IP Phone Administration Guide for Cisco Unified Communications Manager 8.5
OL-23092-01
Chapter 9
Troubleshooting and Maintenance
Troubleshooting Cisco Unified IP Phone Security
Phone cannot authenticate CTL file.
The security token that signed the updated CTL
file does not exist in the CTL file on the phone.
Phone cannot authenticate any of the configuration
files other than ITL file.
The configuration file may not be signed by the
corresponding certificate in the phone’s Trust List.
Phone does not register with
Cisco Unified Communications Manager.
The CTL file does not contain the correct
information for the
Cisco Unified Communications Manager server.
Phone does not request signed configuration files.
The CTL file does not contain any TFTP entries
with certificates.
802.1X Enabled on Phone but Not Authenticating
Phone cannot obtain a DHCP-assigned IP address.
These errors typically indicate that 802.1X
authentication is enabled on the phone, but the
phone is unable to authenticate.
1.
Verify that you have properly configured the
required components (see
Supporting 802.1X
Authentication on Cisco Unified IP Phones,
page 1-19
for more information).
2.
Confirm that the shared secret is configured
on the phone (see
802.1X Authentication and
Status, page 4-42
for more information).
If the shared secret is configured, verify
that you have the same shared secret
entered on the authentication server.
If the shared secret is not configured,
enter it, and ensure that it matches the one
on the authentication server.
Phone does not register with
Cisco Unified Communications Manager.
Phone status display as “Configuring IP” or
“Registering”.
802.1X Authentication Status displays as “Held”
(see
802.1X Authentication and Status, page 4-42
for more details).
Status menu displays 802.1X status as “Failed”
(see
Status Menu, page 7-3
for more details).
802.1X Not Enabled
Phone cannot obtain a DHCP-assigned IP address
These errors typically indicate that 802.1X
authentication is not enabled on the phone. To
enable it, see
802.1X Authentication and Status,
page 4-42.
Phone does not register with
Cisco Unified Communications Manager
Phone status display as “Configuring IP” or
“Registering”
802.1X Authentication Status displays as
“Disabled”
Status menu displays DHCP status as timing out
Table 9-1
Cisco Unified IP Phone Security Troubleshooting (continued)
Problem
Possible Cause