Cisco CP-7961G Administration Guide - Page 193

Problem, Possible Cause, 1X Enabled on Phone but Not Authenticating, 1X Not Enabled

Page 193 highlights

Chapter 9 Troubleshooting and Maintenance Troubleshooting Cisco Unified IP Phone Security Table 9-1 Cisco Unified IP Phone Security Troubleshooting (continued) Problem Possible Cause Phone does not register with Cisco Unified The CTL file does not contain the correct information for the Cisco Communications Manager. Unified Communications Manager server. Phone does not request signed configuration The CTL file does not contain any TFTP entries with certificates. files. 802.1X Enabled on Phone but Not Authenticating Phone cannot obtain a DHCP-assigned IP These errors typically indicate that 802.1X is enabled on the phone, but the address phone is unable to authenticate. Phone does not register with Cisco Unified 1. Verify that you have properly configured the required components Communications Manager Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-18. Phone status display as "Configuring IP" or 2. Confirm that the shared secret is configured on the phone (see Security "Registering" Configuration Menu, page 4-30 for more information). 802.1X Authentication Status displays as "Held" (see 802.1X Authentication and Status, page 4-43). Status menu displays 802.1x status as "Failed" (see Call Statistics Screen, page 7-13). - If the shared secret is configured, verify that you have the same shared secret entered on the authentication server. - If the shared secret is not configured, enter it, and ensure that it matches the one on the authentication server. 802.1X Not Enabled Phone cannot obtain a DHCP-assigned IP address Phone does not register with Cisco Unified Communications Manager These errors typically indicate that 802.1X is not enabled on the phone. To enable it, see Security Configuration Menu, page 4-30 for information on enabling 802.1X on the phone. Phone status display as "Configuring IP" or "Registering" 802.1X Authentication Status displays as "Disabled" (see 802.1X Authentication and Status, page 4-43). Status menu displays DHCP status as timing out (see Call Statistics Screen, page 7-13). Factory Reset Deleted 802.1X Shared Secret Phone cannot obtain a DHCP-assigned IP address Phone does not register with Cisco Unified Communications Manager Phone status display as "Configuring IP" or "Registering" Cannot access phone menus to verify 802.1X status These errors typically indicate that the phone has completed a factory reset while 802.1X was enabled. A factory reset deletes the shared secret, which is required for 802.1X authentication and network access. To resolve this, you have two options: • Temporarily disable 802.1X on the switch. • Temporarily move the phone to a network environment that is not using 802.1X authentication. Once the phone starts up normally in one of these conditions, you can access the 802.1X configuration menus and re-enter the shared secret. OL-21011-01 Cisco Unified IP Phone Administration Guide for Cisco Unified Communications Manager 8.0 (SCCP and SIP) 9-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241

9-9
Cisco Unified IP Phone Administration Guide for Cisco Unified Communications Manager 8.0 (SCCP and SIP)
OL-21011-01
Chapter 9
Troubleshooting and Maintenance
Troubleshooting Cisco Unified IP Phone Security
Phone does not register with Cisco Unified
Communications Manager.
The CTL file does not contain the correct information for the Cisco
Unified Communications Manager server.
Phone does not request signed configuration
files.
The CTL file does not contain any TFTP entries with certificates.
802.1X Enabled on Phone but Not Authenticating
Phone cannot obtain a DHCP-assigned IP
address
These errors typically indicate that 802.1X is enabled on the phone, but the
phone is unable to authenticate.
1.
Verify that you have properly configured the required components
Supporting 802.1X Authentication on Cisco Unified IP Phones, page 1-18
.
2.
Confirm that the shared secret is configured on the phone (see
Security
Configuration Menu, page 4-30
for more information).
If the shared secret is configured, verify that you have the same shared
secret entered on the authentication server.
If the shared secret is not configured, enter it, and ensure that it
matches the one on the authentication server.
Phone does not register with Cisco Unified
Communications Manager
Phone status display as “Configuring IP” or
“Registering”
802.1X Authentication Status displays as
“Held” (see
802.1X Authentication and
Status, page 4-43
).
Status menu displays 802.1x status as
“Failed” (see
Call Statistics Screen,
page 7-13
).
802.1X Not Enabled
Phone cannot obtain a DHCP-assigned IP
address
These errors typically indicate that 802.1X is not enabled on the phone. To
enable it, see
Security Configuration Menu, page 4-30
for information on
enabling 802.1X on the phone.
Phone does not register with Cisco Unified
Communications Manager
Phone status display as “Configuring IP” or
“Registering”
802.1X Authentication Status displays as
“Disabled” (see
802.1X Authentication and
Status, page 4-43
).
Status menu displays DHCP status as timing
out (see
Call Statistics Screen, page 7-13
).
Factory Reset Deleted 802.1X Shared Secret
Phone cannot obtain a DHCP-assigned IP
address
These errors typically indicate that the phone has completed a factory reset
while 802.1X was enabled. A factory reset deletes the shared secret, which is
required for 802.1X authentication and network access. To resolve this, you
have two options:
Temporarily disable 802.1X on the switch.
Temporarily move the phone to a network environment that is not using
802.1X authentication.
Once the phone starts up normally in one of these conditions, you can access
the 802.1X configuration menus and re-enter the shared secret.
Phone does not register with Cisco Unified
Communications Manager
Phone status display as “Configuring IP” or
“Registering”
Cannot access phone menus to verify
802.1X status
Table 9-1
Cisco Unified IP Phone Security Troubleshooting (continued)
Problem
Possible Cause