IEEE 802.1X overview
- Last UpdatedAug 28, 2023
- 1 minute read
The IEEE 802.1X standard provides specifications for secure layer 2 network access. Phones implement 802.1X supplicant in unicast and multicast. For the PC port, the phone supports pass-through modes with and without proxy logoff.
The phone supports the MD5, TLS, TTLS and PEAP authentication methods.
When the authentication method is TLS, set the parameter DOT1XEAPTLSONLYWITHCERT to 1 for the phone to automatically enable the 802.1X supplicant only when the phone has an installed trusted certificate and an identity certificate for use with 802.1X.
You can use the 46xxsettings.txt file, phone web interface, or Avaya Aura® Device Services (AADS) to configure the parameter DOT1XEAPTLSONLYWITHCERT.
When 802.1X is enabled, the phone ignores any incoming LLDP packets until the 802.1X authentication is completed or there is a time-out. The LLDP packets are processed after one of the following:
-
802.1X authentication completes successfully.
-
802.1X authentication fails.
-
The phone does not receive a response from the switch on any 802.1X request for 90 seconds.
If the switch is in the force-auth mode, there is an additional delay of 90 seconds during the phone boot-up.
If you configure any of the usage parameters, such as PKCS12_USAGE and SCEP_USAGE, that affect which identity certificate the phone uses for 802.1X, restart the phone again to use the correct identity certificate. An additional reboot for the phone is required when the usage parameter affects the identity certificate used.