Design Guide

Cisco Wireless IP Phone 8821 and 8821-EX Wireless LAN Deployment Guide
76
On the Wireless > Configure > Access control page, select WPA2-Enterprise to enable 802.1x authentication.
The Cisco Meraki authentication server or an external RADIUS server can be utilized when selecting WPA2-Enterprise.
The Cisco Meraki authentication server supports PEAP authentication and requires a valid email address.
Other authentication types (e.g. Pre-Shared Key) are available as well.
Ensure 802.11r is enabled.
Ensure Splash page is set to None to enable direct access.
Note: Cisco Meraki access points support 802.11r (FT) for fast secure roaming, but do not support Cisco Centralized Key
Management (CCKM).
If WPA2-Enterprise is enabled where the Cisco Meraki authentication server will be utilized as the RADIUS server, then a
user account must be created on the Network-wide > Configure > Users page, which the Cisco Wireless IP Phone 8821 and
8821-EX will be configured to use for 802.1x authentication.
Note: Cisco Meraki access points do not support EAP-FAST.