I am configuring an 871 router and have 802.1x enabled. The clients can authenticate properly thru the VPN tunnel. We also will have a printer and IP Phone behind the remote 871 router. They cannot run 802.1x so I have a virtual template with "device authorize mac-address" configured for these devices. The problem is this is not like port security or mac auth bypass. I cannot configure the mac addresses under the interface. How can I lock down these ports so they cannot be used by another device? I have searched and cannot find how to configure this. The phones will work but what prevents someone from unplugging the phone and plugging in a non-authorized PC?