We had some Cisco 7920 IP Phones connected to Aironet1130ag. They worked fine with WEP. Now we changed the network to WPA with Microsoft IAS as Radius Server. The clients authenticate over a certificate, the Phone should authenticate with user and password. Testet with this username and password a non-domain-computer (without certificate) and my phone could connect over the aironet1130ag Accesspoint, so it should not be a problem of the Radiusserver. It also works with WPA-PSK, but to handle two different authentication, I had to use two vlans, which I couldn't handle without a router or layer 3 switch, if I understood that correct.
I've set cipher to tkip in the encryption manager and set both open authentication with eap (for the Clients) and Network EAP (I've read, that I have to set Network EAP for the 7920 Phones), but the phones still can't connect: authentication failed.
Thanks for any help