VLAN voice N3048P and DHCP issues

Hello

I just received several switches for our N3048P and 2 x 4048 access layer - WE for our base layer. Are the N3048P VLT'd between two of 4048. There are 4 x N3048P of one on the other. The 4048 possess all gateways via VRRP.

I have 802. 1 x works with my Windows client test, and I can get the phone (Cisco 7941) to acquire a DHCP address if I put it on a port "switchport mode access. However, if I change the port to a general port with vlan enabled voice and 802. 1 x, the phone does not have a DHCP address, but the PC attached to the phone Gets a DHCP address in the VLAN correct.

I see CDP and LLDP messages exchanged via Wireshark, and it seems that the phone and the switch are to exchange the VLAN voice correctly.

My question is, why the phone can't one address DHCP?

Here's the relevant config of switch below. I know that some of the config can be duplicated for troubleshooting steps:

VLAN 75
the name 'Test '.
output
VLAN 76
name "Test_Phones".
output

IP helper-address 1.1.1.3 dhcp
IP helper-address 1.1.1.4 dhcp

interface vlan 75
IP 172.16.75.4 255.255.255.0
IP helper 1.1.1.3
IP helper 1.1.1.4
output
interface vlan 76
IP 172.16.76.4 255.255.255.0
IP helper 1.1.1.3
IP helper 1.1.1.4

AAA authentication local connection to "defaultList".
radius of start-stop AAA accounting dot1x default
control-dot1x system-auth
radius AAA dot1x default authentication service
AAA authorization network default RADIUS

VLAN, VoIP

source-ip 172.16.75.4 RADIUS server
Server RADIUS 'key' key
RADIUS-server host 1.1.1.1 auth
primary
name "rad1.
use of 802. 1 x
key 'key '.
output
RADIUS-server host 1.1.1.2 auth
name "rad2.
use of 802. 1 x
key 'key '.
output
Server RADIUS acct 1.1.1.1 host
name "rad1.
output
host server RADIUS acct 1.1.1.2
name "rad2.
output

Gi2/0/1 interface

Description '802. 1 x client port.
spanning tree portfast
spanning tree guard root
switchport mode general
switchport general allowed vlan add 75-76 the tag
dot1x re-authentication
dot1x quiet-period 5
dot1x tx-period 5
dot1x comments - vlan 20
dot1x Informati-vlan 20
LLDP transmit tlv ESCR-sys sys - cap
LLDP transmit-mgmt
notification of LLDP
LLDP-med confignotification
VLAN voice 76
disable voice vlan auth
output

Thanks for any input you may have. I would like to know if there is any other information, I can provide.

-Jason

That ends up being the correct port configuration:

Gi2/0/1 interface

Description '802. 1 x client port.

spanning tree portfast

switchport mode general

switchport General pvid 75

VLAN allowed switchport General add 75

switchport general allowed vlan add 76 tag

dot1x port-control on mac

dot1x re-authentication

dot1x quiet-period 5

dot1x timeout supp-timeout 15

dot1x tx-period 5

dot1x comments-vlan-deadline 15

dot1x comments - vlan 20

dot1x Informati-vlan 20

VLAN voice 76

disable voice vlan auth

The most important line here is «the dot1x port-control on mac» I got 'auto control by port dot1x' configured, but it does not work as expected. In addition, defining the comments-vlan-period and supp-timeout were necessary. If the port was shot, the switch would not necessarily reauth port.

Tags: Dell Switches

Similar Questions

  • Configure the VLAN voice and data in CISCO SF 300 8 P

    I have a couple of Cisco SF 300 8 P and P 24 switches. I have voice and data VLANS configured as:

    Data VLAN: default 145.17.59.0/24

    Voice VLANS: VLAN 20 172.22.20.0/24

    I have different DHCP servers regarding the data VLAN, we have a physical server that is configured for 145.17.59 * extended IP and Voice VLAN DHCP Server is configured as a router gateway with option 150.

    This configuration works very well with other cisco 2960 switches and 3750 etc. except CISCO SF 300 8 P and 24 p. I tried to set up the voice and data VLAN in these CISCO switches so that phone CISCO (model 6941) should get IP of the VLAN voice and PC should get the IP address of the DHCP server on the data VLAN. I tried several techniques such as LLDP, Port-to-VLAN Config etc.

    Can anyone please guide me / help on this.

    Kind regards
    A K.M.Sayeed

    Hi A.K.M., with Cisco phones you should be able to define simply automatic voice VLAN to be VLAN20.

    ID of the vlan 20 voices

    You must ensure CDP or LLDP is enabled as well. I would check in the web GUI. DHCP for phones can come from a DHCP server on a port access VLAN20 switch, or you can use dhcp for assistance to redirect DHCP server elsewhere.

    If you prefer or you have problems with the CDP or LLDP, you can also program the ports as trunks and add the tag VLAN 20 for them.  In this scenario, you need to ensure inter - vlan routing works and phones that download the file config with corrrect VLAN config.

    These switches do not run ios, so they are similar, but different from the catalyst switches that you mentioned.

    -remember messages useful rate.

  • Several VLANS and DHCP relay on two stacked switch SGE2000-G5

    We were put to the task of securing a small desktop system managed that is currently set up with a standard switch for each of the offices (with different companies) to see each other and in some cases, access to each of the other documents on the network.

    Obviously, this is far from adequate set up and our goal is to isolate each office using VIRTUAL networks, but share a common internet connection provided by managed offices.  We have two switches for layer 3 Cisco SGE2000-G5, but we are new on Cisco equipment and VLAN, so we are not quite sure on how to implement this.  DHCP must be provided by a router, there is no server.  We are open to suggestions on the router as we still buy a.

    I hope that someone may be useful.

    Thank you very much

    Jim

    Hi Jim,.

    SGE2000 switches you are using must be able to handle this without issue. What type of router you are using? As long as you have a router that will take in charge VLAN / several subnets, it should be a simple configuration.

    Here's a quick run down of the measures to be implemented. (using vlan1 and vlan2)

    On the router, create a vlan / subnet 2 and set the port to connect to your shared resources with the two VLAN 1 and 2 switch. (it will be untagged, two will be marked)

    On the switch, create vlan2 and do the same for the port connected to the router. (vlan1 marked and tagged vlan2)

    Now for each switch port that you want to assign the port access and vlan1 and vlan2. (this vlan will be without a label)

    If your router allows, disable routing inter - vlan. If this isn't the case, you must create rules to block traffic from one network to the other.

    All this happens under the assumption that your router can support VLAN and can also make DHCP for this VLAN.

    Hope this information helps

  • Cisco 1921 & SG500 VLAN and DHCP problem

    Dear all,

    Thank you in advance for taking the time to read this.

    A little history:

    I want to install a project for an athlete, which is unfortunately on a budget pretty tight with a potentially large quantity of network users (~ 200 without public WIFI). I need to separate the 5 groups of users and to give them all access to internet without see each other. 5 user groups also share the same bandwidth to the internet and VLANs must be controlled bandwidth.

    To do this, I had planned to use Cisco devices built-in functions and buy a 1921 Cisco router as a switch of SG500.

    I have configured the router for 8 subinterfaces is internal NIC with 8 VLAN. I also configured DHCP Pools 8 on the 1921 and set up NAT and firewall.

    What I want to do now is have the SG500 to recognize the VLAN ID, I configured on the router (as well as on the switch using the same VLAN ID numbers), and then assign ports to the VLAN on the switch, and depending on where I plug into the switch, the device receives different IP addresses from DHCP.

    However, I can't get this to work. The router works fine, the 'intact' if left switch gives me an IP address from the DHCP server on the IP address of higher network VLAN (I.e. 168.8.0). but I can not configure the switch ports correctly so that it works. I was also confused, is that dhcp pools that I have configured on the command-line command on the router do not appear in professional CP in the mask of the pool.

    Can someone kindly check the configuration of the router and throw some guidance on how I need to configure the Ports on the SG500? I must say that I have had too many nights and I seem to confuse tagging, untagging, to exclusion and prohibiting the ;.)

    I have the router for you here:

    Thanks again and good night!

    W.

    Hi Wolfgang, for the sx500 configuration can be something like this

    config t

    database of VLAN

    VLAN 2-8

    int item in gi1/1/1

    switchport mode general

    switchport trunk allowed vlan add 2-8 tag

    switchport General disable filtering of capture

    For any client that connects must be no tagged coelio

    So if you want a client access port then you should do something like 5 unidentified to this port

    config t

    int item in gi1/1/2

    switchport mode access

    switchport access vlan 5

    -Tom
    Please mark replied messages useful

  • VLAN protected port and voice

    When protected switchport is configured on a switchport (3750G switch), is what affects him vlan voice as well? I currently have protected ports configured, but we'll be adding IP phones soon and would prefer not to have to disable ports protected to allow phone phone voice traffic. I found on cisco.com where a port in a vlan voice can be a protected port, but it does not say if the traffic of phones on the switch is blocked or allowed, just that it can be configured on a protected Harbor.

    Thanks for any assistance on this.

    Thank you

    Mark

    Hello

    By default, all traffic on a 'protected switchport' interface will be sent for the uplinks. This includes all voice traffic and data from this particular interface.

    However, there is a work around available according to your configuration. There is a layer 2 isolation between ports, all traffic to these ports are sent to the uplinks and must be routed from one port to another, even though they may be in the same VLAN. A router is connected to running "proxy arp local' (or local-proxy-arp ip) can respond to ARP requests for IP addresses in a subnet where normally no routing is necessary."

    Depending on the connected device, you can have an able to use the local proxy arp feature to get around this VLAN voice. It should be an L3 device with the available command. 3750's take on support this command.

    Hope this helps

    -Joe

  • Wirless VLAN and DHCP

    I am trying to configure my Aironet 1121 G acess points with several VLANs, got the VLAN everything works great with wired devices, but wireless devices don't you DHCP.

    Basically I have the BVI on my virtual LAN management and two other vlans that cross, try to have the public WiFi on 1 vlan and the two VLAN corporate with separate wifi. Impossible to get IPs on any of them though.

    Vlnas are moved by a catlayst 3550 with addresses of assistance set up on all the VLAN interfaces.

    DHCP comes from 2 boxes of windows on another virtual local network Server 2003

    any ideas?

    Hello

    If I understand, you have plugged your access point to one of the L2 switch. I suggest you to set up your L3 (tandem switch) with pool dhcp to obtain the ip address for vlan respective first.

    To set the dhcp pool in your L3 192.168.2.1.

    create interface IVR and IP address assignment for the VLAN respective (which will act as a gateway of the vlan respective)

    Repeat the same for all the VLANS.

    Create the DHCP pool for the vlan respective and router by default with the ip address of L3.

    AccessPoint#configure terminal
    AccessPoint(config)#interface dot11radio 0
    AccessPoint(config-if)#ssid .......give the name of your ssid
    AccessPoint(config-if-ssid)#vlan ?
    AccessPoint(config-if-ssid)#authentication open
    AccessPoint(config-if-ssid)#end

    AccessPoint(config) interface fastethernet 0.30
    AccessPoint(config-subif) encapsulation dot1Q 30
    AccessPoint(config-subif) exit

    AccessPoint(config) interface dot11radio 0.30
    AccessPoint(config-subif) encapsulation dot1Q 30
    AccessPoint(config-subif) exit     

    Check if you have the ip address for the customers.

    In case await you get the IP address of your external dhcp server...

    try to give below command on each respective dot11Radio 0 subinterface "helper-... to give the dhcp server ip address here"

    Please let me know if it works...

    Thank you

    Vinod

  • Get some VLAN voice to work on 5548P

    Hello

    I was wondering if there is a way to accomplish the following. I want the passage to the tag the traffic on its own based on the YES Table and pass it up to the Sonicwall (DHCP server/router) without going through the phone itself do the marking. Is this possible? Currently, the installation so I put manually the VLAN ID on the phone itself, but these phones can work anywhere there is a sense of internet connection if I manually add the tag VLAN, the phone will not work outside of the corporate network.

    Thank you

    If your phone supports LLDP-MED, you can install the switch with a VLAN voice. This wiki covers the implementation of the VLAN voice.

    http://en.community.Dell.com/TechCenter/networking/w/wiki/configuring-Dell-PowerConnect-55xx-series-switch-voice-VLAN.aspx

    Do not have to configure phones that you configure LLDP-MED. The VLAN ID information are passed with LLDP-MED configured on the VoIP phone using the LLDP-MED mechanism. By this method, the voice from the VoIP phone data are tagged with the VLAN ID exchanged and the usual traffic would go to the PVID.

    Here is the link to the user guide. LLDP-MED configuration begins at page 540.

    FTP://FTP.Dell.com/ Manuals /Cccomplis /powerconnect-5524_User%27s%20Guide_en-us.pdf

    Once the phone is in the voice VLAN it can still receive an IP address by the DHCP server using the DHCP relay. The switch acts as a DHCP relay agent that listens for DHCP messages,

    and passes between DHCP servers and clients, residing in IP or VLAN different subnets.

    Relay DHCP and espionage begins on page 563 of the user guide.

    I hope this helps.

  • Requirement of DNS and DHCP Server Essentials 2012 home

    I have a Server Windows Essentials 2012 acting as DNS and DHCP server with a domain name for backups etc on my home network. It's that everything works fine, no errors, no problem. Works well actually, telling me when the children did not install updates or restarted.

    I have two groups of users. My sons step, 10 and 12, which I want to use OpenDNS as a provider external DNS with a policy very, very limited and my wife and me who want to use indications of root or Google DNS or any other DNS provider. Others, specific devices no user (box of the xBox, WII, Satellite, TV, CCTV etc.) can use.

    Before the 2012 server, I had a 2 k 3 server running in a virtual machine for DHCP, alone and put my wife and my devices on static reservations with the just and external DNS provider used OpenDNS as the default scope, DNS. Unfortunately different bits of domain services 2012 don't seem to work unless the server of 2012 is the first DNS server listed on client machines (backups failed. Impossible to find other local computers). Currently, this means that we are all using OpenDNS.

    What I would like is a way to say 2012 to send adult group DNS queries to another DNS provider and leave the rest at default to OpenDNS, while still having them register in the original DNS domain. Any suggestions?

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.msdn.Microsoft.com/forums/en-us/home

  • HP Procurve vlan voice with trunks

    Hi all

    I am a trained guy cisco, so I try to transfer my knowledge to the HP Procurve switches but it takes a little help to obtain VLAN etc set up.

    What I have is 4 switches, 3 at the access layer to the and 1 to the base and distribution.

    I want that switches to a trunk of the base and distribution layer 2 interfaces access layer allows to increase the speed of 2 instead of 1 gigabit uplink. Also, I want is that 2 VLANS is set up for separate voice and data. I want that all ports to be able to take in charge a PC or a VOIP phone. I put the phones to automatically tag the tag of vlan for the vlan voice, but I want all traffic to forward the link to resources shared at the base and distribution layer.

    From what I understand, so I need to:

    Configure a network interface on the access and use of basic/distribution layer switches: b1 - b2 trk1 lacp trunk

    Add VLAN for voice and data and assign vlan voice.

    The problem I have is the tag-no identified parameters.

    I tag vlan trk1 voice and set the priority of the qos to 6 and then comes to create the vlan data not marked on trk1?

    the config I've written so far is:

    b1 - b2 trk1 lacp trunk
    show trunks
    spanning tree
    spanning tree force version rstp operation
    voice VLAN 100 name
    voice
    Tagged trk1
    QoS priority 6
    data name VLAN 200
    not tagged trk1

    is this correct or am I missing something here?

    Thanks in advance!

    Hello:

    You can also copy and paste your message into the HP Business Support Forum - section Procurve switches.

    http://h30499.www3.HP.com/T5/ProCurve-provision-based/BD-p/switching-e-series-Forum

  • How VLANs ' IP subnet ing works with based port of VLAN (series N2000 and N3000)

    Hi all

    I have a small pile of x N3024 2 acting as my heart L3 with a lag of 2 x 10 g down to a stack of x N2048 5 acting as L2 switch for my PC workstations.

    Workstations are that all on the port assigned VLAN 10 (switchport access vlan 10). I have a bunch of developers who want to access without restrictions more or less to assign random IP addresses for their VM (Virtualbox and VMware) Workstation.  As you can imagine, I would like some control over this situation.  the powerconnect guide I described features of subnet IP VLAN but does not seem to enter in how it works and interacts with the port actually function vlan assignments.

    What I currently have is the VLAN 10 assigned to a segment that support the subnet 172.100.x.x which dates back to our base of L3 for routing to other segments. What I want to do is to configure the VLAN based on IP and then load the dev is to config their VM with another IP range, say 10.10.x.x.

    Theory here is, I set the L3 core with say 20 VLAN and an IP to register in L3 path between subnets and then configure the battery switch L2 workstation with IP - based VLAN to recognize 10.10.x.x and separate on VLAN 20.

    However, I think the simplified here question is if I have a nail up to 10 ports VLAN, will the than basic work IP subnet VLANS as I want only it? Or, I need to create a subnet IP VIRTUAL local area network for the two IP ranges? I have to remove the assignenment VLAN per port and are based entirely on the treatment of subnet IP VLAN?

    If there is a better RTFM on this topic you can tell me I would appreciate it

    Thank you!

    I ended up calling specialists... great Dell technical support here.

    In fact, the IP based VLAN works very close to what I want to achieve. Missing from the user guide is that the port needs to be in the mode. Ports using switch port mode and bound to a VLAN just didn't work... probably because the vlan IP based did not differ from the port binding. Dell support has suggested to use the trunk mode, but my answer is finished using the general mode; any traffic not referenced, PVID located my usual LAN vlan ID and acceptance of port traffic of new vlan based on IP. In this way, I'm able to have a physical host DHCP on the corporate LAN and a virtual machine on that host to bind to a different subnet which is then isolated in the new NAV based on IP.

  • Transferred file xp laptop visa vidio. Has received the record of voice only and not the vidio

    Transferred video files from xp to laptop of visa.  A received voice only and not the video file.  Now, I have that video file without sound on the xp and visa phone only plays the sound.  How can I fix it?

    Please repost your question in images and video Forum at: http://social.answers.microsoft.com/Forums/en-US/vistapictures/threads where people who specialize in graphics issues, including partial transfers (sound or video only) will be more than happy to help you with your problem.

    Good luck! Lorien - MCSA/MCSE/network + / A +.

  • L3 - SG300 - 28 p and DHCP

    Hi all

    I'm having a bit of difficulty up a SG300 - 28 p to L3 and DHCP. I will attach a basic network diagram and a very short list of my needs.

    I'm building a temporary network for a company event 1 day that I can't make it work in our office "Lab".

    L3 - SG300 - 28 p connects to our provider using a connection of the SFP.

    I have to be able to address IP DHCP 300 + using the SG300 - 28 p

    My problem is that I can ping my 2 machines test (manually configured IP) about 172.16.0.3 and 172.16.0.4, but cannot ping after the (internet) referral. Also DHCP distributes no intellectual property for the range 172.16.0.10 - 172.16.1.200

    VLAN 1 is set to 10.2.2.20 access port (to the provider through a connection on port 28 FPS)

    VLAN 100 is 172.16.0.2 access port (ports 1-26)

    I have the WLC and WAP tri...

    Is the set of even possible? I know that the EQ network is a bit budget for users, but for a one day business event I just do not have a budget for the purchase of switches better.

    Please excuse the gross chart.

    Thank you in advance.

    -RJ

    Thanks for the reply.

    With the information that you have provided, it seems the only part missing is the way return the unit for service providers. Unfortunately there is no way around that, and no, you will not be able to put anything between the two, because the device doing the NATting is unity of suppliers.

    I think that what is happening is that traffic is actually the side provider, but there is no way to do so as soon as the provider is not a route for the subnet in 172.16.x.x.

    Out of curiosity, why do you use a VLAN for the devices connected to the SG300? Could you use the 10 subnet Ip addresses? If you do this, you will not need to have a route back from the supplier, as all devices will be on the same subnet.

  • function of guard of source IP and dhcp DHCP scope of exhaustion (customer parodies other customers)

    Hello world.

    A dhcp server assigns ip address based on the mac address by equipment of the customer field in the dhcp packets.

    A potential attack is when a crowd of thugs mimics different mac addresses and causes the dhcp server to assign ip addresses until no ip address is left for legitimate host.

    For example, a host with mac1 h1 is designated by the ip address of the dhcp server as:

    199.199.199.1 mac1

    DHCP server has this entry in its database.

    Using hacking tools such as Yersinia or Gobbler can create a DHCP discover messages every time that create another mac for material scope of the client to the dhcp server, thereby causing a dhcp server to assign ip addresses because they are of legitimate dhcp to dhcp server discover messages with matching each another Mac in hardware of client addresses.

    You could use dhcp snooping and it will avoid that (exhaustion of dhcp scope) and configure the switch to check if the CBC mac fits the hardware address of the client in the dhcp message. But when even we can creat spoofed discover messages where mac src in the ethernet header will match the client hardware address in dhcp discovery message. It did not always overcome the problem.

    You might say use IP source guard characteristic but it really will prevent this problem from happening?

    Let me illustrate:

    H1 - f1/1SW - DHCP server

    Let's say that we have configured dhcp snooping on sw1 and f1/1 is untrusted port.  Switch a suite dhcp binding

    199.199.199.1 mac1 vlan1 f1/1

    Then, we configure source ip guard in order to validate the mac src and src ip against the dhcp bindings. When you configure keep source ip first, it will allow dhcp only if a host can request ip address and dhcp binding can be built. After that IP keep source will validate ip or mac src src or both against the binding.depending dhcp on how configure us source ip guard.

    In our case, we have configured source ip guard in order to validate the mac src and src ip against the dhcp binding.

    A dhcp connection is already created as:

    199.199.199.1 mac1 vlan 1 f1/1

    Now, using hacking tools Yersinia or Gobbler on h1, we create our first spoofed dhcp discovery message where mac src = mac2 ethernet header and client harware address = mac2 in dhcp discovery message. As the switch is configured with the function of guard of source ip and therefore allows dhcp discover message to pass through. DHCP server after you receive the message dhcp assigns another IP from the pool. The dhcp server has now after the entries:

    199.199.199.1 mac1

    199.199.199.2 mac2.

    We continue to spoofed dhcp to craft discover messages as described above and are dhcp server keep ip address assignment until exhausts the entire pool.

    So my question is how ip source guard in conjunction with dhcp snooping doesn't stop this attack does not happen? (IE DHCP scope exhaustion)

    I really appreciate your comments.

    Thank you and have a week.

    Hi Sara,.

    Ask was quite interesting. As far as I know that whatever it is port snooping untrusted won't let your fake dhcp server.

    You can take this query in the Sub forum of experts mentioned that is specific for dhcp snooping and source of guard.

    https://supportforums.Cisco.com/message/3689811#3689811

    Please assess whether the information provided is useful.

    By

    Knockaert

  • Subject of the vlan voice SRW224G4P

    Hello

    I have configured the SRW as vlan, use vlan for voice 212, 348 for data and communicate with cisco IP Phone.

    database of VLAN
    VLAN, 210-216 345-348
    output
    ID of the vlan voice 212

    !

    !
    interface fastethernet1
    activate the storm control
    Storm-control broadcast level 10
    Storm-control include multicast
    maximum port security by 10 points
    port security mode max-addresses
    port security throw trap 60
    spanning tree portfast
    switchport trunk allowed vlan add 212
    switchport trunk vlan native 348
    macro description ip_phone_desktop
    ! next order is internal.
    macro auto smartport dynamic_type ip_phone_desktop
    !

    but when I show vlan voice,.

    It shows:

    =====================================

    1ASW01 #show voice vlan
    Manage the VLAN voice State is automatically triggered
    Operational status of VoIP VLAN is enabled in auto
    Best Local Voice VLAN ID is 212
    Best Local VPT is 5 (default)
    Best Local DSCP is (by default) 46
    Concerted VLAN voice is received from the 34:62:88:73:05:c9 switch
    Concerted VLAN voice priority is 0 (static source active)
    Concerted Voice VLAN ID is 216
    Agreed VPT is 5
    Agreed DSCP is 46
    Voice VLAN agreed last change is 3 May 13 05:06:31

    =====================================

    I don't know why the vlan 216 became the vlan voice?

    I tried changed the build-in macro settings,

    auto macro of the built-in parameters ip_phone $native_vlan 348
    auto macro of the built-in parameters ip_phone_desktop $native_vlan 348

    but the system could not change the value of $voice_vlan.

    How to fix?

    Hi Skywings,

    So I think the above output is after the change, right? If this is true, it seems that something was wrong during the configuration process. Process of VLAN automatic voice has two main phases where one is related to communication between the switches and other Cisco infrastructure devices and synchronization of voice VLAN ID. The second phase is related to the identification of the end device as phone. What I see in your case that the first phase has failed somehow the voice VLAN ID is different from locally configured. Can you share with me your race and also start-up config more CDP neighbors? You can use private message.

    Kind regards

    Aleksandra

  • VLAN voice ISE with MAB

    Hi all

    I just configured the ISE and the switch to make authentication for my phones of vlan voice.

    Authentication and authorization works well with ISE.

    #show TEST-CONTACT authentication sessions

    Interface MAC address method field status Fg Session ID
    Item in gi1/0/1 001a.e867.4c1a mab VOICE Auth 0A0B1050000000250136CED3

    But, I've only one ip phone connected to the switchport mode multi-domain, I don't have any pc connected to the phone yet, but the command 'show mac - add table int xx' show me the telephone ip and two local area networks virtual, 316(voice vlan) mac and vlan 1.

    The question is, why vlan 1? is it good?

    I have only the VLANs voice 316 configured policy result with the VLAN TAG = 316 and permission of field voice check box selected.

    SWITCH-TEST mac address-table interface gigabitEthernet 0/1/1 #show

    Mac address table
    -------------------------------------------

    VLAN Mac Address Type Ports
    ----    -----------       --------    -----
    316 001a.e867.4c1a STATIC item in gi1/0/1
    1 001a.e867.4c1a STATIC item in gi1/0/1

    Thank you

    Rafael

    I would recommend that you keep the command ' switchport voice vlan "because it is what allows the port to be a port" multi - vlan "without set it up as a trunk. If you remove this command and you always want to spend two VLANS (one per voice) and other data, then you will need to configure the port as 'trunk '. Unfortunately, it won't only 802. 1 x is not supported on the trunk ports :)

    I hope this helps!

    Thank you for evaluating useful messages!

Maybe you are looking for

  • How can I make my big enough to be usable in all night of Mozilla google search bar?

    I have been on your support page to fix the tiny google search box, you have now on every night, he said to look for the userContent.css file, after looking at the file I realized, that it does not appear anywhere in the file of firefox that I can fi

  • Delete the texts

    How to remotely remove SMS from my iPhone without wiping my phone completely?

  • Lost my hard drive

    Can I Exchange my 500 GB Serial ATA SATA Hard Drive IQ506 for a 500 GB Serial ATA SATA Hard Drive HP TouchSmart IQ775 IQ770 HP TouchSmart? My product is KQ437AA SN[personal information] Hitachi HDP725050GLA360 HARD drive Win Vista 64-bit

  • Satellite M40 is Bootable from USB?

    Hello Model: Satellite M40-200 (psm40e) There seems to be no obvious way to boot from USB in the bios. Did I miss something? The closest is "USB - FDD Legacy Emulation", but that seems doing nothing when a USB device is installed. See you soon Marcus

  • Cannot save my router on behalf of readyCLOUD

    I'm trying get readyCLOUD up and running. I created an account on readyCLOUD but when I try to register my router in the interface of the router with the login and the password of readyCLOUD that it does not work. About 20 seconds after you have ente