<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Phone Not Trusted in IP Telephony and Phones</title>
    <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720894#M11275</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This turns on trust:&lt;/P&gt;&lt;P&gt;mls qos trust cos &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This actually turns off trust if there is no IP phone (hence "conditional trust"):&lt;/P&gt;&lt;P&gt;mls qos trust device cisco-phone &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command itself never turns on trust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a lot of documentation, but actually it's not really good...&lt;/P&gt;&lt;P&gt;Even in the newest BCMSN book there are wrong examples...&lt;/P&gt;&lt;P&gt;..and then there is the SW...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know of issues with ATAs. ATAs will end up in the Voice VLAN, but are not trusted if there is the "mls qos trust device cisco-phone".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably this issue is also there with other phone types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have this problem only with some phone types?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Dec 2007 21:49:47 GMT</pubDate>
    <dc:creator>MARTIN STREULE</dc:creator>
    <dc:date>2007-12-13T21:49:47Z</dc:date>
    <item>
      <title>Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720887#M11268</link>
      <description>&lt;P&gt;I have been investigating issues where certain phones traffic is not passing QoS parameters across the LAN.  I started walking back through the network and got all the way to the access switch where I did a "show mls qos inter fa XX" and found the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FastEthernet3/0/22&lt;/P&gt;&lt;P&gt;trust state: not trusted&lt;/P&gt;&lt;P&gt;trust mode: trust cos&lt;/P&gt;&lt;P&gt;trust enabled flag: dis&lt;/P&gt;&lt;P&gt;COS override: dis&lt;/P&gt;&lt;P&gt;default COS: 0&lt;/P&gt;&lt;P&gt;DSCP Mutation Map: Default DSCP Mutation Map&lt;/P&gt;&lt;P&gt;Trust device: cisco-phone&lt;/P&gt;&lt;P&gt;qos mode: port-based&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This port appears in "show cdp nei"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SEP0019E7290456 Fas 3/0/22 46 H P IP Phone 7Port 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration on the port:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet3/0/22&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 12&lt;/P&gt;&lt;P&gt; srr-queue bandwidth share 10 10 60 20&lt;/P&gt;&lt;P&gt; srr-queue bandwidth shape  10  0  0  0&lt;/P&gt;&lt;P&gt; mls qos trust device cisco-phone&lt;/P&gt;&lt;P&gt; mls qos trust cos&lt;/P&gt;&lt;P&gt; auto qos voip cisco-phone&lt;/P&gt;&lt;P&gt; no mdix auto&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been going through the switch line by line and I have not found anything that would indicate why 90% of the ports on the switch are in a not trusted state, but 10% are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output of the "show mls qos" command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;QoS is enabled&lt;/P&gt;&lt;P&gt;QoS ip packet dscp rewrite is enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone offer any assistance before I open a TAC case?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 05:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720887#M11268</guid>
      <dc:creator>djohnson</dc:creator>
      <dc:date>2019-03-15T05:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720888#M11269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the configuration which you have provided a cisco phone is trusted because of the command " mls qos trust device cisco-phone "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2007 14:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720888#M11269</guid>
      <dc:creator>smahbub</dc:creator>
      <dc:date>2007-07-25T14:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720889#M11270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The syntax of "mls qos trust device cisco-phone" refers to the packet classification the phone does for voice and the data packets it passes through for any PC connected to it.  If you have LAN QOS implemented in the network, this should be one of a few commands on each switchport that a phone is connected to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shikamaru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2007 14:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720889#M11270</guid>
      <dc:creator>shikamarunara</dc:creator>
      <dc:date>2007-07-25T14:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720890#M11271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;quote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I have been going through the switch line by line and I have not found anything that would indicate why 90% of the ports on the switch are in a not trusted state, but 10% are. &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are all the ports that are connected to phones configured in exactly the same way and with identical configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the answer is yes there are two things you can do, or perhaps three.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Reset a phone to see if it makes a difference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Reload the switch - see if it fixes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If after completing the above mentioned and most obvious actions - raise a TAC case, it definately sounds like SW related defect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way what version of code do you have loaded on the Cisco switch that is connected to the phones...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ajaz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2007 19:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720890#M11271</guid>
      <dc:creator>AJAZ NAWAZ</dc:creator>
      <dc:date>2007-07-25T19:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720891#M11272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever get a resolution for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 17:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720891#M11272</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2007-12-13T17:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720892#M11273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you have "trust cost" and "trust device"?  Also, what does "sh cdp neigh" show?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 17:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720892#M11273</guid>
      <dc:creator>Aaron Dhiman</dc:creator>
      <dc:date>2007-12-13T17:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720893#M11274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have mls qos trust device cisco-phone&lt;/P&gt;&lt;P&gt;have tried mls qos trust cos and dscp&lt;/P&gt;&lt;P&gt;show cdp neighbors shows the phone on port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 17:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720893#M11274</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2007-12-13T17:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720894#M11275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This turns on trust:&lt;/P&gt;&lt;P&gt;mls qos trust cos &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This actually turns off trust if there is no IP phone (hence "conditional trust"):&lt;/P&gt;&lt;P&gt;mls qos trust device cisco-phone &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command itself never turns on trust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a lot of documentation, but actually it's not really good...&lt;/P&gt;&lt;P&gt;Even in the newest BCMSN book there are wrong examples...&lt;/P&gt;&lt;P&gt;..and then there is the SW...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know of issues with ATAs. ATAs will end up in the Voice VLAN, but are not trusted if there is the "mls qos trust device cisco-phone".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably this issue is also there with other phone types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have this problem only with some phone types?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 21:49:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720894#M11275</guid>
      <dc:creator>MARTIN STREULE</dc:creator>
      <dc:date>2007-12-13T21:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720895#M11276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried to configure a port in "trunk" mode?  Also, what is the switch model?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 00:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720895#M11276</guid>
      <dc:creator>Aaron Dhiman</dc:creator>
      <dc:date>2007-12-14T00:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720896#M11277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Odd thing...take out the mls qos trust device command and now it appears to be working:  The original problem was that I wasn't seeing any matches on the policy map on the Router...now I am:&lt;/P&gt;&lt;P&gt;Customer_Switch#show cdp neighbors  &lt;/P&gt;&lt;P&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/P&gt;&lt;P&gt;                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/P&gt;&lt;P&gt;SEP000D65C2DC7A  Fas 0/11           128          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;SEP000D65C2CFA2  Fas 0/4            170          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;SEP000D65BC9575  Fas 0/5            166          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;SEP000D65C2E06B  Fas 0/8            131          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;SEP000D65E61447  Fas 0/7            173          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;SEP000D65E61449  Fas 0/10           164          H P      Cisco SystPort 1&lt;/P&gt;&lt;P&gt;Customer_RoutFas 0/1            121           R       1760      Fas 0/0&lt;/P&gt;&lt;P&gt;Customer_Switch#show run&lt;/P&gt;&lt;P&gt;Customer_Switch#show running-config int fas 0/11&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 215 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/11&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 210&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; switchport voice vlan 192&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; mls qos trust dscp&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer_Switch#sho mls qo&lt;/P&gt;&lt;P&gt;Customer_Switch#sho mls qos int&lt;/P&gt;&lt;P&gt;Customer_Switch#sho mls qos interface fas&lt;/P&gt;&lt;P&gt;Customer_Switch#sho mls qos interface fastEthernet 0/11&lt;/P&gt;&lt;P&gt;FastEthernet0/11&lt;/P&gt;&lt;P&gt;trust state: trust dscp&lt;/P&gt;&lt;P&gt;trust mode: trust dscp&lt;/P&gt;&lt;P&gt;COS override: dis&lt;/P&gt;&lt;P&gt;default COS: 0&lt;/P&gt;&lt;P&gt;DSCP Mutation Map: Default DSCP Mutation Map&lt;/P&gt;&lt;P&gt;trust device: none&lt;/P&gt;&lt;P&gt;Router:&lt;/P&gt;&lt;P&gt;Service-policy output: outgoing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Class-map: Voicertp (match-all)&lt;/P&gt;&lt;P&gt;      269381 packets, 19284602 bytes&lt;/P&gt;&lt;P&gt;      30 second offered rate 27000 bps, drop rate 0 bps&lt;/P&gt;&lt;P&gt;      Match: ip dscp ef &lt;/P&gt;&lt;P&gt;      Queueing&lt;/P&gt;&lt;P&gt;        Strict Priority&lt;/P&gt;&lt;P&gt;        Output Queue: Conversation 264 &lt;/P&gt;&lt;P&gt;        Bandwidth 384 (kbps) Burst 9600 (Bytes)&lt;/P&gt;&lt;P&gt;        (pkts matched/bytes matched) 615/42932&lt;/P&gt;&lt;P&gt;        (total drops/bytes drops) 0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Class-map: Voicesignal (match-any)&lt;/P&gt;&lt;P&gt;      7242 packets, 398049 bytes&lt;/P&gt;&lt;P&gt;      30 second offered rate 0 bps, drop rate 0 bps&lt;/P&gt;&lt;P&gt;      Match: ip dscp cs3 &lt;/P&gt;&lt;P&gt;        7242 packets, 398049 bytes&lt;/P&gt;&lt;P&gt;        30 second rate 0 bps&lt;/P&gt;&lt;P&gt;      Queueing&lt;/P&gt;&lt;P&gt;        Output Queue: Conversation 265 &lt;/P&gt;&lt;P&gt;        Bandwidth 70 (kbps) Max Threshold 64 (packets)&lt;/P&gt;&lt;P&gt;        (pkts matched/bytes matched) 30/1668&lt;/P&gt;&lt;P&gt;        (depth/total drops/no-buffer drops) 0/0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 13:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720896#M11277</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2007-12-14T13:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Phone Not Trusted</title>
      <link>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720897#M11278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did get a resolution to this.  Cisco told me to reboot the switch and it fixed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it happens again. It appears to be a degredation in the state of the ports.  We are now seeing this on connections to routers, gateways, servers, and phones.  This is causing a big issue because no matter what I do there is no way to get the trust state back without taking an outage on the switch during a reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to get a TAC case opened again and see if there are any more resolutions to this now.  I have been working with my consulting group to find a published bug or a software upgrade solution, but nothing yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2008 02:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/ip-telephony-and-phones/cisco-phone-not-trusted/m-p/720897#M11278</guid>
      <dc:creator>djohnson</dc:creator>
      <dc:date>2008-03-05T02:57:04Z</dc:date>
    </item>
  </channel>
</rss>

