<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIsco ISE and dynamic Voice Vlan assigment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/4014141#M484942</link>
    <description>&lt;P&gt;I think i run into the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the default port config on the switches look like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan yyy&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport vocie vlan xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for voice devices which support vlan discovery via lldp/cdp it works fine to push the "Voice Permission" via ISE.&lt;/P&gt;&lt;P&gt;Unfortunatelly we also have voice devices on the same switches, which need the voice vlan natively (switchport access vlan xxx).&lt;/P&gt;&lt;P&gt;the problem is, that the switch can not apply the access vlan xxx, as long as it has the voice vlan xxx hardcoded on the switchport.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the idea here was to have the default switchport config look like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan yyy&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and assign the voice vlan dynamically either with "voice permission" or "natively".&amp;nbsp; but since there is no attribute to push voice vlan ID within the Voice domain, i guess i'll have to move those voice clients to a different vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Jan 2020 12:24:22 GMT</pubDate>
    <dc:creator>samuel.heinrich</dc:creator>
    <dc:date>2020-01-19T12:24:22Z</dc:date>
    <item>
      <title>CIsco ISE and dynamic Voice Vlan assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806634#M484938</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have a ISE deployment with Cisco Catalyst 3560, 3750, 3650 Switches. We use Unify, Avaya and Alcatel Phones and want to seperate them in different voice vlans.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So our idea was to push the voice vlan on to the access ports. Is there are a way to push different voice vlans to the ports?&lt;/P&gt;
&lt;P&gt;Our current port config looks like that:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;network-policy 713&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;switchport mode access&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;ip device tracking maximum 10&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication control-direction in&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication event fail action next-method&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication event server dead action authorize vlan 1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication event server dead action authorize voice&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication event server alive action reinitialize&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication host-mode multi-auth&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication order dot1x mab&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication priority dot1x mab&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication port-control auto&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication periodic&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication timer reauthenticate server&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication timer inactivity server&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;authentication violation restrict&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;mab&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;dot1x timeout tx-period 8&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;no lldp med-tlv-select power-management&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;spanning-tree portfast&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;network-policy profile 713&lt;BR /&gt;&amp;nbsp;voice vlan 13&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ISE is pushing a Authz Result with Voice Permission and a Vlan ID.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The authentication on the switch itself false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;MAC Address: aabb.ccdd.eeff&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;IPv6 Address: Unknown&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;IPv4 Address: Unknown&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;User-Name: mschap-username&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Status: &lt;U&gt;Unauthorized&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Domain: VOICE&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Oper host mode: multi-auth&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Oper control dir: in&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Session timeout: N/A&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Restart timeout: N/A&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Periodic Acct timeout: N/A&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Common Session ID: 0A1BF1E200000101B6B357DF&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Acct Session ID: Unknown&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Handle: 0x1D00009C&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Current Policy: POLICY_INTERFACE&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Local Policies:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Method status list:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Method State&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;dot1x Authc Success&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and the following event is logged:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Feb 21 11:42:06: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas or suggestions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanky you for your help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sven&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806634#M484938</guid>
      <dc:creator>swenska</dc:creator>
      <dc:date>2019-03-09T03:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE and dynamic Voice Vlan assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806728#M484939</link>
      <description>Hi, ISE doesn't override voice vlan. It allows the use of voice vlan using&lt;BR /&gt;voice domain feature.&lt;BR /&gt;</description>
      <pubDate>Thu, 21 Feb 2019 12:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806728#M484939</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-21T12:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE and dynamic Voice Vlan assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806746#M484940</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sorry for the misunderstanding. I am aware of the "Voice Permission" parameter.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to push the endpoint to the voice domain AND what to push a dynmaic voice vlan id.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sven&lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2019 12:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3806746#M484940</guid>
      <dc:creator>swenska</dc:creator>
      <dc:date>2019-02-21T12:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE and dynamic Voice Vlan assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3807764#M484941</link>
      <description>&lt;P&gt;Yes, should work but if I recall you need to have the following:&lt;/P&gt;
&lt;P&gt;- Default voice VLAN configured on the interface: run 'switchport voice vlan XXX' to assign a default voice VLAN&lt;/P&gt;
&lt;P&gt;- Send voice domain permission (Which I believe you are already doing)&lt;/P&gt;
&lt;P&gt;- Change the host-mode to multi-domain&lt;/P&gt;
&lt;P&gt;- Since using 3rd party phone enable LLDP: Using DHCP to provide voice VLAN ID will be tricky since you have different vendor phones connecting, so will need to use LLDP to share voice VLAN from the switch to the phones&lt;/P&gt;
&lt;P&gt;I believe all of the Catalyst models you mentioned should be able to support it, but suggest testing all three independently in case one of the model may not.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/3807764#M484941</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-02-22T16:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE and dynamic Voice Vlan assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/4014141#M484942</link>
      <description>&lt;P&gt;I think i run into the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the default port config on the switches look like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan yyy&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport vocie vlan xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for voice devices which support vlan discovery via lldp/cdp it works fine to push the "Voice Permission" via ISE.&lt;/P&gt;&lt;P&gt;Unfortunatelly we also have voice devices on the same switches, which need the voice vlan natively (switchport access vlan xxx).&lt;/P&gt;&lt;P&gt;the problem is, that the switch can not apply the access vlan xxx, as long as it has the voice vlan xxx hardcoded on the switchport.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the idea here was to have the default switchport config look like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan yyy&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and assign the voice vlan dynamically either with "voice permission" or "natively".&amp;nbsp; but since there is no attribute to push voice vlan ID within the Voice domain, i guess i'll have to move those voice clients to a different vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 12:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-dynamic-voice-vlan-assigment/m-p/4014141#M484942</guid>
      <dc:creator>samuel.heinrich</dc:creator>
      <dc:date>2020-01-19T12:24:22Z</dc:date>
    </item>
  </channel>
</rss>

