<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Voice VLAN Dynamic Assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430462#M538466</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a situation where when ISE does a dynamic VLAN assignment for the voice VLAN, the voice device doe snot auth like it should. From what we can tell ISE is doing it's job. Auth logs on ISE show the phone being properly identified and assigned the VLAN/DACL/VOICE domain as expected. RADIUS debug on the switch confirms that the switch is getting the correct VLAN, but the switch appears not to apply it properly.&lt;/P&gt;&lt;P&gt;The switches that we are using are 2960S &amp;amp; 2960X switches with at the 15.2.2.e4 as the code level. Per the documentation you need to be at least at version 15.2.2.e3 to support ISE. We see this behavior on both models of 2960's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have tried the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- No voice VLAN defined:&amp;nbsp; this resulted in the auth session being put in &lt;BR /&gt; the voice domain, but not applying the vlan that ISE assigned and the &lt;BR /&gt; status was "Unauth" rather than the usual "Auth" status.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;SPAN style="font-size: 10pt;"&gt;- Voice VLAN defined as quarantine VLAN:&amp;nbsp; same result as above&lt;BR /&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- Voice VLAN defined as usual/correct VLAN for the switch:&amp;nbsp; works &lt;BR /&gt; great.&amp;nbsp; But we're trying to avoid having to manually specify the voice &lt;BR /&gt; VLAN on all switch ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- Removed voice domain from the ISE authorization policy.&amp;nbsp; This, &lt;BR /&gt; surprisingly, worked-- kinda.&amp;nbsp; The switch used the VLAN specified by ISE &lt;BR /&gt; for the phone's auth session, but in the data domain.&amp;nbsp; But this won't &lt;BR /&gt; play nice with "multi-domain" authorization-- since the phone and the &lt;BR /&gt; workstation behind it are both put in the "data" domain, only one of &lt;BR /&gt; them will function at a time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Looking over documentation and others trials and tribulations, this should work with the voice domain checked from the ISE authentication policy, The phone never gets authed, but on the data side all appears to work as expected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Has anyone had this work as expected with the data &amp;amp; voice both being dynamically assigned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Sam&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Jun 2016 01:22:55 GMT</pubDate>
    <dc:creator>sholley</dc:creator>
    <dc:date>2016-06-28T01:22:55Z</dc:date>
    <item>
      <title>Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430462#M538466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a situation where when ISE does a dynamic VLAN assignment for the voice VLAN, the voice device doe snot auth like it should. From what we can tell ISE is doing it's job. Auth logs on ISE show the phone being properly identified and assigned the VLAN/DACL/VOICE domain as expected. RADIUS debug on the switch confirms that the switch is getting the correct VLAN, but the switch appears not to apply it properly.&lt;/P&gt;&lt;P&gt;The switches that we are using are 2960S &amp;amp; 2960X switches with at the 15.2.2.e4 as the code level. Per the documentation you need to be at least at version 15.2.2.e3 to support ISE. We see this behavior on both models of 2960's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have tried the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- No voice VLAN defined:&amp;nbsp; this resulted in the auth session being put in &lt;BR /&gt; the voice domain, but not applying the vlan that ISE assigned and the &lt;BR /&gt; status was "Unauth" rather than the usual "Auth" status.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;SPAN style="font-size: 10pt;"&gt;- Voice VLAN defined as quarantine VLAN:&amp;nbsp; same result as above&lt;BR /&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- Voice VLAN defined as usual/correct VLAN for the switch:&amp;nbsp; works &lt;BR /&gt; great.&amp;nbsp; But we're trying to avoid having to manually specify the voice &lt;BR /&gt; VLAN on all switch ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- Removed voice domain from the ISE authorization policy.&amp;nbsp; This, &lt;BR /&gt; surprisingly, worked-- kinda.&amp;nbsp; The switch used the VLAN specified by ISE &lt;BR /&gt; for the phone's auth session, but in the data domain.&amp;nbsp; But this won't &lt;BR /&gt; play nice with "multi-domain" authorization-- since the phone and the &lt;BR /&gt; workstation behind it are both put in the "data" domain, only one of &lt;BR /&gt; them will function at a time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Looking over documentation and others trials and tribulations, this should work with the voice domain checked from the ISE authentication policy, The phone never gets authed, but on the data side all appears to work as expected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Has anyone had this work as expected with the data &amp;amp; voice both being dynamically assigned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Sam&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 01:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430462#M538466</guid>
      <dc:creator>sholley</dc:creator>
      <dc:date>2016-06-28T01:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430463#M538468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure port is configured for MDA (authentication host-mode multi-domain) and not multi-auth.&amp;nbsp; Also, be sure to still send Voice VLAN permission in authorization.&amp;nbsp; You may need to also set some default Voice VLAN on port, but you can verify in testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, a point of clarification...&lt;/P&gt;&lt;P&gt;IOS 15.2(2)E4 is not the minimum required IOS version, but the minimum &lt;EM&gt;recommended&lt;/EM&gt; version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 02:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430463#M538468</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-06-28T02:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430464#M538469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we have MDA and not multi-auth set on the port and we are sending the voice VLAN permission in the authorization. We have also tried with and without a default voice vlan set on the port, and still see the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 03:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430464#M538469</guid>
      <dc:creator>sholley</dc:creator>
      <dc:date>2016-06-28T03:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430465#M538470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Recommendation would be to open a TAC case.&amp;nbsp; It does not sound like an ISE issue, but behavior specific to switch model/version.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 03:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430465#M538470</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-06-28T03:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430466#M538471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Per Craig's comment about recommended switch version... ignore the &lt;A href="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" title="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html"&gt;ISE Compatibility Guides&lt;/A&gt;' recommended switch IOS version at your own peril.&amp;nbsp; If it doesn't work and it's not an ISE-recommended version, it's probably a switch bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 06:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430466#M538471</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-28T06:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430467#M538472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think this is possible. Network devices don't take voice vlan assignment via RADIUS. Voice VLAN has to be configured statically on the switch. You can try to use auto smart ports to set the voice vlan: &lt;A href="http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3750-series-switches/116515-configure-autosmartports-00.html" title="http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3750-series-switches/116515-configure-autosmartports-00.html"&gt;Auto Smartport with Custom Trigger Configuration Example - Cisco&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The phone may take extra time to register in that case because it would have to wait for a CDP update and then re-ip on a new voice vlan. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 17:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430467#M538472</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2016-06-28T17:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN Dynamic Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430468#M538473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Viktor, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dynamic Voice VLAN as the name implies is the ability to set Voice VLAN from AAA server.&amp;nbsp; For more info, can review Catalyst IOS Configuration Guides, or nice session here from Shelly Cadora in 2012 at Cisco Live: &lt;A href="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=4374&amp;amp;backBtn=true" title="https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=4374&amp;amp;backBtn=true"&gt;Advanced IEEE 802.1X (2012 San Diego)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2016 19:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-dynamic-assignment/m-p/3430468#M538473</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-06-28T19:13:36Z</dc:date>
    </item>
  </channel>
</rss>

