<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthr in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747472#M579041</link>
    <description>&lt;P&gt;Hello! I have tried it with Smart port enabled and disabled, the working situation I described is with Smartport enabled, seemed to give the best results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you tell me what settings are you interested in? The port is in trunk mode, added workstation vlan(3U) and voip vlan(10T) to it and operational vlans are&amp;nbsp;&lt;SPAN&gt;3U, 6G(Guest vlan), 10T. Smartport is set to static ip phone + Desktop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;802.1x: Port authentication is set to auto, with guest vlan and 802.1x based auth enabled. Re-auth is set to default 3600 so are other settings. Host and session auth is set to:&amp;nbsp;Multiple Host (802.1X).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jan 2023 08:29:25 GMT</pubDate>
    <dc:creator>mdsgnmds</dc:creator>
    <dc:date>2023-01-02T08:29:25Z</dc:date>
    <item>
      <title>Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthrough</title>
      <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4746854#M579025</link>
      <description>&lt;P&gt;Hello dear experts!&lt;/P&gt;&lt;P&gt;Recently I finally got my order of 3x&amp;nbsp;&lt;SPAN&gt;CBS350-48P-4G switches. So far we were working in a simple and insecure manner - we have one workstation VLAN, IP phones connect directly to the switch ports and via passthrough on the IP Phone we connect our laptops. Now I would like to configure ports that go to our workstations to have the following features:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) IP Phone itself gets Auto Voice VLAN(10), We use Grandstream GXP2170.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) If a corporate laptop is connected to passthrough port, it authenticates via 802.1X and gets Workstation VLAN(3).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) If a device fails 802.1X auth it gets guest network(Vlan 6) for simple internet access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Now the issues - all these features I have configured and they work fine, if I connect one device directly to the Switch, IP phone gets an Auto Voice VLAN, Workstations get on corporate network and any other devices are assigned the guest network. The issue is when using the passthrough port - If a corporate laptop is connected, it authenticates and get on the internal network, but then so does the phone, that after a while switches to Voice VLAN. If i move the passthrough cable to a non-corporate laptop, the authorisation still is active and that device also gets on the corporate workstation VLAN.&lt;/P&gt;&lt;P&gt;Is there anything I am missing in configuration, or is this simply the issue with my setup and I wont get it to work this way?&lt;/P&gt;&lt;P&gt;Appreciating all thoughts!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 08:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4746854#M579025</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2022-12-30T08:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthr</title>
      <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4746905#M579029</link>
      <description>&lt;P&gt;how is your port config - can you post that information&lt;/P&gt;
&lt;P&gt;do you have smart port enabled on the port ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 12:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4746905#M579029</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-12-30T12:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthr</title>
      <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747077#M579033</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp; I would check if within the port you have multiple authentication configured , as with this feature, both devices connected ( the PC and the ip-phone) will have an independent Radius session within the switchport , also confirm that the feature is valid within the platform where you're working ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your reference&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/sec-user-8021x-xe-3se-5700-book/sec-ieee-802x-multi-auth.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/5700/sec-user-8021x-xe-3se-5700-book/sec-ieee-802x-multi-auth.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it helped you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 23:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747077#M579033</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2022-12-30T23:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthr</title>
      <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747472#M579041</link>
      <description>&lt;P&gt;Hello! I have tried it with Smart port enabled and disabled, the working situation I described is with Smartport enabled, seemed to give the best results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you tell me what settings are you interested in? The port is in trunk mode, added workstation vlan(3U) and voip vlan(10T) to it and operational vlans are&amp;nbsp;&lt;SPAN&gt;3U, 6G(Guest vlan), 10T. Smartport is set to static ip phone + Desktop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;802.1x: Port authentication is set to auto, with guest vlan and 802.1x based auth enabled. Re-auth is set to default 3600 so are other settings. Host and session auth is set to:&amp;nbsp;Multiple Host (802.1X).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 08:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747472#M579041</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2023-01-02T08:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using Auto voice VLAN for IP Phone and 802.1x/Guest access passthr</title>
      <link>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747473#M579042</link>
      <description>&lt;P&gt;Thank you for the idea, the passthrough port now authenticates nicely and&amp;nbsp; devices that fail authentication get on the guest vlan!&lt;/P&gt;&lt;P&gt;For some reason the auto voice vlan is not assigned anymore for the phone itself, instead it gets on the guest VLAN, but that must be a mistake I have made somewhere while trying to get this to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 11:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-auto-voice-vlan-for-ip-phone-and-802-1x-guest-access/m-p/4747473#M579042</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2023-01-02T11:25:45Z</dc:date>
    </item>
  </channel>
</rss>

