<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Phone not getting Auto Voice VLAN if no passthrough connected in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4749070#M579060</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1448587"&gt;@mdsgnmds&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;good news that you solve your issue by specifying the &lt;STRONG&gt;VLAN&lt;/STRONG&gt; tag on the &lt;STRONG&gt;Phones&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I would like to add the following:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;. If a device advertises itself as a &lt;STRONG&gt;Phone&lt;/STRONG&gt;, the default &lt;STRONG&gt;Smartport Macro&lt;/STRONG&gt; is &lt;STRONG&gt;Phone&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;. If a device advertises itself as a &lt;STRONG&gt;Phone and Host&lt;/STRONG&gt;, the default &lt;STRONG&gt;Smartport Macro&lt;/STRONG&gt; is &lt;STRONG&gt;Phone+Desktop&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;.&amp;nbsp;&amp;nbsp;a device (in your case &lt;STRONG&gt;Grandstream GXP2170&lt;/STRONG&gt;) attaching to a &lt;STRONG&gt;Port&lt;/STRONG&gt; advertises itself as a &lt;STRONG&gt;Voice Endpoint&lt;/STRONG&gt; through &lt;STRONG&gt;CDP&lt;/STRONG&gt; and/or &lt;STRONG&gt;LLDP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ww2598054" class="Ex1_Example1"&gt;. &lt;STRONG&gt;Voice&lt;/STRONG&gt; and &lt;STRONG&gt;Data VLAN&lt;/STRONG&gt; configuration (just an example):&lt;/DIV&gt;
&lt;PRE class="Ex1_Example1"&gt;smartport switchport trunk allowed vlan add&lt;EM&gt;&amp;nbsp;voice_vlan&amp;gt;&lt;/EM&gt;&lt;BR /&gt;smartport switchport trunk native vlan&amp;nbsp;&lt;EM&gt;&amp;lt;native_vlan&amp;gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;DIV class="Ex1_Example1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Ex1_Example1"&gt;Hope this helps !!!&lt;/DIV&gt;</description>
    <pubDate>Wed, 04 Jan 2023 14:32:46 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2023-01-04T14:32:46Z</dc:date>
    <item>
      <title>IP Phone not getting Auto Voice VLAN if no passthrough connected</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748496#M579047</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am trying to set up three CBS 350 switches to have following features:&lt;/P&gt;&lt;P&gt;Workstation ports have Auto Voice vlan, LAN with 802.1x and guest access for devices that don't authenticate with 1x.&lt;/P&gt;&lt;P&gt;In 99% cases each switch port will go to an IP Phone(Grandstream GXP2170) and a corporate computer will be connected to the passthrough PC port on the IP Phone. Guest access is for rare cases of employees connecting their private laptops.&lt;/P&gt;&lt;P&gt;Issue I am facing now is that if an IP phone is connected without any device in the passthrough/pc port, then it fails to get Auto Voice vlan and ends up on guest vlan. If a computer is connected to the passthrough/pc port(Does not matter if it is corporate with 1x authentication or gets a guest vlan) then the phone gets on the voice vlan without a problem.&lt;/P&gt;&lt;P&gt;Also the Smartport macro for IP Phone + Desktop is failing on the command: "port security discard trap 60" with error: "802.1x Guest Enable prevents executing Lock Port Disable."&lt;/P&gt;&lt;P&gt;Here is my config:&lt;/P&gt;&lt;P&gt;VLANs: LAN(3) Guest(6) Voice(10)&lt;/P&gt;&lt;P&gt;Port vlan: Trunk(3U,10T), Operational ports: 3U, 6G, 10T&lt;/P&gt;&lt;P&gt;Smartport set to auto&lt;/P&gt;&lt;P&gt;802.1x: Host authentication set to multiple sessions, Guest vlan enabled.&lt;/P&gt;&lt;P&gt;Not sure what other info is needed, so just ask what additional information I should provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 13:20:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748496#M579047</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2023-01-03T13:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: IP Phone not getting Auto Voice VLAN if no passthrough connected</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748723#M579054</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1448587"&gt;@mdsgnmds&lt;/a&gt;&amp;nbsp;, as it would appear that the issue is only when a phone is connected and it's not being assigned correctly , I would verify if within the Access Accept request of the Radius server is giving you the following attributes within the phone' session (example taken from ISE attributes sent to a the endpoint' session where within the authorization profile we have the option "voice domain permission" enabled ) , there should be another attributes that are proper from the vlan assigned like Tunnel-Type that correspond to the vlan :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;
&lt;P&gt;cisco-av-pair = device-traffic-class=voice&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 21:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748723#M579054</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-01-03T21:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: IP Phone not getting Auto Voice VLAN if no passthrough connected</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748987#M579056</link>
      <description>&lt;P&gt;Thank you for the reply, Rodrigo! Unfortunately we do not have ISE or any other 3rd party software, we use the built in Windows Server NPS. Additionally, we did not want to authenticate the phones in any way, just assign them the VLAN. So we went a way that is not so pretty - specifying the VLAN tag on the phones themselves.&lt;/P&gt;&lt;P&gt;This issue is now resolved, thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 12:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4748987#M579056</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2023-01-04T12:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: IP Phone not getting Auto Voice VLAN if no passthrough connected</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4749070#M579060</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1448587"&gt;@mdsgnmds&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;good news that you solve your issue by specifying the &lt;STRONG&gt;VLAN&lt;/STRONG&gt; tag on the &lt;STRONG&gt;Phones&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I would like to add the following:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;. If a device advertises itself as a &lt;STRONG&gt;Phone&lt;/STRONG&gt;, the default &lt;STRONG&gt;Smartport Macro&lt;/STRONG&gt; is &lt;STRONG&gt;Phone&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;. If a device advertises itself as a &lt;STRONG&gt;Phone and Host&lt;/STRONG&gt;, the default &lt;STRONG&gt;Smartport Macro&lt;/STRONG&gt; is &lt;STRONG&gt;Phone+Desktop&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;.&amp;nbsp;&amp;nbsp;a device (in your case &lt;STRONG&gt;Grandstream GXP2170&lt;/STRONG&gt;) attaching to a &lt;STRONG&gt;Port&lt;/STRONG&gt; advertises itself as a &lt;STRONG&gt;Voice Endpoint&lt;/STRONG&gt; through &lt;STRONG&gt;CDP&lt;/STRONG&gt; and/or &lt;STRONG&gt;LLDP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="ww2598054" class="Ex1_Example1"&gt;. &lt;STRONG&gt;Voice&lt;/STRONG&gt; and &lt;STRONG&gt;Data VLAN&lt;/STRONG&gt; configuration (just an example):&lt;/DIV&gt;
&lt;PRE class="Ex1_Example1"&gt;smartport switchport trunk allowed vlan add&lt;EM&gt;&amp;nbsp;voice_vlan&amp;gt;&lt;/EM&gt;&lt;BR /&gt;smartport switchport trunk native vlan&amp;nbsp;&lt;EM&gt;&amp;lt;native_vlan&amp;gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;DIV class="Ex1_Example1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Ex1_Example1"&gt;Hope this helps !!!&lt;/DIV&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4749070#M579060</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-01-04T14:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: IP Phone not getting Auto Voice VLAN if no passthrough connected</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4749093#M579063</link>
      <description>&lt;P&gt;Thank you for the reply! I actually have an issue with Smartport assignment and it seems that 802.1x authentication is the culprit.&lt;/P&gt;&lt;P&gt;When the switch tries to apply the macro for Phone or Phone+Desktop, it fails on step &lt;STRONG&gt;port security discard trap 60&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If I try to run the command manually on that port in CLI, the message is this:&amp;nbsp;&lt;STRONG&gt;Port gi13: 802.1x Guest Enable prevents executing Lock Port Disable.&amp;nbsp;&lt;/STRONG&gt;So all the smartports that I connect Phones, or Phones+Laptops to are showing up as Smartport Type: Unknown. They do get the right VLANs and actually work though.&lt;/P&gt;&lt;P&gt;I have Classic Lock on all ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 15:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-not-getting-auto-voice-vlan-if-no-passthrough-connected/m-p/4749093#M579063</guid>
      <dc:creator>mdsgnmds</dc:creator>
      <dc:date>2023-01-04T15:00:35Z</dc:date>
    </item>
  </channel>
</rss>

