<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC bypassing IP Phone switch in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316186#M790649</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It might also be the use of trunking between the switch and the router.  If you have trunking, remove it and use the connection between the two devices, router and switch, as an access port only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works out for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, any other devices on the switch that the NAC identifies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Apr 2005 15:13:52 GMT</pubDate>
    <dc:creator>stevanp</dc:creator>
    <dc:date>2005-04-08T15:13:52Z</dc:date>
    <item>
      <title>NAC bypassing IP Phone switch</title>
      <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316185#M790641</link>
      <description>&lt;P&gt;On  NAC configuration (1751 router )&lt;/P&gt;&lt;P&gt;i try to bypass IP Phone configuring ip phone identification  with :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;identity profile eapoudp&lt;/P&gt;&lt;P&gt;device authorize type cisco ip phone policy ip_phone&lt;/P&gt;&lt;P&gt;identity policy ip_phone&lt;/P&gt;&lt;P&gt;access-group nac_ip_phone_acl&lt;/P&gt;&lt;P&gt;eou allow clientless&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended nac_ip_phone_acl&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If IP Phone is directly connected to the router the identity profile is metched and NAC work fine .&lt;/P&gt;&lt;P&gt;But if IP Phone is connected to a switch port (C3550)and router is connected to another switch port  (C3550) router NAC fail to identify device IP Phone.&lt;/P&gt;&lt;P&gt;I think because router CDP don't see IP Phone but i am not shure.&lt;/P&gt;&lt;P&gt;Is there anyone who can lend me a hand ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316185#M790641</guid>
      <dc:creator>slupetti</dc:creator>
      <dc:date>2020-02-21T08:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAC bypassing IP Phone switch</title>
      <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316186#M790649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It might also be the use of trunking between the switch and the router.  If you have trunking, remove it and use the connection between the two devices, router and switch, as an access port only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works out for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, any other devices on the switch that the NAC identifies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Apr 2005 15:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316186#M790649</guid>
      <dc:creator>stevanp</dc:creator>
      <dc:date>2005-04-08T15:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAC bypassing IP Phone switch</title>
      <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316187#M790661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All switch ports are access port and router ,phone are the only devices .&lt;/P&gt;&lt;P&gt;I think the CDP is protocol with the router identify Phone ,if this is true , router don't see Phone &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Apr 2005 07:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316187#M790661</guid>
      <dc:creator>slupetti</dc:creator>
      <dc:date>2005-04-09T07:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAC bypassing IP Phone switch</title>
      <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316188#M790691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - you are right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router can use CDP to discover a phone and apply it to your clientless group.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the same phone plugs into a switch, the CDP packets are not forwarded by the switch to the router, so the router is not able to use CDP to have the phone be clientless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what are the possible solutions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would guess that I would permit access to the DHCP server for the IP Phone vlan on the default interface ACL.  I would place my phones and PCs in seperate Vlans and then exempt the ip addresses from the phone vlans from NAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this sound feasible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Apr 2005 16:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316188#M790691</guid>
      <dc:creator>pcomeaux</dc:creator>
      <dc:date>2005-04-12T16:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: NAC bypassing IP Phone switch</title>
      <link>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316189#M790707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have similar issue with wireless 7920 IP Phone connecting to 871W when I apply admission to BVI1 interface.  Does any know if NAC is supported for 7920 wireless? TIA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;identity profile eapoudp&lt;/P&gt;&lt;P&gt; device authorize type cisco ip phone policy VoicePolicy&lt;/P&gt;&lt;P&gt;identity policy VoicePolicy&lt;/P&gt;&lt;P&gt; access-group VoiceACL&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip admission name SDM_EOU_1 eapoudp inactivity-time 60&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt; ip access-group 100 in&lt;/P&gt;&lt;P&gt; ip admission SDM_EOU_1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2007 21:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-bypassing-ip-phone-switch/m-p/316189#M790707</guid>
      <dc:creator>cko</dc:creator>
      <dc:date>2007-04-27T21:18:27Z</dc:date>
    </item>
  </channel>
</rss>

