cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
846
Views
2
Helpful
13
Replies

MAB authentication with cisco Phone

Hi all 

i`m using DNA and my company recently bougth ISE and we doing our implamantion o face problem with the Cisco Phone 

the problem it how to assigend Voice vlan to cisco phone when they try to connect using mab , becuse when i use authiz profile that assend vlan X when phone authication it`s give the port as access vlan not voice vlan 

i read about i can assgned template this teplate have command (sw acc voice vlan) , but the problem with this solution is the dna when i applyed close authication dna pushed template and i cannt apply two template on the same port 

so if anyone have any idea about how to make any phone auth mab assgiend to voice vlan 

 

thanks 

13 Replies 13

@Saeed Abd Elhalim Hamada create an Authorisation Profile to to send a Cisco Attribute-Value (AV) pair attribute with a value of - device-traffic-class=voice

Example

 

you mean voice per ?

saeedabdelhalimhamada_0-1738567269117.png

 

 

@Saeed Abd Elhalim Hamada yes you can use the "Voice Domain Permission" common task.

saeedabdelhalimhamada_0-1738568441652.png

 

@Saeed Abd Elhalim Hamada ok, what is the issue now?

Provide the output of "show authentication session interface gig 6/0/23 detail"

Provide the output of the configuration of GI6/0/23

the interface should be in VLAN 8 as voice and Vlan 50 as data  

saeedabdelhalimhamada_0-1738569041714.png

 

 

@Saeed Abd Elhalim Hamada is "switchport voice vlan 8" configured under the interface?

Provide the output of the configuration of GI6/0/23

no it`s not 

i need to make it dynamic vlan is that possible , cuz if i didnt i need to make all interface voice vlan static

I think you can, but you would still need to configure a default voice VLAN on the switch interfaces. Say if you configure the default voice VLAN to be 20 and then you push different voice VLAN IDs from ISE, the voice VLAN attributes on the ports will be taken from ISE. Alternatively I think you can rely on the interface template feature but that would require running IBNS 2.0 to be able to assign the VLAN ID.

@Aref Alsouqi - I have yet to find the RADIUS attribute that tells a switch to change the VOICE VLAN.  I don't believe this feature exists. It does of course exist for the 'access vlan' (DATA domain).

@Arne Bier I was wrong on this one, thanks for pointing that out. I checked on a deployment I have and I couldn't find any attribute to change the voice VLAN dynamically. I think the only option to do that would be via the interface templates or maybe the service templates but I think both would require IBNS 2.0.

phone keep in verviy your network stage 

saeedabdelhalimhamada_1-1738567713186.png

Overview

Event5200 Authentication succeeded
Username6C:41:0E:DE:DA:E4
Endpoint Id6C:41:0E:DE:DA:E4 
 
Endpoint ProfileCisco-IP-Phone-8811
Authentication PolicyWired MAB NIB Phones >> New-Mab Auth
Authorization PolicyWired MAB NIB Phones >> Authorization Rule 1
Authorization ResultVOICE_VLAN_8

 

Authentication Details

Source Timestamp2025-02-03 09:23:19.453
Received Timestamp2025-02-03 09:23:19.453
Policy ServerISE-01
Event5200 Authentication succeeded
Username6C:41:0E:DE:DA:E4
User TypeHost
Endpoint Id6C:41:0E:DE:DA:E4
Calling Station Id6C-41-0E-DE-DA-E4
Endpoint ProfileCisco-IP-Phone-8811
Authentication Identity StoreInternal Endpoints
Identity GroupCisco-IP-Phone
Audit Session Id01000C0A0000ED04CAE5D5B6
Authentication Methodmab
Authentication ProtocolLookup
Service TypeCall Check
Network DeviceEdge-F3-01-R.Nibhq.local
Device TypeAll Device Types#NAS Address
NAS IPv4 Address10.100.3.1
NAS Port IdGigabitEthernet6/0/23
NAS Port TypeEthernet
Authorization ProfileVOICE_VLAN_8
Response Time8 milliseconds

 

Other Attributes

ConfigVersionId389
DestinationPort1812
ProtocolRadius
NAS-Port50623
Framed-MTU1468
OriginalUserName6c410ededae4
NetworkDeviceProfileIdb0699505-3150-4215-a80e-6753d45bf56c
IsThirdPartyDeviceFlowfalse
AcsSessionIDISE-01/526818642/733406
SelectedAuthenticationIdentityStoresInternal Endpoints
AuthenticationStatusAuthenticationPassed
IdentityPolicyMatchedRuleNew-Mab Auth
AuthorizationPolicyMatchedRuleAuthorization Rule 1
EndPointMACAddress6C-41-0E-DE-DA-E4
ISEPolicySetNameWired MAB NIB Phones
IdentitySelectionMatchedRuleNew-Mab Auth
TotalAuthenLatency8
ClientLatency0
DTLSSupportUnknown
HostIdentityGroupEndpoint Identity Groups:Profiled:Cisco-IP-Phone
Network Device ProfileCisco
LocationLocation#All Locations
Device TypeDevice Type#All Device Types#NAS Address
IPSECIPSEC#Is IPSEC Device#No
NameEndpoint Identity Groups:Profiled:Cisco-IP-Phone
RADIUS Username6C:41:0E:DE:DA:E4
Device IP Address10.100.3.1
CPMSessionID01000C0A0000ED04CAE5D5B6
Called-Station-ID7C:AD:4F:28:FD:97
CiscoAVPaircts-pac-opaque=****,service-type=Call Check,audit-session-id=01000C0A0000ED04CAE5D5B6,method=mab,client-iif-id=371229461,AuthenticationIdentityStore=Internal Endpoints
UseCaseHost Lookup

 

Result

UserName6C:41:0E:DE:DA:E4
User-Name6C-41-0E-DE-DA-E4
ClassCACS:01000C0A0000ED04CAE5D5B6:ISE-01/526818642/733406
cisco-av-pairdevice-traffic-class=voice
cisco-av-pairprofile-name=Cisco-IP-Phone-8811
LicenseTypesAdvantage license consumed.