cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6898
Views
0
Helpful
3
Replies

Voice domain behavior... confirming behavior

paul
Level 10
Level 10

I want to confirm something I have seen for a long time, but never confirmed if this is functioning as designed.  When in closed mode on the switch port here is what I observe:

 

  1. If the authorization profile doesn't specify the Voice domain and the device, typically an IP phone, tries to use the voice VLAN on the port the switch will drop the traffic.
  2. If the authorization profile specifies the Voice domain but the device is on the data VLAN on the port the switch allows the traffic.

So Voice domain works on any device, but not setting voice domain will break IP phones trying to access voice vlan on the port.

 

That is what I have seen for year, but never confirmed if that was functioning as designed.  This is on Multi Auth.  On older IOS versions, I thought you could only have 1 voice domain device even in Multi Auth, but now I have seen ports with more than one Voice domain device function just fine.

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

The behavior is different depending on auth mode (multi-host vs multi-mda vs multi-auth).  With multi-host, the phone can be authorized to voice VLAN via CDP alone--not very secure, but simple.  With multi-mda, only one endpoint is authorized for data and one for voice.  Even in open mode, voice domain permissions must be assigned to authorize phone to voice VLAN/domain.  In multi-auth, you can have multiple endpoints authorized in data domain and one for voice.  There are reported cases where phone is stuck in data domain, but if authorized for voice then expected behavior is for it to move to voice VLAN.  Originally the data domain was limited to a single VLAN, so all devices had to share the same data VLAN--first PC, for example, would get VLAN 10, then all other data endpoints had to be assigned to same VLAN.  Newer versions of IOS allow multiple data VLANs so that each endpoint can be assigned to its own data VLAN.

View solution in original post

3 Replies 3

Craig Hyps
Level 10
Level 10

The behavior is different depending on auth mode (multi-host vs multi-mda vs multi-auth).  With multi-host, the phone can be authorized to voice VLAN via CDP alone--not very secure, but simple.  With multi-mda, only one endpoint is authorized for data and one for voice.  Even in open mode, voice domain permissions must be assigned to authorize phone to voice VLAN/domain.  In multi-auth, you can have multiple endpoints authorized in data domain and one for voice.  There are reported cases where phone is stuck in data domain, but if authorized for voice then expected behavior is for it to move to voice VLAN.  Originally the data domain was limited to a single VLAN, so all devices had to share the same data VLAN--first PC, for example, would get VLAN 10, then all other data endpoints had to be assigned to same VLAN.  Newer versions of IOS allow multiple data VLANs so that each endpoint can be assigned to its own data VLAN.

Thanks Craig.  I think I have seen in newer IOS as well more than one device allowed in the voice VLAN, but I would have to retest.  This is all in multi-auth.  I haven't tested the multiple data VLANs on same port in a while.  I didn't know newer versions of IOS were allowing that. 

 

 

howon
Cisco Employee
Cisco Employee

Paul, your observations are expected. When device is assigned voice domain permission, the switch allows access to both data and voice VLAN. This is to accommodate IP phones without CDP/LLDP capability, which depends on DHCP to learn voice VLAN ID. By allowing temporary data VLAN access, the IP phone can boot up on data VLAN and get IP address without tagging, where it learns the voice VLAN, then restarts network interface with voice VLAN ID tag to get IP from the voice VLAN.

However, one voice device requirement still holds true on a given interface. You may be able to assign multiple devices with voice domain permission to the same interface, however, you won’t be able to send traffic from more than one device in voice VLAN.

Note that it is not the newer IOS that supports multi-VLAN assignment, rather specific platform supports the feature; 3850, 3650, and 2960X.