cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
1
Replies

dot1x on trunk ports???? Why not???

kirkster
Level 3
Level 3

Hi,

I am running IP telephony (not Cisco) over Cisco LAN switches using the voice VLAN feature. Everything works fine. NOw, I want to use dot1x for port authentication. This is not supported on voice vlans or any type of trunking interface. Why not? ANyone got any ideas of how I could do this since my IP phones will act as a dot1z client. Can CIsco IP phones utilise dot1x?

Best regards,

Steve

1 Reply 1

milan.kulik
Level 10
Level 10

Hi,

it seems like Cisco is using CDP only to authenticate IP phones on voice-vlan ports.

See http://cisco.com/en/US/products/hw/switches/ps628/products_configuration_guide_chapter09186a0080150b73.html#50544

What type of IP phones are you using?

Wouldn't it be possible to configure your IP phone to sent voice with higher 802.1p priority (similar to switchport voice vlan dot1p command) but in the same (native) vlan as PC data?

If you left 802.1x authentication running on the port, wouldn't the IP phone have to auithenticate then?

Regards,

Milan

Review Cisco Networking for a $25 gift card