03-04-2008 11:31 AM - edited 03-09-2019 08:14 PM
When a phone is on the voice vlan packet destined for it should have a 802.1q tag with a VLAN ID of the voice vlan.
Does the EAP packet (for the phone) have an 802.1q vlan header when using 802.1X MDA? What about re-authentication packets?
The RFC says VLAN tagging is not supported but it was not written with MDA in mind.
03-10-2008 01:55 PM
You can add MAC address on ACS for MAB with asterix *. ---> This immediately allows you to get the IP-phones added to the
voice-VLAN. guess its not possible, that a "2-VLAN-trunk" between the ATA186 and the switch is getting build up. Exactly for all those devices MDA has been developed.
03-10-2008 02:01 PM
EAPOL frames are not tagged. It wouldn't matter what vlan a device thinks it should be on. If the switch has not authenticated it, it wouldn't know it's a phone (yet) anyway.
EAPOL is sent to the specific MAC address of the device for ports enabled for MDA. This includes re-auth frames.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide