cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2914
Views
5
Helpful
13
Replies

Cdp disabled, IP phone get data vlan IP address, need your support to fix the issue

sjd2020
Level 1
Level 1

Dears, 
IN switch interface level I disable cdp for security practice. after that my IP phone get data vlan IP address, then I set manually Voice vlan in IP phone in admin vlan id option, it took voice vlan IP,
Now this activity I can’t perform for 500 + users, so need a solution to fix the issue, 
I tried lldp -med also I face same, looking for experts response. 

Thanks.

1 Accepted Solution

Accepted Solutions

Leo Laohoo
Hall of Fame
Hall of Fame
If you plug a computer a port with the voice VLAN as the data VLAN, does the computer get an IP address?

View solution in original post

13 Replies 13

Leo Laohoo
Hall of Fame
Hall of Fame
If you plug a computer a port with the voice VLAN as the data VLAN, does the computer get an IP address?

Yes its PC getting Data vlan IP address(Through DHCP), and IP phone also getting data vlan IP address.

balaji.bandi
Hall of Fame
Hall of Fame

Tell us more about device information and code running in it.

 

have you set the port in trunk mode ? 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Device Model  C3560 & WS-C3560G-24PS
Device IOS : IOS12.2(55)SE12
 
Configuration perform below commands,
config t
Int gi0/5
no cdp enable
end
--------------
Ip phone cp 8945.
 
Please let me more details from my end

what is the interface config ? post below output :

 

show vlan

show run Int gi0/5

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Sh vlan

15 Data-SW3 active Gi0/2, Gi0/5, Gi0/7, Gi0/8
Gi0/10, Gi0/11, Gi0/13, Gi0/14
Gi0/15, Gi0/17, Gi0/18, Gi0/20
Gi0/21, Gi0/22, Gi0/24

16 Voice-SW3 active Gi0/2, Gi0/3, Gi0/21, Gi0/6

 

SW3#show run Int gi0/5
Building configuration...

Current configuration : 185 bytes
!
interface GigabitEthernet0/5
switchport access vlan 15
switchport mode access
switchport voice vlan 16
no cdp enable
spanning-tree portfast
spanning-tree bpduguard enable
end

Dan Lukes
VIP Alumni
VIP Alumni

To verify I understood the issue correctly - you faced no issue configuring the first phone. You just wish avoid manual configurations of voice vlan id for thousands phones and CDP and LLDP is not acceptable for you. Am I true ?

  • Absolutely Right Dan Lukes,  How could i do this for 500 + users its not acceptable.
  • Even some IP phones are in 'Register IP phone' mode display , look like searching for ip. Even in our company some of IP phones are 7900 series , in this model manually i cant able to add admin vlan id.
  • So many things here.. so without cdp IP phones  have issues.
           


@sjd2020 wrote:
  • Absolutely Right Dan Lukes,  How could i do this for 500 + users its not acceptable.

What CDP security vulnerability are you trying to avoid?

Someone is overreacting.  Did anyone attempted to read (and understand) the Security Advisory?

What is the model of the switch we are talking about?

Judging from the output, I know what switch this is but I want to hear it. 

You are in Small Business area and you mentioned no models of phone we are speaking of, thus I assumed SMB product line - e.g. SPA3xx or SPA5xx. I have no experience with 7900 - my advice may or may not apply to them.

 

Virgin phone starts in data vlan asking network configuration from DHCP.

Configure DHCP server (the one running in data vlan) to respond with IP address and option 150 (tftp server with phone configuration) OR option 160 (https url with phone configuration). The configuration is static file/configuration (neither per-phone configuration nor dynamic configuration generated on the fly by script is necessary). You can place it on a TFTP/HTTP server accessible from data vlan. Configuration contains no sensitive information, so it need not to be secured. It configures just VLAN ID(following example assimes it's 123):

 

<flat-profile>

<VLAN_ID ua="na">123</VLAN_ID>

</flat-profile>

 New configuration causes phone reboot - but phone have vlan id configured now, so it starts into voice vlan. It will fetch IP address and configuration as usual.

 

 

Hello Mr Dan lukes,

What you want to say in short your not using Cisco, virigin and you configure as a Data vlan and for voice option 150 or 160 tftp  or https  for ip phones, and phones reboot and work properly with 123 vlan id, 
ok here i need some details what is your voice vlan id and data vlan id ... that i want to know?

 

looking for your response.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Switch products supported in this community
Cisco Business Product Family
  • CBS110
  • CBS220
  • CBS250
  • CBS350
Cisco Switching Product Family
  • 110
  • 200
  • 220
  • 250
  • 300
  • 350
  • 350X
  • 550X