cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1740
Views
0
Helpful
5
Replies

IP Phones on a SDA network

ianjgrant
Level 1
Level 1

Hi.

 

Are there any guides on how best to handle voice services on a SDA network?  I have a PoC setup working nicely for data, with .1x auth on the switchports, but I'm struggling to understand how to add the IP phones into the mix, now that there will be two devices per switchport.

Is it best to use a separate VN, or is a separate IP Pool enough?  Any recommendations for authentication methods and identifying the phones?  In my particular case I need to handle two different types of phone system.

 

Thanks.

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

Most of the Enterprise that is standard setup, Phone - PC conencted to same port with 802.1x authentication.

 

Look below guide for Voice and Data

 

https://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/dna-center/guide-c07-741862.html

 

Still issue give more informaion, what DNAC version, ISE version, what Switch models with IOS Code running ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello BB

 

Thanks for your response, but which part of the linked document answers any of my queries? 

The document will give you full process, how you can create a VN . IP pools for Data and Voice and IOT devices, how you can integrate with ISE .

Create IP pool reservations for APs, campus, guest, multicast, IoT, and border handoff for a building

 

what part it was not clear ?

 

s it best to use a separate VN, or is a separate IP Pool enough?  Any recommendations for authentication methods and identifying the phones?  In my particular case I need to handle two different types of phone system.

Different phone in same Voice VLAN, ISE will identify the device based MAB (mac based authentication) ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I understand how to create all the component parts.  What I looking for is information the covers the voice aspects in more details. 

 

Nothing here explains what happens with two devices on the same switchport.  Or whether Voice devices should be put into a separate VN, or if that is even possible.

 

As for authentication of phones, MAB does not seem very secure, especially if they should be part of the Corporate network, so what are the Cisco recommendations, and the reasons behind the recommendation.

 

Nothing here explains what happens with two devices on the same switchport.  Or whether Voice devices should be put into a separate VN, or if that is even possible.

It all depends on your design, if you like to put each vendor to be different VN you can do, more admin task.

 

As for authentication of phones, MAB does not seem very secure, especially if they should be part of the Corporate network, so what are the Cisco recommendations, and the reasons behind the recommendation.

MAB is not a great - but that is the only Option available if the Phone do not have option to get Certificate installed in the device ?

 

so if you looking more secure, buy a Phones which has Certiificate authentication.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help