04-15-2021 02:45 AM
Hi.
Are there any guides on how best to handle voice services on a SDA network? I have a PoC setup working nicely for data, with .1x auth on the switchports, but I'm struggling to understand how to add the IP phones into the mix, now that there will be two devices per switchport.
Is it best to use a separate VN, or is a separate IP Pool enough? Any recommendations for authentication methods and identifying the phones? In my particular case I need to handle two different types of phone system.
Thanks.
04-15-2021 03:02 AM
Most of the Enterprise that is standard setup, Phone - PC conencted to same port with 802.1x authentication.
Look below guide for Voice and Data
Still issue give more informaion, what DNAC version, ISE version, what Switch models with IOS Code running ?
04-19-2021 03:40 AM
Hello BB
Thanks for your response, but which part of the linked document answers any of my queries?
04-19-2021 04:29 AM
The document will give you full process, how you can create a VN . IP pools for Data and Voice and IOT devices, how you can integrate with ISE .
Create IP pool reservations for APs, campus, guest, multicast, IoT, and border handoff for a building
what part it was not clear ?
s it best to use a separate VN, or is a separate IP Pool enough? Any recommendations for authentication methods and identifying the phones? In my particular case I need to handle two different types of phone system.
Different phone in same Voice VLAN, ISE will identify the device based MAB (mac based authentication) ?
04-20-2021 03:14 AM
I understand how to create all the component parts. What I looking for is information the covers the voice aspects in more details.
Nothing here explains what happens with two devices on the same switchport. Or whether Voice devices should be put into a separate VN, or if that is even possible.
As for authentication of phones, MAB does not seem very secure, especially if they should be part of the Corporate network, so what are the Cisco recommendations, and the reasons behind the recommendation.
04-20-2021 04:46 AM
Nothing here explains what happens with two devices on the same switchport. Or whether Voice devices should be put into a separate VN, or if that is even possible.
It all depends on your design, if you like to put each vendor to be different VN you can do, more admin task.
As for authentication of phones, MAB does not seem very secure, especially if they should be part of the Corporate network, so what are the Cisco recommendations, and the reasons behind the recommendation.
MAB is not a great - but that is the only Option available if the Phone do not have option to get Certificate installed in the device ?
so if you looking more secure, buy a Phones which has Certiificate authentication.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide