The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
If you both want to not trust an attached PC (vlan 501?) but want to trust a VoIP phone (vlan 601), you could configure the port to use a vlan based policy, then not trust anything on vlan 501, and trust typical VoIP markings on vlan 601.
Or, you might have port policy that accepts just VoIP markings but with a rate-limiter for those markings (about 128 Kbps for bearer and maybe about 32 Kbps for signaling).