Authenticating an IP phone when RADIUS does not return a VLAN assignment

An 802.1X-capable IP phone can be authenticated in a voice VLAN when the Remote Authentication Dial-In User Service (RADIUS) server does not return a VLAN assignment.
Prior to completing the following task, the RADIUS server must be configured and you must configure a profile for the IP phone (without configuring any attributes) on the RADIUS server.

Authenticating an IP phone when RADIUS does not return a VLAN assignment

The preceding figure shows a configuration in which an IP phone is connected to an ICX device that uses a RADIUS server for authentication. The following task shows how to configure the ICX device so that the IP phone is authenticated when RADIUS does not return a VLAN assignment.

  1. From privileged EXEC mode, enter global configuration mode.
    device# configure terminal
  2. Configure the device to use the configured RADIUS server to authenticate 802.1X and MAC authentication clients.
    device(config)# aaa authentication dot1x default radius 
    
  3. Configure a RADIUS server on the device.
    device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth 
    In this example, the IP address of the RADIUS server is 10.20.64.208 and the shared key specified for communication with the server is “secret”. The shared key must match the key specified during client configuration on the RADIUS server. UDP port 1812 is used for RADIUS authentication messages and UDP port 1813 is used for RADIUS accounting messages.
  4. Configure an auth-default VLAN.
    device(config)# vlan 2 name auth-default-vlan 
    device(config-vlan-2)# exit
    The auth-default VLAN must be configured to enable authentication. When a port is enabled for MAC authentication, by default it is moved into the auth-default VLAN as a MAC-based VLAN member. When the RADIUS server only authenticates the client and does not return a VLAN where the client should be placed, the client is placed in the auth-default VLAN. This example configures VLAN 2 as the auth-default VLAN and then returns to global configuration mode.
  5. Configure a voice VLAN.
    device(config)# vlan 200 name voice-vlan 
    device(config-vlan-200)# exit 
    
    An authentication-enabled port must be a tagged member of the voice VLAN prior to use by an IP phone for the voice calls. This example configures VLAN 200 as the voice VLAN and then returns to global configuration mode.
  6. Enter authentication configuration mode.
    device(config)# authentication 
    
  7. Specify the previously configured auth-default VLAN (VLAN 2) for authentication.
    device(config-authen)# auth-default-vlan 2
  8. Specify the previously configured default voice VLAN (VLAN 200) for authentication.
    device(config-authen)# voice-vlan 200
    Note: LLDP, with default MED policies (priority = 5 and dscp = 46), is automatically enabled on the port with voice VLAN.
  9. Enable 802.1X authentication on the device.
    device(config-authen)# dot1x enable 
  10. Enable 802.1X authentication on Ethernet interface 1/1/11.
    device(config-authen)# dot1x enable ethernet 1/1/11 
  11. Return to global configuration mode.
    device(config-authen)# exit
  12. Configure 802.1X authentication for the interface.
    device(config)# dot1x port-control auto ethernet 1/1/11
    
    Setting port-control to auto enables 802.1X authentication on the interface.
  13. Enable Power over Ethernet (PoE) on the interface.
    device(config)# interface ethernet 1/1/11
    device(config-if-e1000-1/1/11)# inline power  
    
  14. Return to privileged EXEC mode.
    device(config-if-e1000-1/1/11)# end
  15. Verify the configuration.
    device# show running-configuration authentication 
    
    authentication 
     auth-default-vlan 2 
     voice-vlan 200 
     dot1x enable 
     dot1x enable ethernet 1/1/11  
    

The following example shows the configuration of an ICX device to ensure that an IP phone (connected to Ethernet interface 1/1/11) is authenticated and placed in the voice VLAN when RADIUS does not return a VLAN assignment.

device# configure terminal

device(config)# aaa authentication dot1x default radius 
device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth 

device(config)# vlan 2 name auth-default-vlan 
device(config-vlan-2)# exit

device(config)# vlan 200 name voice-vlan 
device(config-vlan-200)# exit 

device(config)# authentication
device(config-authen)# auth-default-vlan 2 
device(config-authen)# voice-vlan 200
device(config-authen)# dot1x enable
device(config-authen)# dot1x enable ethernet 1/1/11 
device(config-authen)# exit

device(config)# dot1x port-control auto ethernet 1/1/11
device(config)# interface ethernet 1/1/11
device(config-if-e1000-1/1/11)# inline power  
device(config-if-e1000-1/1/11)# end