Authenticating an IP phone when RADIUS fails or times out

An IP phone can be authenticated in a voice VLAN using MAC authentication when the Remote Authentication Dial-In User Service (RADIUS) server fails or times out.

Prior to completing the following task, the RADIUS server must be configured and you must create a profile for the IP phone on the RADIUS server with the attributes shown in the following table.

RADIUS server attributes for an IP phone

Attribute Value Comment
Tunnel-Medium-Type 802
Tunnel-Pvt-Group-ID T:200 The format is T:<Voice-VLAN-id>
Tunnel-Type VLAN
Foundry-Voice-Phone-Config “ “ dscp:46, priority:5 are LLDP advertised

Authenticating an IP phone when RADIUS fails or times out

The preceding figure shows a configuration in which an IP phone is connected to an ICX device that uses a RADIUS server for authentication. The following task shows how to configure the ICX device to authenticate the IP phone using MAC authentication in a voice VLAN when RADIUS fails or times out.

  1. From privileged EXEC mode, enter global configuration mode.
    device# configure terminal
  2. Configure a RADIUS server on the device.
    device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth 
    In this example, the IP address of the RADIUS server is 10.20.64.208 and the shared key specified for communication with the server is “secret”. The shared key must match the key specified during client configuration on the RADIUS server. UDP port 1812 is used for RADIUS authentication messages and UDP port 1813 is used for RADIUS accounting messages.
  3. Configure an auth-default VLAN.
    device(config)# vlan 2 name auth-default-vlan 
    device(config-vlan-2)# exit
    The auth-default VLAN must be configured to enable authentication. When a port is enabled for MAC authentication, by default it is moved into the auth-default VLAN as a MAC-based VLAN member. When the RADIUS server only authenticates the client and does not return a VLAN where the client should be placed, the client is placed in the auth-default VLAN. This example configures VLAN 2 as the auth-default VLAN and then returns to global configuration mode.
  4. Configure a voice VLAN.
    device(config)# vlan 200 name voice-vlan 
    device(config-vlan-200)# exit 
    
    An authentication-enabled port must be a tagged member of the voice VLAN prior to use by an IP phone for the voice calls. This example configures VLAN 200 as the voice VLAN and then returns to global configuration mode.
  5. Enter authentication configuration mode.
    device(config)# authentication
    device(config-authen)# 
    
  6. Specify the previously configured auth-default VLAN (VLAN 2) for authentication.
    device(config-authen)# auth-default-vlan 2
  7. Specify the previously configured default voice VLAN (VLAN 200) for authentication.
    device(config-authen)# voice-vlan 200
    Is the following note correct for this step?
    Note: LLDP, with default MED policies (priority = 5 and dscp = 46), is automatically enabled on the port with voice VLAN.
  8. Specify the critical VLAN ID used for authentication.
    device(config-authen)# critical-vlan 20 
    
  9. Note: The auth-timeout-action command takes effect only when flexible authentication is enabled on the ports. Therefore, flexible authentication must be enabled on ports prior to configuring the RADIUS timeout action. The RADIUS timeout action must also be reconfigured after a change to the flexible authentication status of a port.
    Configure the RADIUS timeout action.
    device(config-authen)# auth-timeout-action critical-vlan voice voice-vlan 
    
    In this example, when RADIUS is not reachable, data devices are moved to the critical VLAN and voice devices to the voice VLAN.
  10. Specify the restricted VLAN ID used for authentication.
    device(config-authen)# restricted-vlan 4 
    
  11. Note: The auth-fail-action command takes effect only when flexible authentication is enabled on the ports. Therefore, flexible authentication must be enabled on ports prior to configuring the authentication failure action. The authentication failure action must also be reconfigured after a change to the flexible authentication status of a port.
    Configure the RADIUS failure action.
    device(config-authen)# auth-fail-action restricted-vlan voice voice-vlan
    In this example, when RADIUS fails to authenticate the client, data devices are moved to the restricted VLAN and voice devices are moved to the voice VLAN.
  12. Enable MAC authentication on the device.
    device(config-authen)# mac-authentication enable 
  13. Enable MAC authentication on Ethernet interface 1/1/11.
    device(config-authen)# mac-authentication enable ethernet 1/1/11 
  14. Return to global configuration mode.
    device(config-authen)# exit
  15. Enter interface configuration mode for Ethernet interface 1/1/11.
    device(config)# interface ethernet 1/1/11 
  16. Enable Power over Ethernet (PoE) on the interface.
    device(config-if-e1000-1/1/11)# inline power  
    
  17. Return to privileged EXEC mode.
    device(config-if-e1000-1/1/11)# end
  18. Verify the configuration.
    device# show running-config authentication 
    
    authentication 
     auth-default-vlan 2 
     voice-vlan 200 
     critical-vlan 20
     auth-timeout-action critical-vlan voice voice-vlan 
     restricted-vlan 4
     auth-fail-action restricted-vlan voice voice-vlan 
     mac-authentication enable 
     mac-authentication enable ethernet 1/1/11  
    

The following example shows how to configure an ICX device to authenticate the IP phone using MAC authentication in a voice VLAN when RADIUS fails or times out.

device# configure terminal

device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth

device(config)# vlan 2 name auth-default-vlan 
device(config-vlan-2)# exit

device(config)# vlan 200 name voice-vlan 
device(config-vlan-200)# exit 

device(config)# authentication
device(config-authen)# auth-default-vlan 2
device(config-authen)# voice-vlan 200
device(config-authen)# critical-vlan 20
device(config-authen)# auth-timeout-action critical-vlan voice voice-vlan
device(config-authen)# restricted-vlan 4
device(config-authen)# auth-fail-action restricted-vlan voice voice-vlan
device(config-authen)# mac-authentication enable 
device(config-authen)# mac-authentication enable ethernet 1/1/11
device(config-authen)# exit

device(config)# interface ethernet 1/1/11
device(config-if-e1000-1/1/11)# inline power
device(config-if-e1000-1/1/11)# end