Authenticating an IP phone when RADIUS does not return a VLAN assignment
Authenticating an IP phone when RADIUS does not return a VLAN assignment

The preceding figure shows a configuration in which an IP phone is connected to an ICX device that uses a RADIUS server for authentication. The following task shows how to configure the ICX device so that the IP phone is authenticated when RADIUS does not return a VLAN assignment.
- From privileged EXEC mode, enter global configuration mode.
- Configure the device to use the configured RADIUS server to authenticate 802.1X and MAC authentication clients.
- Configure a RADIUS server on the device.
device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth
In this example, the IP address of the RADIUS server is 10.20.64.208 and the shared key specified for communication with the server is “secret”. The shared key must match the key specified during client configuration on the RADIUS server. UDP port 1812 is used for RADIUS authentication messages and UDP port 1813 is used for RADIUS accounting messages. - Configure an auth-default VLAN.
The auth-default VLAN must be configured to enable authentication. When a port is enabled for MAC authentication, by default it is moved into the auth-default VLAN as a MAC-based VLAN member. When the RADIUS server only authenticates the client and does not return a VLAN where the client should be placed, the client is placed in the auth-default VLAN. This example configures VLAN 2 as the auth-default VLAN and then returns to global configuration mode.
- Configure a voice VLAN.
An authentication-enabled port must be a tagged member of the voice VLAN prior to use by an IP phone for the voice calls. This example configures VLAN 200 as the voice VLAN and then returns to global configuration mode.
- Enter authentication configuration mode.
- Specify the previously configured auth-default VLAN (VLAN 2) for authentication.
- Specify the previously configured default voice VLAN (VLAN 200) for authentication.
Note: LLDP, with default MED policies (priority = 5 and dscp = 46), is automatically enabled on the port with voice VLAN.
- Enable 802.1X authentication on the device.
- Enable 802.1X authentication on Ethernet interface 1/1/11.
- Return to global configuration mode.
- Configure 802.1X authentication for the interface.
- Enable Power over Ethernet (PoE) on the interface.
- Return to privileged EXEC mode.
- Verify the configuration.
The following example shows the configuration of an ICX device to ensure that an IP phone (connected to Ethernet interface 1/1/11) is authenticated and placed in the voice VLAN when RADIUS does not return a VLAN assignment.
device# configure terminal device(config)# aaa authentication dot1x default radius device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth device(config)# vlan 2 name auth-default-vlan device(config-vlan-2)# exit device(config)# vlan 200 name voice-vlan device(config-vlan-200)# exit device(config)# authentication device(config-authen)# auth-default-vlan 2 device(config-authen)# voice-vlan 200 device(config-authen)# dot1x enable device(config-authen)# dot1x enable ethernet 1/1/11 device(config-authen)# exit device(config)# dot1x port-control auto ethernet 1/1/11 device(config)# interface ethernet 1/1/11 device(config-if-e1000-1/1/11)# inline power device(config-if-e1000-1/1/11)# end