Voice VLAN Requirements for Flexible Authentication
A voice VLAN is configured at the global level (using the
voice-vlan command in authentication configuration mode) or at the local level (using the
authentication voice-vlan command in interface configuration mode).
When a local voice VLAN is configured, it overrides the global voice VLAN configuration. The global voice VLAN is used only when a voice VLAN is not configured on the port.
A voice VLAN is used for voice communication by IP phones in the following ways:
- Authentication Success: When a RADIUS server authenticates an IP phone and the server does not specify a VLAN, the device is placed in the auth-default VLAN and also added to the voice VLAN (as a tagged member). The auth-default VLAN is used for initial authentication, learning the IP address, and so on, while the voice VLAN is used for voice traffic.
- Authentication Failure: When a phone fails authentication by a RADIUS server, the
phone is blocked in hardware by default. To ensure that an IP phone continues to operate
and that both data and voice traffic from the IP phone are appropriately forwarded,
use the
auth-fail-actioncommand to set the fail action torestricted-vlan, and specify thevoice voice-vlanoption. This causes the device to be placed in the restricted VLAN for data traffic and the voice VLAN (as a tagged member) for voice traffic. - Authentication Timeout: When a RADIUS server is not
reachable, the phone cannot be authenticated, in which case several
timeout-action options are available: treat as success, treat as failure, and
treat as critical. Success and Failure cases work as explained previously. The
critical-VLAN case works in a similar way to the restricted-VLAN case. To ensure
that an IP phone continues to operate and that both data and voice traffic from
the IP phone are appropriately forwarded, use the
auth-timeout-actioncommand to set the timeout action tocritical-vlan, and specify thevoice voice-vlanoption. This causes the device to be placed in the critical VLAN for data traffic and the voice VLAN (as a tagged member) for voice traffic.
authentication voice
vlan only when lldp med network-policy is not configured on an interface.If present, authentication voice VLAN configuration takes precedence over LLDP-MED voice VLAN configuration. The following example includes voice VLAN configuration.
device# show running-config auth Current configuration for flexauth: authentication auth-default-vlan 596 voice-vlan 100 <--- Voice VLAN configured for authentication mac-authentication enable mac-authentication enable ethernet 8/1/41
The following example shows incompatible LLDP-MED voice VLAN configuration for the same interface.
lldp med network-policy application voice tagged vlan 100 priority 3 dscp 34 ports ethernet 8/1/41