Voice VLAN Requirements for Flexible Authentication

Voice VLAN configuration facilitates the continued functioning of Voice over IP (VoIP) phones when external server authentication or authorization fails.

A voice VLAN is configured at the global level (using the voice-vlan command in authentication configuration mode) or at the local level (using the authentication voice-vlan command in interface configuration mode).

When a local voice VLAN is configured, it overrides the global voice VLAN configuration. The global voice VLAN is used only when a voice VLAN is not configured on the port.

A voice VLAN is used for voice communication by IP phones in the following ways:

  • Authentication Success: When a RADIUS server authenticates an IP phone and the server does not specify a VLAN, the device is placed in the auth-default VLAN and also added to the voice VLAN (as a tagged member). The auth-default VLAN is used for initial authentication, learning the IP address, and so on, while the voice VLAN is used for voice traffic.
  • Authentication Failure: When a phone fails authentication by a RADIUS server, the phone is blocked in hardware by default. To ensure that an IP phone continues to operate and that both data and voice traffic from the IP phone are appropriately forwarded, use the auth-fail-action command to set the fail action to restricted-vlan, and specify the voice voice-vlan option. This causes the device to be placed in the restricted VLAN for data traffic and the voice VLAN (as a tagged member) for voice traffic.
  • Authentication Timeout: When a RADIUS server is not reachable, the phone cannot be authenticated, in which case several timeout-action options are available: treat as success, treat as failure, and treat as critical. Success and Failure cases work as explained previously. The critical-VLAN case works in a similar way to the restricted-VLAN case. To ensure that an IP phone continues to operate and that both data and voice traffic from the IP phone are appropriately forwarded, use the auth-timeout-action command to set the timeout action to critical-vlan, and specify the voice voice-vlan option. This causes the device to be placed in the critical VLAN for data traffic and the voice VLAN (as a tagged member) for voice traffic.

Note: RUCKUS recommends that you configure authentication voice vlan only when lldp med network-policy is not configured on an interface.

If present, authentication voice VLAN configuration takes precedence over LLDP-MED voice VLAN configuration. The following example includes voice VLAN configuration.

device# show running-config auth
Current configuration for flexauth:
  authentication
  auth-default-vlan 596
  voice-vlan 100 <--- Voice VLAN configured for authentication
mac-authentication enable
  mac-authentication enable ethernet 8/1/41

The following example shows incompatible LLDP-MED voice VLAN configuration for the same interface.

lldp med network-policy application voice tagged vlan 100  priority 3 dscp 34 ports ethernet 8/1/41