- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Polycom IP Phone Bypass Vlan Voices Access Policies
Hello everyone,
we want to implement these configuration, for this kind of topology below :
MS Switch - IP Phone - Desktop Endpoint
with a detailed behavior below :
- Create Access Policies to authenticate endpoint only(data vlan) and bypass IP Phone (voice vlan)
- IP Phone will be connected to MS Switch port
- Endpoint will connected to IP Phone
we have already configured Hybrid Authentication + Multi Auth with bypass Voice Vlan Auth
But it's seems the MAB didn't bypass voice vlan of our Polycom VOIP devices as captured below :
our goals are :
- Polycom IP Phone still granted access by using bypassed Voice VLAN, even there are no connected desktop endpoint behind it
- When user try connected via IP Phone, the user required to authenticate to our RADIUS server to granted access
hopefully hear from you all soon
cheers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not sure if that voice auth checkbox means you can just have a phone on the port without authenticating. I believe it is to signal that you have a phone possibility on the port and can have the Radius attribute sent for voice domain authorization.
The documentation also says in most host modes every client needs to be authenticated including the phone.
If your radius server supports MAB you could just have the MAC addresses of the phones in there to authenticate against.
