Users Guide

Table Of Contents
788 VLANs
If no RADIUS server is reachable, newly authenticating voice devices, i.e.,
devices just powered on or connected to the network, are denied access to the
Voice VLAN. The phone will be authenticated and allowed access to the
Voice VLAN when a RADIUS server becomes reachable. Configuring a
RADIUS server with a deadtime of 0 (default) effectively disables features
such as critical Voice VLAN as the configured server is always marked live.
Use the authentication event server dead action authorize voice command
to enable critical Voice VLAN treatment on an interface. A non-zero dead
time must be configured on all RADIUS servers for the servers to be marked
dead so a device can be placed into the critical Voice VLAN.
Critical Voice VLAN is also supported for 802.1X unaware clients by using
MAB. Additionally, the switchport voice vlan override-authentication
command may be used to configure 802.1X unaware IP phones in 802.1X port
based mode.
Voice VLAN Restrictions
The switch enforces the following restrictions regarding Voice VLAN:
Multiple VLANs may be configured as voice VLANs on the switch, but
only one voice VLAN may be configured on any given interface.
A voice VLAN may not be configured as a PVID. The switch enforces this
restriction by not configuring the voice VLAN if the VLAN is the PVID of
any port, or by failing the PVID assignment if the VLAN is a voice VLAN.
This prevents operator misconfiguration which allows DoS attacks on the
data VLAN to disrupt voice traffic.
A voice VLAN may not be configured as the unauthenticated VLAN and
vice-versa. This prevents operator misconfiguration which allows DoS
attacks on the unauthenticated VLAN to disrupt the voice traffic.
A voice VLAN may not be configured as the guest VLAN and vice-versa.
This prevents operator misconfiguration which allows DoS attacks on the
guest VLAN to disrupt the voice traffic.
A voice VLAN may not be configured as a private VLAN host port. This
prevents interference between the internal Private VLAN and Voice VLAN
treatment of packets.