Dell PowerConnect 6248 Configuration Guide - Page 39

Example #2: Configuring Voice VLAN on an Unauthenticated Port

Page 39 highlights

Example #2: Configuring Voice VLAN on an Unauthenticated Port In some networks, multiple devices (for example, a PC, Printer, and phone) are connected to a single port on the switch. The PCs and printers are authenticated by 802.1X, but the phone might not support 802.1X authentication. The PowerConnect 6200 Series switches can allow unauthenticated traffic on the Voice VLAN for the phones that do not support authentication while requiring all other devices on the port to authenticate individually. The phones that do not support 802.1X authentication are automatically directed to the Voice VLAN without manual configuration. The phones will obtain this information using one of the following methods: • LLDP-MED • CDP • DHCP In this example, interface 1/g10 is set to an 802.1Q VLAN. The port must be in general mode in order to enable MAC-based 802.1X authentication. Then, port 1/g10 is configured with MAC-based port authentication to allow authentication for multiple hosts on the same port (see "Example #2: MACBased Authentication Mode" on page 108 for more information). Next, Voice VLAN is enabled on the port with the Voice VLAN ID set to 25. Finally, Voice VLAN authentication is disabled on port 1/g10 because the phone connected to that port does not support 802.1X authentication. All other devices are required to use 802.1X authentication for network access. Support for unauthenticated Voice VLANs is available in release 2.1 and later versions. console#configure console(config)#interface ethernet 1/g10 console(config-if-1/g10)#switchport mode general console(config-if-1/g10)#dot1x port-control mac-based console(config-if-1/g10)#voice vlan 25 console(config-if-1/g10)#voice vlan auth disable console(config-if-1/g10)# console#show voice vlan interface 1/g10 Interface 1/g10 Voice VLAN Interface Mode Enabled Voice VLAN ID 25 Voice VLAN COS Override False Voice VLAN Port Status Disabled Voice VLAN Authentication Disabled Switching Configuration 39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

Switching Configuration
39
Example #2: Configuring Voice VLAN on an Unauthenticated Port
In some networks, multiple devices (for example, a PC, Printer, and phone) are connected to a single port
on the switch. The PCs and printers are authenticated by 802.1X, but the phone might not support
802.1X authentication. The PowerConnect 6200 Series switches can allow unauthenticated traffic on the
Voice VLAN for the phones that do not support authentication while requiring all other devices on the
port to authenticate individually.
The phones that do not support 802.1X authentication are automatically directed to the Voice VLAN
without manual configuration. The phones will obtain this information using one of the following
methods:
LLDP-MED
CDP
DHCP
In this example, interface 1/g10 is set to an 802.1Q VLAN. The port must be in general mode in order to
enable MAC-based 802.1X authentication. Then, port 1/g10 is configured with MAC-based port
authentication to allow authentication for multiple hosts on the same port (see "Example #2: MAC-
Based Authentication Mode" on page 108 for more information). Next, Voice VLAN is enabled on the
port with the Voice VLAN ID set to 25. Finally, Voice VLAN authentication is disabled on port 1/g10
because the phone connected to that port does not support 802.1X authentication. All other devices are
required to use 802.1X authentication for network access.
Support for unauthenticated Voice VLANs is available in release 2.1 and later versions.
console#configure
console(config)#interface ethernet 1/g10
console(config-if-1/g10)#switchport mode general
console(config-if-1/g10)#dot1x port-control mac-based
console(config-if-1/g10)#voice vlan 25
console(config-if-1/g10)#voice vlan auth disable
console(config-if-1/g10)#<CTRL+Z>
console#show voice vlan interface 1/g10
Interface
......................................
1/g10
Voice VLAN Interface Mode
......................
Enabled
Voice VLAN ID
..................................
25
Voice VLAN COS Override
........................
False
Voice VLAN Port Status
.........................
Disabled
Voice VLAN Authentication
......................
Disabled