cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1213
Views
0
Helpful
2
Replies

Cisco Switch - Allow VoIP Disable ACCESS

TomTinsley
Level 1
Level 1

We have a situation where some switchports are in a public area with Cisco IP Phones connected.  We want to disable the ACCESS VLAN but allow the VOICE.  Is it best practice to just remove the 'switchport mode access' command?                  

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

That's one good step along the way.

If you really want to lock it down further use port-security and restrict the allowed MAC address to the single phone connected on a given port. That will put the port into err-disable if anything else is even plugged into it.

Otherwise someone could put their machine up on the phone VLAN, give themselves a static IP that the phone they displaced had gotten via DHCP, and possibly navigate around your network that way.

More advanced solutions would be use of 802.1x and/or ISE but that requires investment in products and significant configuration steps.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

That's one good step along the way.

If you really want to lock it down further use port-security and restrict the allowed MAC address to the single phone connected on a given port. That will put the port into err-disable if anything else is even plugged into it.

Otherwise someone could put their machine up on the phone VLAN, give themselves a static IP that the phone they displaced had gotten via DHCP, and possibly navigate around your network that way.

More advanced solutions would be use of 802.1x and/or ISE but that requires investment in products and significant configuration steps.

Good idea, I will also add port security.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: