Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

New Member

LLDP - 802.1x Cisco - Nortel

Greetings,

We are currently trying to deploy LLDP for voice vlan assignment

and 802.1x for access control.

We are running Cat3560 running 12.2(46)SE.

Both features work independently:

-phone gets assigned appropriate voice

vlan via LLDP, obtains IP from DHCP and operates normally.

-PC successfully autenticates using dot1x or

gets assigned guest vlan if no dot1x configured.

When both features deployded simulaneously the phone hangs waiting for DHCP.

At this stage we do not want to deploy dot1x authentication for the phones as LLDP is working successfully (standalone).

Any thoughts on this?

3 REPLIES
New Member

Re: LLDP - 802.1x Cisco - Nortel

You might need to ignore / filter the mac of the IP phone in your auth server. I had this issue when I deployeed a simular solution. Auth server thinks the phone is a PC therefore won't let it access the voice VLAN.

Or is the phone in the correct Voice VLAN while waiting for DHCP?

Re: LLDP - 802.1x Cisco - Nortel

Hello Roman

When using IP phones with dot1x, you need to enable multi-domain authentication for both the devices to function properly.. you also need to enable the mac address of the IP phones to get authenticated through the external server. Posting an example here:

http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a00808abf2d.shtml

Hope this helps you.. rate replies if found useful..

Regards

Raj

New Member

Re: LLDP - 802.1x Cisco - Nortel

Thank You for your inputs guys.

What I am trying to accomplish is to have dot1x port capability for the desktops without the requirement of authentication (dot1x eap or mac-auth-bypass) for the IP phones. Currently I had automated IP phone assignment without the LLDP. This setup is working using 802.1x guest vlan and private dhcp options to redirect phones into voice vlan. I would like to eliminate the reliance on DHCP option fields (and requiring phone scope in guest vlan altogheter) and assign voice vlan using LLDP. From Cisco's LLDP documentation and its interaction 802.1x the LLDP only occurs after the 802.1x authentication. However in our case the clients do not get assigned either the guest-vlan or the voice vlan when LLDP and 802.1x is enabled. The port remains in un-authorised state. Form our testing LLDP decreases IP phone boot times significantly by providing less complex IP address/vlan assignment mechanism. So close yet so far...

1221
Views
0
Helpful
3
Replies
CreatePlease to create content