Red Hat NETWORK 4.1.0 - Guide de l'utilisateur Page 90

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 101
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 89
Chapter 14
Copyright © 2008-2013 Inverse inc.
More on VoIP Integration 86
Note
Not all vendors support VoIP on port-security, please refer to the Network Configuration
Guide.
Mac Authentication and 802.1X
Cisco hardware
On Cisco switches, we are looking at the multi-domain configuration. The multi-domain means that we
can have one device on the VOICE domain, and one device on the DATA domain. The domain assignment
is done using a Cisco VSA. When the phone connects to the switchport, PacketFence will respond with
the proper VSA only, no RADIUS tunneled attributes. CDP then tells the phone to tag its ethernet frames
using the configured voice VLAN on the port. When a PC connects, the RADIUS server will return tunneled
attributes, and the switch will place the port in the provided access VLAN.
Non-Cisco hardware
On other vendor hardware, it is possible to make VoIP work using RADIUS VSAs. When a phone connects
to a switchport, PacketFence needs to return the proper VSA to tell the switch to allow tagged frames
from this device. When the PC will connect, we will be able to return standard RADIUS tunnel attributes
to the switch, that will be the untagged VLAN.
Note
Again, refer to the Network Configuration Guide to see if VoIP is supported on your
switch hardware.
What if CDP/LLDP feature is missing
It is possible that your phone doesn’t support CDP or LLDP. If it’s the case, you are probably looking at
the "DHCP way" of provisionning your phone with a voice VLAN. Some models will ask for a specific DHCP
option so that the DHCP server can give the phone a voice VLAN id. The phone will then reboot, and tag
its ethernet frame using the provided VLAN tag.
In order to make this scenario work with PacketFence, you need to ensure that you tweak the registration
and your production DHCP server to provide the DHCP option. You also need to make sure there is a voice
VLAN properly configured on the port, and that you auto-register your IP Phones (On the first connect,
the phone will be assigned on the registration VLAN).
Vue de la page 89
1 2 ... 85 86 87 88 89 90 91 92 93 94 95 ... 100 101

Commentaires sur ces manuels

Pas de commentaire