Got it

Voice vlan with mac 802.1x order authentication on S5700-52P-LI

Latest reply: Aug 16, 2018 08:58:34 1746 2 0 0

PC  connects to IP phone  and they connect to the switch. 
For PC there is the need to use order of authentication.  Need firstly to check  mac-authen if fail then  dot1x.
For IP phone No auth at all. Phone must work even without PC.  No mac of phones added to Radius.

Voice vlan with mac 802.1x order authentication on S5700-52P-LI-1079871-1

 

  • x
  • convention:

Rickymoon
Created Mar 23, 2016 18:31:33 Helpful(0) Helpful(0)

Firstly we used recommended software version for S5700 --- V200R003C00SPC300.

This version suggests  mac-bypass function. But  if we made authentication by mac, and after it 802.1x become available process of re-authentication will begin. It  was not suitable for customer.
From Huawei product documentation

Voice vlan with mac 802.1x order authentication on S5700-52P-LI-1171075-1

Comparing with Cxx manufacturer  switches: Cxx manufacturer may act as both Case 1 and Case 2. Huawei can act only like Case 2, when using V200R003C00SPC300 version.

Voice vlan with mac 802.1x order authentication on S5700-52P-LI-1171075-2

We tested S5700-52P-PWR-LI-AC.  At  V200R006C00SPC500 release we can config like Case 1.  Following commands appear.  Unified Mode has been realesed.
[interface view] authentication  mac-authen dot1x
                               authentication single-access


At  V200R007C00SPC500  version command authentication device-type voice authorize appeared.  It helps not to use authentication for VoIP phones at all.

So for desired auth scheme we advised customer to use V200R007C00SPC500 with Unified Mode NAC.

View more
  • x
  • convention:

SafarovSH
Created Aug 16, 2018 08:58:34 Helpful(0) Helpful(0)

Posted by Rickymoon at 2016-03-23 18:31 Firstly we used recommended software version for S5700 --- V200R003C00SPC300. This version suggest ...
As I understand, with authentication device-type voice authorize command all IP Phones will be automatically authorized, but how to accomplish if I want to allow only particular group of IP Phones, which belong to the Company?
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits

Login

Huawei Enterprise Support Community
Huawei Enterprise Support Community
Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.