Hi, we are currently testing the MAC adress authentication feature of the IC series. We have IC-4000, Cisco switches and a Cisco phone. What we want to do is to connect an endpoint to a phone, and the phone to the switch. The phone voice traffic should go to a specific VLAN and the data from the PC connected to the phone should be sent to a different VLAN, depending on the success of 802.1x authentication and the assigned roles depending on the host checker compliance, etc. The switch port is 802.1x enabled and switchport voice vlan is set to 3. On the IC Newtork Access > Radius Attributes, we've set a new policy por VoIP phones: VLAN = 3 Return Attribute: tunnel-type 13 tunnel-medium-type 6 tunnel-private-group-id 3 This configuration is currently working for other VLANs where 802.1x endpoints are being connected directly to the switch with or without Oddyssey Access Client The problem is that although the IC seems to be assigning VLAN = 3 to the phone and its corresponding role, and VLAN = 30 to the endpoint connected to the phone, and its corresponding role, (checked this on Log/Monitoring > User Access) the switch's interface keeps showing the native access VLAN, which in this case, is = 1. I've been checking Cisco forums for switch configuration and everything seems to be ok so I wonder if there is any parameter I'm missing on the IC configuration. Thanks, Gorka.
... View more