Dynamically advertising an authorization VLAN through LLDP or CDP

This function is available only on IP phones that support LLDP or CDP.

Dynamic authorization VLAN advertisement through LLDP or CDP works with 802.1X or MAC authentication. If 802.1X authentication is used, make sure the IP phone support 802.1X authentication.

After the IP phone passes authentication, LLDP advertises the authorization VLAN in the LLDP-MED Network Policy TLV to the IP phone. If the IP phone supports only CDP, CDP advertises the authorization VLAN in CDP packets to the IP phone. The port connected to the IP phone will be added to the authorization VLAN.

To implement this function, perform the following configuration tasks:

  1. Enable LLDP globally and on the port connected to the IP phone.

    If the IP phone supports only CDP, configure CDP compatibility on the device.

  2. Configure 802.1X or MAC authentication to ensure that the IP phone can pass security authentication. For more information about 802.1X and MAC authentication, see Security Configuration Guide.

  3. Configure the authorization VLAN for the IP phone on the authentication server. For more information about authorization VLANs, see Security Configuration Guide.