Thanks for your help on this. I noticed it started after updating to 3.0.1.
The strange thing is that these phones are not new phones they have been
registered in Packetfence for ages and when I go look at the node I see them
there and they are in the PHONE Category.
Just thought of a question. How does packetfence know the category I created
called PHONE, belongs on the voice vlan. Maybe that is it. Maybe I missed
something in the set.
On 11/10/11 10:04 AM, Dan Nelson wrote:
> Sorry, I am not explaining myself and after reading my initial post I
> can see the confusion. The phones are getting the correct VLAN (yes we
> are using the DHCP codes 128). That portion is and has been working for
> about 2 years now. When a new phone comes online, packetfence will
> register the phone mac on the access vlan, in other words it will push
> the ?switchport port-security mac address 0800.0fxx.xxxx? and It
> should/used to just allow it to go through without any issue. If
> anything I think packetfence should be sending the ?switchport
> port-security mac address 0800.0fxx.xxxx vlan voice? command.
>
It was working before and now it is not working because of ?
VoIP is tricky business, on the first authorization, PacketFence doesn't
know it's a voice device yet (it never did dhcp and we do CDP only after
access I think) so it authorizes it the best it can. Sometimes the best
to do is to have a 'provisioning cycle' where you plug the devices and
have them recorded as voip then send the devices in the field where they
will be correctly put in the right VLAN since they'll already be known
to pf. But then again that's all guesswork, maybe you found a new cisco
or pf issue..
What version are you running? What changed since it was working? Maybe a
ticket would be more appropriate for this as it is going to be a tricky
road (http://packetfence.org/bugs/).
Have a good one!
--
Olivier Bilodeau
[email protected]<mailto:[email protected]> :: +1.514.447.4918 *115 ::
www.inverse.ca<http://www.inverse.ca>
Inverse inc. :: Leaders behind SOGo (www.sogo.nu<http://www.sogo.nu>) and
PacketFence
(www.packetfence.org<http://www.packetfence.org>)
Thanks
Dan Nelson
Nutraceutical Corporation
Network Administrator
801-334-3702
------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a
definitive record of customers, application performance, security
threats, fraudulent activity and more. Splunk takes this data and makes
sense of it. Business sense. IT sense. Common sense.
http://p.sf.net/sfu/splunk-d2d-oct
_______________________________________________
Packetfence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users