Engineering Guidelines
258
compatible with the Auxiliary_VLAN setting in CDP can be used with another attached device,
such as a PC. An IP phone that cannot determine the Auxiliary_VLAN setting will be treated
as a single end device, and require an entry in the VMPS database.
When the VMPS (Server) is enabled, a MAC address to VLAN mapping database is downloaded
from a TFTP server and VMPS begins to accept client (access switch) requests. When a valid
request from a client is received, the VMPS searches through the database for a MAC address
to VLAN mapping. The VMPS will then instruct the client how to configure the port for access
and also which VLAN to enable.
Access can be restricted to certain ports, and it can be denied for certain MAC addresses (e.g.
a known attacker). In either of these cases, the ports can also be configured to simply deny
access, or they can be physically shut down. Re-enabling a shutdown port,
no shutdown,
requires configuration access to the network switch of the affected port, for example, via the
serial interface or Telnet.
A
fallback
VLAN can also be defined for devices that are unknown, but that may be granted
limited access, for example, to a guest VLAN. Access to the remainder of the network will then
be controlled through the VLAN router. An example may be a hotel room with Internet access
where unknown guest devices will connect to the network.
Some other rules that apply to configuration of VMPS include:
•
A dynamic port can belong to only one VLAN
(that is, one device per port, or common
group of devices per port. Note: The number of attached devices differs by switch product.
•
The VMPS must be configured
before
the access ports are enabled as dynamic.
•
When a port is configured as dynamic, spanning-tree Portfast is enabled automatically for
that port. Automatic enabling of spanning tree Portfast prevents applications on the host
from timing out and entering loops caused by incorrect configurations. You
can
disable
spanning-tree PortFast mode on a dynamic port, but it is not recommended.
•
If a port is reconfigured from a static port to a dynamic port on the same VLAN, the port
connects immediately to that VLAN. However, VMPS checks the legality of the specific host
on the dynamic port after a certain period, and may disconnect if it is not valid.
•
Static secure ports cannot become dynamic ports. Security on the static, secure port must
be turned off before it can become dynamic.
•
Trunk ports cannot become dynamic ports. Trunks must be turned into access ports before
being changed from static to dynamic in order to work with VMPS.
Table 78: VLAN Membership Policy Server (VMPS)
RECOGNIZED
DEVICE
ALLOWED
ACCESS
FALLBACK VLAN
DEFINED
SECURE
SETTINGS
ACTION
Yes
Yes
N/A
N/A
Send dynamic VLAN
Unknown
Unknown
Yes
N/A
Fallback VLAN (guest)
No
vmps mode open
Access denied
No
vmps mode secure
Port shutdown
Yes
No
N/A
vmps mode open
Access denied
N/A
vmps mode secure
Port shutdown
Содержание MiVOICE BUSINESS
Страница 1: ...Mitel MiVoice Business RELEASE 7 2 ENGINEERING GUIDELINES ...
Страница 15: ...Chapter 1 ABOUT THIS DOCUMENT ...
Страница 16: ......
Страница 22: ...Engineering Guidelines 8 ...
Страница 23: ...Chapter 2 SYSTEM OVERVIEW ...
Страница 24: ......
Страница 28: ...Engineering Guidelines 14 ...
Страница 29: ...Chapter 3 TYPICAL CONFIGURATIONS ...
Страница 30: ......
Страница 73: ...Chapter 4 PHONES AND VOICE APPLICATIONS ...
Страница 74: ......
Страница 95: ...Phones and Voice Applications 81 Figure 9 ICP Connection Paths and Limitations ...
Страница 100: ...Engineering Guidelines 86 ...
Страница 101: ...Chapter 5 POWER ...
Страница 102: ......
Страница 128: ...Engineering Guidelines 114 ...
Страница 129: ...Chapter 6 PERFORMANCE ...
Страница 130: ......
Страница 135: ...Chapter 7 APPLICATIONS ...
Страница 136: ......
Страница 142: ...Engineering Guidelines 128 ...
Страница 143: ...Chapter 8 EMERGENCY SERVICES ...
Страница 144: ......
Страница 151: ...Chapter 9 IP NETWORKING ...
Страница 152: ......
Страница 167: ...Chapter 10 LICENSING ...
Страница 168: ......
Страница 183: ...Chapter 11 BANDWIDTH CODECS AND COMPRESSION ...
Страница 184: ......
Страница 209: ...Chapter 12 NETWORK CONFIGURATION CONCEPTS ...
Страница 210: ......
Страница 244: ...Engineering Guidelines 230 ...
Страница 245: ...Chapter 13 NETWORK CONFIGURATION SPECIFICS ...
Страница 246: ......
Страница 309: ...Appendix A CAT 3 WIRING ...
Страница 310: ......
Страница 315: ...CAT 3 Wiring 301 Figure 55 CX MX MXe AX and LX Minimum Cable Standard ...
Страница 316: ...Engineering Guidelines 302 ...
Страница 317: ...Appendix B INSTALLATION EXAMPLES ...
Страница 318: ......
Страница 335: ...Appendix C LLDP AND LLDP MED CONFIGURATION EXAMPLES ...
Страница 336: ......
Страница 347: ...Appendix D VOIP AND VLANS ...
Страница 348: ......
Страница 353: ...Appendix E VOIP SECURITY ...
Страница 354: ......
Страница 381: ... ...