Security Mode And Normal Mode Of Voice Vlans - HP 3100 Series Configuration Manual

Table of Contents

Advertisement

Port
link
type
Trunk
Hybrid
When you configure the voice VLAN assignment modes, follow these guidelines:
The PVID is VLAN 1 for all ports by default. You can configure the PVID of a port and assign a
port to other VLANs by using commands. For more information, see
VLANs."
Use the display interface command to display the PVID of a port and the VLANs to which the
port is assigned.

Security mode and normal mode of voice VLANs

Depending on their inbound packet filtering mechanisms, voice VLAN-enabled ports operate in the
following modes:
Normal mode—The port receives voice VLAN-tagged packets and forwards them in the voice
VLAN without examining their MAC addresses. If the PVID of the port is the voice VLAN and the
port operates in manual VLAN assignment mode, the port forwards all received untagged
packets in the voice VLAN.
In normal mode, voice VLANs are vulnerable to traffic attacks. Malicious users might send large
quantities of forged voice VLAN-tagged or untagged packets to consume the voice VLAN
bandwidth, affecting normal voice communication.
Security mode—Only voice packets whose source MAC addresses match the recognizable
OUI addresses can pass through the voice VLAN-enabled inbound port, but all other packets
are dropped.
In a safe network, you can configure the voice VLANs to operate in normal mode, reducing the
consumption of system resources due to source MAC addresses checking.
TIP:
Hewlett Packard Enterprise does not recommend transmitting both voice traffic and non-voice traffic
in a voice VLAN. If you must transmit both voice traffic and nonvoice traffic, make sure that the voice
VLAN security mode is disabled.
Voice VLAN
Support for
assignment
untagged voice
mode
traffic
Manual
Yes
Automatic
No
Manual
Yes
Automatic
No
Manual
Yes
Configuration requirements
Configure the voice VLAN as the PVID of the
port.
N/A
Configure the voice VLAN as the PVID of the
port and assign the port to the voice VLAN.
N/A
Configure the voice VLAN as the PVID of the
port. Configure the port to forward the packets
from the voice VLAN without VLAN tags.
127
"Configuring port-based

Advertisement

Table of Contents
loading

Table of Contents