Hi,
I need your help with a Voice VLAN issue that persists when 802.1X is enabled.
Problem: As soon as I enable 802.1X Authentication Mode on access ports, the Voice VLAN stops working and IP phones do not receive their IP addresses. If I disable the Voice VLAN, phones immediately start getting IP addresses (from the data VLAN). Also, on the RADIUS side we do not see any authentication attempts from the phones-there are no queries hitting the RADIUS server.
Expected behavior: With 802.1X enabled, IP phones should either:
-
be placed into the Voice VLAN via LLDP-MED/OUI/SIP (and receive DHCP from the voice scope), or
-
successfully perform MAB/802.1X as configured and still land in the Voice VLAN.
Actual behavior: Phones fail to obtain an IP on the Voice VLAN, and no RADIUS requests from the phones are observed.
Could you advise on the correct configuration or known issues/interactions between 802.1X and Voice VLAN (LLDP-MED/MAB) that would cause this behavior? I can provide running configs, switch models/firmware, and RADIUS logs if needed.
------------------------------
Sadikov Sarvar
------------------------------
Original Message:
Sent: 09-15-2025 07:55 AM
From: gorazd
Subject: Aruba Instant On 1930 - Voice VLAN not working with RADIUS
You are using NPS as RADIUS server. I can't help with it. In Clearpass you should do a MAC authentication first and onboard the device and then dot1x authentication when it is available.
Maybe it will also work with NPS.
So factory phone should do a mac authentication and get on onboarding vlan where it can configure itself. It's more NAC system functionality than switch functionality.
When it is configured, it should use dot1x authentication to get correct vlan.
Best, Gorazd
------------------------------
Gorazd Kikelj
Original Message:
Sent: 09-15-2025 02:00 AM
From: JSC UzAirports
Subject: Aruba Instant On 1930 - Voice VLAN not working with RADIUS
Thank you for your answer!
We are using a locally managed Instant On 1930 (not cloud).
Returning to your answer, I would like to clarify our scenario:
What if we have more than 5000 phones in the environment?
Phones should initially bypass 802.1X (so they can download their provisioning/configuration from the PBX server).
After provisioning, the phones should then perform 802.1X authentication and move into the correct VLAN.
On the same ports, there are also PCs connected behind the phones, and those PCs already use 802.1X authentication.
How can we achieve this scenario on the Instant On 1930?
Is there any recommended way to support both stages (pre-provisioning + 802.1X) for large numbers of phones together with PCs?
------------------------------
Sadikov Sarvar
Original Message:
Sent: 09-14-2025 03:02 AM
From: gorazd
Subject: Aruba Instant On 1930 - Voice VLAN not working with RADIUS
Do you have cloud or local managed switch?
In port profile you should select Client based authentication and deselect all vlans except native vlan. Your RADIUS server need to provide correct vlan when authenticated.
Authentication (dot1x or mac) will always take place any your RADIUS server need to provide access/accept and vlan response.
You can set the port to device mode and in this case the first device that gets online on the port will do the authentication and all other devices will share the same vlan and authentication. This is most probably not the scenario you want.
The best way is to enable dot1x authentication on phones and it should work.
Best, Gorazd
------------------------------
Gorazd Kikelj
Original Message:
Sent: 09-12-2025 05:35 AM
From: JSC UzAirports
Subject: Aruba Instant On 1930 - Voice VLAN not working with RADIUS
Hello,
I have an Aruba Instant On 1930 switch and Grandstream IP phones. I want phones to be placed in Voice VLAN through RADIUS (NPS/802.1X), but it doesn't work correctly:
When Voice VLAN membership is enabled on the port, the phone loses network and DHCP.
When Voice VLAN is disabled, the phone works (manual VLAN or DHCP ).
Switch always sends the device to RADIUS, even if VLAN Authentication for voice vlan is disabled.
PAP is not allowed in my environment, so I want to use 802.1X (PEAP/TLS) with Active Directory.
Has anyone configured 1930 + RADIUS + Voice VLAN successfully? Any best practices or reference configs would be appreciated.
Thanks!
------------------------------
Sadikov Sarvar
------------------------------