Friday, December 20, 2019

Voice VLAN from Fortigate to Cisco SG350

Hello everyone,

I have run into a weird situation with my IP phone system (Primus/Polycom VVX) while developing a new network. I have created a VLAN on a Fortigate 100D with an ID of 774 and assigned it to my LAN interface which contains 5 ports on the Firewall. I also made the VLAN a DHCP server as well so the phones can pull an IP from it. I replicated this VLAN in the Cisco SG350 switch with the same VLAN ID. I trunked a port on the switch to the Fortigate which allows our corporate (data) and voice (774) VLAN. I then set an access port to allow VLAN 774 and connected my IP phone to that port on the switch. When the phone powered up, it didn't get an IP address. As a test, I switched the port that the phone is connected to from an access port to a trunk port and now the phone is able to get an IP and make calls. I'm confused to how this is happening, is the phone sending VLAN-tagged packets that the access port isn't able to read? Is there something I can do different so I don't have to make 10+ ports on my switch trunk ports?



No comments:

Post a Comment