Nortel (Avaya) Phones and Cisco switch port security issues

Discussion in 'Networks' started by millsie, Feb 25, 2015.

  1. millsie

    millsie Byte Poster

    169
    4
    34
    Hi all,

    technical help needed!
    My organisation has a number of Nortel IP phones that we have hooked up to a Cisco 3750 switch.
    We are running PC's through the phone PC ports. The phones work fine and connecting ok to the DHCP server and work fine on the network.
    However when connecting PC's to different positions on these phones we are getting a port security violation error and the PC's are unable to work on the network.
    What we are seeing happen is that with port security on and maximum mac addresses allowed of 3. When you plug more than 3 different PC's into the phone, the port is locking out and the mac addresses are not cleared from that interface on the switch.

    The security config we have on the interface is:
    switchport port-security
    switchport port-security maximum 3
    switchport port-security maximum 1 vlan voice
    switchport port-security maximum 1 vlan access
    switchport port-security violation restrict

    When you disconnect the phone from the switch the mac addresses are clearing but only if you disconnect, otherwise they build up and up until you have 100's of violations on the same mac-address.

    this makes it difficult when doing office moves etc.

    We have tried troubleshooting the phones but all the settings seem normal.

    anyone come across this issue with Avaya phones vs Cisco switches before or any other make of phone?

    many thanks

    Millsie
     
    Certifications: N+, CCNA, MCDST
    WIP: CCNP route 642-902
  2. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364

    Sorry if I’m missing something here but how are you patching three PCs into the phone? – usually one PC and phone only when I’ve setup this kinda thing before.

    Unmanaged switch?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  3. JK2447
    Highly Decorated Member Award 500 Likes Award

    JK2447 Petabyte Poster Administrator Premium Member

    7,200
    951
    318
    I was thinking that Sparky, is this just a limitation although I suppose if it has the ports it's supposed to work, but the same, only ever seen 1 PC passing through 1 phone
     
    Certifications: VCP4, 5, 6, 6.5, 6.7, 7, 8, VCAP DCV Design, VMConAWS Skill, Google Cloud Digital Leader, BSc (Hons), HND IT, HND Computing, ITIL-F, MBCS CITP, MCP (270,290,291,293,294,298,299,410,411,412) MCTS (401,620,624,652) MCSA:Security, MCSE: Security, Security+, CPTS, CCA (XenApp6.5), MCSA 2012, VSP, VTSP
    WIP: Google Cloud Certs
  4. millsie

    millsie Byte Poster

    169
    4
    34
    Sorry guys, maybe not being clear enough.
    The initial problem I had was when I was testing the data links through the phone turrets with my laptop. Going to each phone to test. After I tried the first phone it worked fine but when I moved to others I couldnt get a data connection.

    Only 1 PC per phone.
    What we found was the reason this was happening is that although restrict is set to absolute (0) the mac address of my laptop was getting stuck (without sticky command) on each interface, so as I was moving around it was incrementing my mac address and firing the violation.

    I should be able to move around each phone and get a link as the switch should remove my mac address after disconnecting.

    Which is why its causing issues with desk/pc moves etc.

    We test this by having one phone connected to a switch, plugging three different laptops in one after the other, do a 'show mac address-table interface' and you can see that although the other laptops are disconnected, the mac addresses are stuck there unless you disconnect the phone turret from the switch.
    Its as if the phone is causing the switch to stick the addresses when they should be removed from the cam table straight away.

    Hope that makes sense?

    M
     
    Certifications: N+, CCNA, MCDST
    WIP: CCNP route 642-902
  5. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Get you now mate. Is there any settings on the phone that control the PC connection? I’m guessing that the phone is happily telling the switch that the laptop is still connected to the phone and therefore the MAC address is on the switch on that particular interface.

    Out of interest does the MAC address of the laptop ever clear from the switch if you don’t disconnect the phone?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.