Objective:
1. Authenticate workstations based on domain membership using 802.1x (wired) with NPS
2. If the workstation is a member of the domain, then place the workstation into VLAN 1.
3. If the workstation is not a member of the domain, then place the workstation into VLAN 2.
4. Do not authenticate IP phones
Problem:
Objective 1-3 is fine (using Open VLAN) but it's the phone situation I am having some problems with.
The phone is tagged in the right VLAN and we use DHCP (vendor options) to assign an IP address. This is working successfully on the test switch providing the phone is connected to a port that isn't an 'authenticator'.
As soon as the phone is connected to a port authenticator, the phone will boot up and fail to obtain an IP address.
I'm not sure if it's the phone that has the problem or the switch configuration but I've browsed the web/forums for hours and each and every article I read, details the same switch config that I am using.
Do you have any suggestions??
UPDATE:
WireShark capture of phone port shows the DHCP discover packet tagged in the correct VLAN
WireShark capture of the uplink port doesn't see the DHCP discover packet
Uplink port is in the Voice VLAN
Move phone to non 802.1x authenticator port on same switch and phone boots up successfully, with WireShark captures on phone port & uplink port capturing all the DHCP packets.