hi Alen
two advice for you
1- go to unauthentication user dynamically assing voip vlan whit 802.1x config
for example config
vlan 1
name "DEFAULT_VLAN"
untagged 1-26
ip address 10.0.0.1 255.255.255.0
exit
vlan 3
name "voip"
ip address 192.168.1.1 255.255.255.0
exit
aaa authentication port-access eap-radius
aaa accounting network start-stop radius
radius-server host 10.0.0.2 key procurve
aaa port-access authenticator 1-10
aaa port-access authenticator 1 unauth-vid 3
aaa port-access authenticator 2 unauth-vid 3
aaa port-access authenticator 3 unauth-vid 3
aaa port-access authenticator 4 unauth-vid 3
aaa port-access authenticator 5 unauth-vid 3
aaa port-access authenticator 6 unauth-vid 3
aaa port-access authenticator 7 unauth-vid 3
aaa port-access authenticator 8 unauth-vid 3
aaa port-access authenticator 9 unauth-vid 3
aaa port-access authenticator 10 unauth-vid 3
aaa port-access authenticator active
aaa port-access 1-10
this config all authentication user go to vlan 1 and all unauthentication users go to vlan 3 not need tag port all port waiting vlan 1 untag member
but this process very dancer because all malicious user go to dynamically voip vlan
2- connect ip phone voip vlan untag port
namely connect different switch port ip phone