Skip to main content
HS08
Contributor III
July 20, 2026
Solved

FortiNAC Ipphone

  • July 20, 2026
  • 11 replies
  • 79 views

The port switch connected to the ipphone and if i plug endpoint to the port of the ipphone then the port switch is shutdown even there are no port security in the port switch. Anyone know why?

I can see the log from the switch 

Jul 20 14:30:13: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet2/0/1, new MAC address (f4a8.0d3d.5aeb) is seen.AuditSessionID  11C8640A000038317E6EAFB7

 

 switchport access vlan 251
 switchport mode access
 authentication host-mode multi-domain
 authentication order mab dot1x
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate 180
 mab
 snmp trap mac-notification change added
 snmp trap mac-notification change removed
 dot1x pae authenticator
 dot1x timeout quiet-period 10
 dot1x timeout server-timeout 30
 dot1x timeout tx-period 10
 spanning-tree portfast
 

Best answer by HS08

hi ​@ebilcari 

I know the issue why my voice vlan is not working, in the radius attribute previously i have space after voice.

 

11 replies

funkylicious
SuperUser
SuperUser
July 20, 2026
ebilcari
Staff
Staff
July 20, 2026

This event appears to have been triggered by the switch itself not by FNAC.

Emirjon
HS08
HS08Author
Contributor III
July 20, 2026

hi ​@ebilcari , ​@funkylicious 

The port shutdown due fortinac threat the ipphone as data traffic and if i use authentication host-mode multi-domain then only 1 mac of voice + 1 mac of data is allowed. When i change to authentication host-mode multi-host then the port switch is not shutdown.

I was config voice vlan on the inventory and the phone is not getting the ip address.

I read article https://docs.fortinet.com/document/fortinac-f/7.6.0/ip-phone-integration/519915/steps and i already config step1, step2 and step4 but the phone is not getting ip address.

So i create dedicated policy for ipphone and the ipphone is working but the fortinac threat this as data traffic.

Anyone can share with me how we can configure the voice vlan?

ebilcari
Staff
Staff
July 20, 2026

Based on the description, it appears that the switch is unable to identify the IP phone as a voice device. This is done through CDP or LLDP.
Some switches also support bypassing authentication for IP phones and placing them directly into the Voice VLAN. In this scenario, that may be the simpler approach. Also FNAC prefer to apply enforcement only for the host connected after the IP Phone.


If the switch and the IP phone are not able to communicate properly, the phone may be treated as a second host by both the switch and FNAC configurations. FNAC may apply the Voice VLAN as a tagged VLAN for IP Phone authentications:

 

Emirjon
HS08
HS08Author
Contributor III
July 20, 2026

actually teh switch can detect the IP phone by CDP.

and below is my radius attribute

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!