# Voice VLAN and LLDP-MED and CDP and PoE for IP phones

Canonical: https://warmtransfer.net/knowledge/voice-vlan-lldp-poe

Last verified: 2026-09-24

Voice VLAN and discovery protocols allow IP phones to separate voice traffic from data traffic and obtain network parameters at the access layer[^31][^56]. Power over Ethernet (PoE) provides electrical power over network cabling to operational endpoints according to negotiated power classifications[^24][^40].

## Voice VLAN and Port Configuration

On Catalyst 9300 switches running IOS XE 17.15.x, voice VLAN can be configured only on access ports, not on trunk ports[^31]. On Catalyst 9300 (IOS XE 17.15.x) the voice VLAN must be present and active on the switch for the IP phone to communicate on it[^39]. On Catalyst 9300 (IOS XE 17.15.x), configuring a voice VLAN on a port automatically enables PortFast on it[^37].

On Catalyst 9300 (IOS XE 17.15.x), CDP must be enabled on the port connected to a Cisco IP phone for the switch to send it the voice VLAN configuration, and CDP is globally enabled by default on all interfaces[^32]. The Catalyst 9300 (IOS XE 17.15.x) guide says to enable QoS with the `trust device cisco-phone` interface command before enabling voice VLAN, unless auto-QoS is used, which configures these settings automatically[^38]. 

Voice VLAN behavior on the Catalyst 9300 depends on the configured mode:
- The command `switchport voice vlan <vlan-id>` instructs the phone to forward voice traffic tagged in the specified VLAN with a default IEEE 802.1Q priority of 5[^36].
- The command `switchport voice vlan dot1p` configures the switch to accept voice and data 802.1p priority frames tagged with VLAN ID 0 (the native VLAN)[^34].
- The command `switchport voice vlan untagged` directs the phone to send untagged voice traffic[^35].
- The command `switchport voice vlan none` allows the phone to apply its own internal configuration to send untagged voice traffic[^35].

When configuring port security on a voice VLAN port on a Catalyst 9300, the maximum secure addresses must be set to 2 plus the maximum allowed on the access VLAN, because the phone requires up to 2 MAC addresses[^28].

On Juniper EX Series switches, a voice VLAN permits an access port to accept untagged data traffic and tagged voice traffic in separate VLANs, using LLDP-MED to deliver VoIP parameters to the phone so traffic is tagged and prioritized at the source[^44]. Juniper documentation states that without LLDP-MED on an EX switch, the voice VLAN ID must be configured manually on the phone[^45].

## PC Port and Priority Extension

On Catalyst 9300 switches, the `switchport priority extend trust` command instructs the IP phone's PC access port to trust the priority received from an attached PC[^13]. The command `switchport priority extend cos <0-7>` configures the phone to override incoming priority with the specified value, defaulting to cos 0[^13]. Untagged traffic from a device connected to the Cisco IP phone's PC port passes through the phone unchanged regardless of the phone access port's trust state[^20].

For Cisco 8800 MPP phones using 802.1X, the PC port and voice VLAN can remain active only if the connected switch supports multidomain authentication; otherwise, Cisco says to disable both the PC port and the voice VLAN[^46]. Cisco IP phones send an EAPOL-Logoff message to the switch on behalf of an attached PC behind the phone's PC port, providing proxy EAPOL-Logoff functionality[^49].

## Discovery Protocols: CDP and LLDP-MED

ANSI/TIA-1057 defines organizationally specific IEEE 802.1AB TLV extensions for media endpoints across 4 functional areas: network policy (VLAN ID, 802.1p priority, DSCP), location (including emergency call service location), extended PoE power management, and inventory[^56]. ANSI/TIA-1057 was published on 2006-04-06, reaffirmed on 2011-08-26, and is active[^55].

Catalyst 9300 (IOS XE 17.17.x) LLDP defaults are a 120-second holdtime, a 30-second update timer and a 2-second reinitialization delay[^15]. By default, a Catalyst 9300 transmits only standard LLDP packets on an interface until it receives LLDP-MED packets from an endpoint[^16]. The Catalyst 9300 supports LLDP-MED capabilities, network policy, power management, inventory management, and location TLVs[^17]. The LLDP-MED network policy TLV conveys the VLAN, the Layer 2 class of service (CoS), and DSCP value for applications such as voice[^19].

On Catalyst 9300 switches, applying a network-policy profile to an interface first prevents `switchport voice vlan` from being configured on that interface; however, a network-policy profile can be added to an interface that already has `switchport voice vlan` applied[^18].

In the LLDP System Capabilities TLV, a Cisco MPP phone with a PC port sets Bit 2 (Bridge) and Bit 5 (Phone), while a phone without a PC port sets only Bit 5[^50].

On Cisco MPP desk phones with both CDP and LLDP-MED enabled, the active VLAN network policy is whichever policy was set or changed most recently by either protocol[^47]. If neither protocol provides a VLAN assignment, the manually configured VLAN ID is applied; in the absence of a manual VLAN, default network policy rules apply[^48]. On Cisco 8800 phones under Unified CM, the Admin VLAN ID is used only when the phone gets no auxiliary VLAN from the switch, and the phone does not inherit the operational VLAN from it while CDP or LLDP-MED is enabled[^2].

## QoS and Auto-QoS Configurations

Under RFC 4594 guidelines, the Telephony service class SHOULD use the Expedited Forwarding PHB, DSCP EF (decimal 46)[^52]. The Signaling service class SHOULD use the Class Selector PHB with DSCP CS5[^51].

On Catalyst 9300 switches:
- The command `auto qos voip cisco-phone` establishes conditional trust, trusting incoming QoS labels only when CDP detects a connected Cisco IP phone[^7]. If no phone is detected, the port does not trust incoming QoS labels[^7].
- Cisco instructs administrators not to configure `auto qos voip cisco-phone` for IP phones supporting video, because the command overwrites video DSCP markings and misclassifies the traffic[^8].
- The command `auto qos voip trust` unconditionally trusts incoming QoS markings and is designated for uplinks to trusted switches or routers[^9].
- The command `auto qos voip cisco-softphone` classifies and polices incoming traffic while treating the port as untrusted[^9].

## Power over Ethernet (PoE)

Cisco's Catalyst 9300 IEEE power classification table gives the maximum power per class as: Class 0 15.4 W, Class 1 4 W, Class 2 7 W, Class 3 15.4 W, Class 4 30 W, Class 5 45 W, Class 6 60 W, Class 7 75 W, Class 8 90 W[^24].

Catalyst 9300 switches operate in auto PoE power management mode by default, detecting whether an endpoint requires power and allocating budget on a first-come, first-served basis[^21]. In PoE static mode, the switch reserves power for the port regardless of whether a device is attached[^26]. If the PoE budget is insufficient to satisfy a request, the Catalyst 9300 denies power, ensures the port remains unpowered, records a syslog message, and updates the switch LEDs[^22]. Real-time PoE policing acts when an endpoint exceeds its maximum allocation by either disabling the port in an err-disabled state or logging a warning[^25].

Cisco IP Phones 8861 and 8865 operate as PoE Class 4 devices and require a Class 4 capable switch or line card to support their supplementary features[^1]. After an initial allocation based on IEEE classification, the Catalyst 9300 uses CDP to learn the connected device's specific power requirement and updates its power budget accordingly[^23]. Powered devices operating under PoE+ utilize IEEE 802.3at and LLDP power-via-MDI TLVs to negotiate up to 30 W[^27].

When running Cisco Universal Power Over Ethernet (UPOE) delivering up to 60 W over signal and spare wire pairs, the Catalyst 9300 provides spare-pair power only after mutual UPOE capability is verified via CDP or LLDP and requested by the endpoint[^29]. Cisco UPOE+ on Catalyst 9300 complies with IEEE 802.3bt, maintains backward compatibility with 802.3af, 802.3at, and Cisco UPOE, and supplies up to 90 W to 802.3bt Type 4 devices[^30]. IEEE 802.3bt-2018 was approved on 2018-09-27, published on 2019-01-31, increases available power by utilizing all 4 pairs of structured cabling, and is incorporated into IEEE 802.3-2022[^41][^40].

On a Catalyst 9300, the global command `hw-module switch <n> upoe-plus` enables 802.3bt mode and initiates a switch power-cycle; once enabled, Cisco UPOE switches function as 802.3bt Type 3 devices delivering up to Class 6 power on every port[^10]. WarmTransfer's reading of the sources is that turning on 802.3bt mode on an active switch requires a maintenance window because the required power-cycle disconnects power to all attached PoE endpoints[^42].

### Protocol Interaction and Negotiation Locking

The Catalyst 9300 documentation states that when CDP and LLDP run concurrently, LLDP must be disabled on ports utilizing CDP for power negotiation (for instance, via `no lldp tlv-select power-management` or by applying `no lldp transmit` and `no lldp receive`)[^11]. Following a reboot of a Cisco 8800 Series phone, the switch locks power negotiation to the protocol (CDP or LLDP) that transmits the phone's initial power TLV[^5]. If an administrator disables that active negotiation protocol on the phone, the phone cannot supply power to accessories because the switch disregards power negotiation requests received over the alternate protocol[^4].

## DHCP Server Configuration for IP Phones

RFC 5859 (Informational, June 2010) documents DHCPv4 option 150, the TFTP Server Address option, which carries 1 or more IPv4 addresses of configuration servers, and IANA assigned code 150 under RFC 3942[^54]. RFC 5859 dictates that when option 150 and option 66 (TFTP server name) are both present, option 150 SHOULD take precedence[^53]. For Cisco 8800 Series phones managed by Unified CM, Cisco recommends utilizing DHCP option 150 and falling back to option 66 if option 150 is unavailable[^3].

## See also

See also [Cisco IP phone registration and TFTP and ITL and CTL](https://warmtransfer.net/knowledge/cisco-phone-registration).
See also [Troubleshooting Cisco IP phone registration](https://warmtransfer.net/knowledge/cisco-phone-registration-troubleshooting).
See also [QoS marking and queuing for voice](https://warmtransfer.net/knowledge/qos-marking).
See also [RedSky E911 for enterprise UC](https://warmtransfer.net/knowledge/redsky-e911).
See also [Intrado enterprise 911 routing services](https://warmtransfer.net/knowledge/intrado-enterprise-911).
See also [Meeting Kari's Law and RAY BAUM's Act on an enterprise phone system](https://warmtransfer.net/knowledge/kari-ray-baum-compliance).
See also [Setting up Webex Calling emergency calling with RedSky](https://warmtransfer.net/knowledge/webex-calling-redsky-e911-setup).
See also [SD-WAN considerations for voice](https://warmtransfer.net/knowledge/sdwan-voice).
See also [Firewall ports and IP ranges for cloud calling](https://warmtransfer.net/knowledge/firewall-ports-uc).
See also [Codec selection and bandwidth planning](https://warmtransfer.net/knowledge/bandwidth-codec-planning).
See also [DNS SRV and service discovery for SIP](https://warmtransfer.net/knowledge/dns-srv-voice).
See also [Network readiness assessment for cloud calling](https://warmtransfer.net/knowledge/network-readiness-assessment).
See also [Webex Edge Connect private cloud connectivity](https://warmtransfer.net/knowledge/webex-edge-connect).
See also [UC disaster recovery and business continuity](https://warmtransfer.net/knowledge/uc-disaster-recovery).

## Applicability

Catalyst 9300 voice VLAN configuration behaviors apply to Cisco IOS XE 17.15.x[^31][^39]. LLDP and Auto-QoS configurations apply to Cisco IOS XE 17.17.x[^15][^7]. Power over Ethernet specifications for Catalyst 9300 apply to Cisco IOS XE 17.18.x[^24][^10].

## What remains uncertain

The exact LLDP-MED timer negotiation limits on Juniper EX Series switches are not covered by the sources below.

## Sources

[^1]: Cisco IP Phones 8861 and 8865 are PoE Class 4 devices and need a Class 4 capable switch or line card to support their extra features. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Technical Details > Power Requirements (Power Guidelines). Checked 2026-09-24.
[^2]: On Cisco 8800 phones under Unified CM, the Admin VLAN ID is used only when the phone gets no auxiliary VLAN from the switch, and the phone does not inherit the operational VLAN from it while CDP or LLDP-MED is enabled. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_011.html), Cisco IP Phone Installation > Network Setup fields > Admin VLAN ID. Checked 2026-09-24.
[^3]: Cisco's 8800 admin guide for Unified CM recommends DHCP custom option 150, set to the TFTP server IP address, and falls back to DHCP option 66 if option 150 cannot be used. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Technical Details > Network Protocols (DHCP / TFTP entries). Checked 2026-09-24.
[^4]: If an administrator disables on the phone the protocol the switch locked power negotiation to, the Cisco 8800 phone cannot power accessories, because the switch ignores power requests in the other protocol. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Technical Details > Network Protocols > Power Negotiation Over LLDP. Checked 2026-09-24.
[^5]: After a Cisco 8800 phone reboots, the switch locks power negotiation to whichever protocol, CDP or LLDP, carries the phone's first power TLV. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Technical Details > Network Protocols > Power Negotiation Over LLDP. Checked 2026-09-24.
[^6]: A Cisco 8800 phone under Unified CM prefers manually assigned TFTP servers over DHCP-assigned ones, trying manual IPv4, then manual IPv6, then DHCP-provided servers. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_011.html), Cisco IP Phone Installation > Network Setup > TFTP server precedence note. Checked 2026-09-24.
[^7]: On Catalyst 9300, auto qos voip cisco-phone trusts incoming QoS labels only when CDP detects a Cisco IP phone on the port (conditional trust), and does not trust them when no phone is detected. Source: [Quality of Service Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring Auto-QoS](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/qos/b_1717_qos_9300_cg/configuring_auto_qos.html), Configuring Auto-QoS > auto qos voip cisco-phone description. Checked 2026-09-24.
[^8]: Cisco says not to use auto qos voip cisco-phone for IP phones that support video, because it overwrites the video packets' DSCP markings and misclassifies them. Source: [Quality of Service Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring Auto-QoS](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/qos/b_1717_qos_9300_cg/configuring_auto_qos.html), Configuring Auto-QoS > auto qos voip cisco-phone (note). Checked 2026-09-24.
[^9]: On Catalyst 9300, auto qos voip trust is meant for uplinks to a trusted switch or router and trusts incoming QoS labels unconditionally, while auto qos voip cisco-softphone treats the port as untrusted and classifies and polices the traffic. Source: [Quality of Service Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring Auto-QoS](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/qos/b_1717_qos_9300_cg/configuring_auto_qos.html), Configuring Auto-QoS > auto qos voip trust / auto qos voip cisco-softphone descriptions. Checked 2026-09-24.
[^10]: On Catalyst 9300, the global command hw-module switch <n> upoe-plus enables 802.3bt mode and power-cycles the switch, and in that mode Cisco UPOE switches act as 802.3bt Type 3 devices supporting up to Class 6 on every port. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Supported Protocols and Standards. Checked 2026-09-24.
[^11]: The Catalyst 9300 guide says that when CDP and LLDP both run on a switch, LLDP must be disabled on interfaces that use CDP for power negotiation, for example with no lldp tlv-select power-management or no lldp transmit and no lldp receive. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > LLDP and Cisco Discovery Protocol / power negotiation note. Checked 2026-09-24.
[^12]: The Catalyst 9300 voice VLAN guide warns that enabling IEEE 802.1X on an access port can cost the phone up to 30 seconds of connectivity to the switch. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Voice VLAN Configuration Guidelines. Checked 2026-09-24.
[^13]: On Catalyst 9300, switchport priority extend trust tells the phone's access (PC) port to trust the priority received from the attached PC, and switchport priority extend cos <0-7> makes the phone override it, with a default of cos 0. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Configuring the Priority of Incoming Data Frames. Checked 2026-09-24.
[^14]: The Catalyst 9300 IOS XE 17.17.x guide's Default LLDP Configuration table lists LLDP global state, interface state, transmit and receive as Disabled. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > Default LLDP Configuration (table). Checked 2026-09-24.
[^15]: Catalyst 9300 (IOS XE 17.17.x) LLDP defaults are a 120-second holdtime, a 30-second update timer and a 2-second reinitialization delay. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > Default LLDP Configuration (table). Checked 2026-09-24.
[^16]: By default a Catalyst 9300 sends only plain LLDP packets on a port until it receives LLDP-MED packets from the end device. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > LLDP-MED. Checked 2026-09-24.
[^17]: Catalyst 9300 supports these LLDP-MED TLVs: LLDP-MED capabilities, network policy, power management, inventory management and location. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > LLDP-MED (supported TLVs list). Checked 2026-09-24.
[^18]: On Catalyst 9300, if a network-policy profile is configured on an interface first, switchport voice vlan can no longer be applied there, but a network-policy profile can be added to an interface that already has switchport voice vlan. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > Restrictions / network-policy guidelines. Checked 2026-09-24.
[^19]: On Catalyst 9300 the LLDP-MED network policy TLV carries the VLAN, the Layer 2 class of service (CoS) and the DSCP value for an application such as voice. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Configuring LLDP, LLDP-MED, and Wired Location Service > LLDP-MED (Network policy TLV). Checked 2026-09-24.
[^20]: Per the Catalyst 9300 guide, untagged traffic from a device attached to the Cisco IP phone's PC port passes through the phone unchanged, whatever the trust state of the phone's access port. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Cisco IP Phone Data Traffic. Checked 2026-09-24.
[^21]: On Catalyst 9300 the default PoE power management mode is auto: the port detects whether the device needs power and grants it first come, first served if the budget allows. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Power Management Modes. Checked 2026-09-24.
[^22]: When the PoE budget cannot cover a request, a Catalyst 9300 denies power, makes sure the port is unpowered, logs a syslog message and updates the LEDs. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Power Management Modes (auto mode description). Checked 2026-09-24.
[^23]: After a Catalyst 9300 powers a port from the IEEE class, it uses CDP to learn the Cisco powered device's actual power need and adjusts the power budget to match. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Powered-Device Detection and Initial Power Allocation. Checked 2026-09-24.
[^24]: Cisco's Catalyst 9300 IEEE power classification table gives the maximum power per class as: Class 0 15.4 W, Class 1 4 W, Class 2 7 W, Class 3 15.4 W, Class 4 30 W, Class 5 45 W, Class 6 60 W, Class 7 75 W, Class 8 90 W. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Powered-Device Detection and Initial Power Allocation > Table 1 IEEE Power Classifications. Checked 2026-09-24.
[^25]: On Catalyst 9300, real-time PoE policing acts when a powered device draws more than its allocated maximum, either by error-disabling the port or by logging a warning. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Power Monitoring and Power Policing. Checked 2026-09-24.
[^26]: On Catalyst 9300, PoE static mode reserves power for the port even when no powered device is connected. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Power Management Modes. Checked 2026-09-24.
[^27]: The Catalyst 9300 guide says PoE+ powered devices use IEEE 802.3at and LLDP power-via-MDI TLVs to negotiate up to 30 W. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Powered-Device Detection and Initial Power Allocation. Checked 2026-09-24.
[^28]: On Catalyst 9300 with port security on a voice VLAN port, the maximum secure addresses must be set to two plus the maximum allowed on the access VLAN, because the phone needs up to two MAC addresses. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Voice VLAN Configuration Guidelines. Checked 2026-09-24.
[^29]: For Cisco UPOE (up to 60 W over signal and spare pairs), a Catalyst 9300 enables spare-pair power only after the port and device identify each other as UPOE-capable over CDP or LLDP and the device asks for spare-pair power. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Cisco Universal Power Over Ethernet. Checked 2026-09-24.
[^30]: Cisco UPOE+ on Catalyst 9300 follows IEEE 802.3bt, stays compatible with 802.3af, 802.3at and Cisco UPOE, and delivers up to 90 W to 802.3bt Type 4 devices. Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Configuring Power over Ethernet > Supported Protocols and Standards. Checked 2026-09-24.
[^31]: On Catalyst 9300 switches running IOS XE 17.15.x, voice VLAN can be configured only on access ports, not on trunk ports. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Voice VLAN Configuration Guidelines. Checked 2026-09-24.
[^32]: On Catalyst 9300 (IOS XE 17.15.x), CDP must be enabled on the port connected to a Cisco IP phone for the switch to send it the voice VLAN configuration, and CDP is globally enabled by default on all interfaces. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Prerequisites for Voice VLANs. Checked 2026-09-24.
[^33]: The Catalyst 9300 voice VLAN guide says voice traffic carries a default Layer 3 IP precedence of 5 and voice control traffic a default of 3. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Cisco IP Phone Voice Traffic. Checked 2026-09-24.
[^34]: On Catalyst 9300, switchport voice vlan dot1p makes the switch accept voice and data 802.1p priority frames tagged with VLAN ID 0 (the native VLAN). Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Cisco IP Phone Voice Traffic (switchport voice vlan options). Checked 2026-09-24.
[^35]: On Catalyst 9300, switchport voice vlan untagged tells the phone to send untagged voice traffic, while switchport voice vlan none lets the phone use its own configuration to send untagged voice traffic. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Cisco IP Phone Voice Traffic (switchport voice vlan options). Checked 2026-09-24.
[^36]: On Catalyst 9300, switchport voice vlan <vlan-id> tells the phone to send all voice traffic tagged in that VLAN, with a default IEEE 802.1Q priority of 5. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Cisco IP Phone Voice Traffic (switchport voice vlan options). Checked 2026-09-24.
[^37]: On Catalyst 9300 (IOS XE 17.15.x), configuring a voice VLAN on a port automatically enables PortFast on it. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Voice VLAN Configuration Guidelines. Checked 2026-09-24.
[^38]: The Catalyst 9300 (IOS XE 17.15.x) guide says to enable QoS with the trust device cisco-phone interface command before enabling voice VLAN, unless auto-QoS is used, which configures these settings automatically. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Prerequisites for Voice VLANs. Checked 2026-09-24.
[^39]: On Catalyst 9300 (IOS XE 17.15.x) the voice VLAN must be present and active on the switch for the IP phone to communicate on it. Source: [VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-15/configuration_guide/vlan/b_1715_vlan_9300_cg/configuring_voice_vlans.html), Configuring Voice VLANs > Voice VLAN Configuration Guidelines. Checked 2026-09-24.
[^40]: IEEE 802.3bt raises the maximum power available to a powered device by using all four pairs of the structured cabling, and extends the power classification exchanged during negotiation. Source: [IEEE Standard for Ethernet Amendment 2: Physical Layer and Management Parameters for Power over Ethernet over 4 pairs (IEEE 802.3bt-2018)](https://standards.ieee.org/ieee/802.3bt/6749/), IEEE SA catalogue page > Abstract / Scope. Checked 2026-09-24.
[^41]: IEEE 802.3bt-2018 (PoE over 4 pairs) was approved on 2018-09-27, published on 2019-01-31, and is now a superseded standard incorporated into IEEE 802.3-2022. Source: [IEEE Standard for Ethernet Amendment 2: Physical Layer and Management Parameters for Power over Ethernet over 4 pairs (IEEE 802.3bt-2018)](https://standards.ieee.org/ieee/802.3bt/6749/), IEEE SA catalogue page > Status, Board Approval, Published fields. Checked 2026-09-24.
[^42]: Inference: turning on 802.3bt mode on an in-service Catalyst 9300 needs a maintenance window, because the command power-cycles the switch and so drops every PoE phone connected to it (inferred). Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring Power over Ethernet](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/int_hw/b_1718_int_and_hw_9300_cg/configuring_poe.html), Supported Protocols and Standards (hw-module switch upoe-plus note). Checked 2026-09-24.
[^43]: Inference: on a Catalyst 9300 left at documented defaults, a non-Cisco phone that learns its VLAN only through LLDP-MED will not get a voice VLAN until LLDP is enabled globally (lldp run), because CDP is on by default and LLDP is off (inferred). Source: [Interface and Hardware Components Configuration Guide, Cisco IOS XE 17.17.x (Catalyst 9300 Switches) - Configuring LLDP, LLDP-MED, and Wired Location Service](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-17/configuration_guide/int_hw/b_1717_int_and_hw_9300_cg/configuring_lldp__lldp_med__and_wired_location_service.html), Default LLDP Configuration (table), combined with cisco-cat9300-1715-voice-vlans Prerequisites for Voice VLANs. Checked 2026-09-24.
[^44]: On Juniper EX Series switches, a voice VLAN lets an access port accept untagged data and tagged voice traffic in separate VLANs, and the switch uses LLDP-MED to send VoIP parameters to the phone so voice is tagged and prioritised at the source. Source: [VoIP on EX Series Switches | Junos OS](https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/topic-map/802-1x-and-voip-on-switches.html), VoIP on EX Series Switches > Understanding VoIP / LLDP-MED. Checked 2026-09-24.
[^45]: Juniper says that without LLDP-MED on an EX switch the voice VLAN ID must be set manually on the IP phone. Source: [VoIP on EX Series Switches | Junos OS](https://www.juniper.net/documentation/us/en/software/junos/user-access/topics/topic-map/802-1x-and-voip-on-switches.html), VoIP on EX Series Switches > Example: Configuring VoIP without LLDP-MED support. Checked 2026-09-24.
[^46]: For Cisco 8800 MPP phones using 802.1X, the PC port and voice VLAN can stay in use only if the switch supports multidomain authentication; otherwise Cisco says to disable the PC port and the voice VLAN. Source: [Cisco IP Phone 8800 Series Multiplatform Phone Administration Guide for Release 11.3(1) and Later - Cisco IP Phone Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/MPP/8800/english/AG/p881_b_8800-mpp-ag_new/p881_b_8800-mpp-ag_new_chapter_01011.html), Cisco IP Phone Security > 802.1X Authentication. Checked 2026-09-24.
[^47]: On Cisco MPP desk phones with both CDP and LLDP-MED enabled, the VLAN network policy is whichever policy was set or changed most recently by either protocol. Source: [Cisco IP Desk Phone with Multiplatform Firmware (MPP) - Administration Guide - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/MPP/common/ag_desk_mpp_6800_7800_8800/tpcc_b_cisco-ip-desk-phone-multiplatform/tpcc_m_technical-details_deskphone-1201.html), Technical Details > Network Protocols > LLDP-MED / Final Network Policy Resolution and QoS. Checked 2026-09-24.
[^48]: On Cisco MPP desk phones, if neither CDP nor LLDP-MED supplies a VLAN, the manually configured VLAN ID is used, and without a manual VLAN the default network policy applies. Source: [Cisco IP Desk Phone with Multiplatform Firmware (MPP) - Administration Guide - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/MPP/common/ag_desk_mpp_6800_7800_8800/tpcc_b_cisco-ip-desk-phone-multiplatform/tpcc_m_technical-details_deskphone-1201.html), Technical Details > Network Protocols > LLDP-MED / Final Network Policy Resolution and QoS. Checked 2026-09-24.
[^49]: Cisco IP phones send an EAPOL-Logoff to the switch on behalf of a PC behind the phone's PC port (proxy EAPOL-Logoff). Source: [Cisco IP Phone 8800 Series Multiplatform Phone Administration Guide for Release 11.3(1) and Later - Cisco IP Phone Security](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/MPP/8800/english/AG/p881_b_8800-mpp-ag_new/p881_b_8800-mpp-ag_new_chapter_01011.html), Cisco IP Phone Security > 802.1X Authentication. Checked 2026-09-24.
[^50]: In the LLDP System Capabilities TLV, a Cisco MPP phone with a PC port sets Bit 2 (Bridge) and Bit 5 (Phone), while a phone without a PC port sets only Bit 5. Source: [Cisco IP Desk Phone with Multiplatform Firmware (MPP) - Administration Guide - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/MPP/common/ag_desk_mpp_6800_7800_8800/tpcc_b_cisco-ip-desk-phone-multiplatform/tpcc_m_technical-details_deskphone-1201.html), Technical Details > Network Protocols > LLDP-MED > System Capabilities TLV. Checked 2026-09-24.
[^51]: RFC 4594 says the Signaling service class SHOULD use the Class Selector PHB with DSCP CS5. Source: [RFC 4594: Configuration Guidelines for DiffServ Service Classes](https://www.rfc-editor.org/rfc/rfc4594.html), RFC 4594 Section 4.2. Checked 2026-09-24.
[^52]: RFC 4594 says the Telephony service class SHOULD use the Expedited Forwarding PHB, DSCP EF (decimal 46). Source: [RFC 4594: Configuration Guidelines for DiffServ Service Classes](https://www.rfc-editor.org/rfc/rfc4594.html), RFC 4594 Section 4.1. Checked 2026-09-24.
[^53]: RFC 5859 says that when option 150 appears together with option 66 (TFTP server name), option 150 SHOULD take priority. Source: [RFC 5859: TFTP Server Address Option for DHCPv4](https://www.rfc-editor.org/rfc/rfc5859.html), RFC 5859 Section 3. Checked 2026-09-24.
[^54]: RFC 5859 (Informational, June 2010) documents DHCPv4 option 150, the TFTP Server Address option, which carries one or more IPv4 addresses of configuration servers, and IANA assigned code 150 under RFC 3942. Source: [RFC 5859: TFTP Server Address Option for DHCPv4](https://www.rfc-editor.org/rfc/rfc5859.html), RFC 5859 Sections 1, 3 and 5. Checked 2026-09-24.
[^55]: The TIA store lists ANSI/TIA-1057 as published on 2006-04-06, reaffirmed on 2011-08-26 and Active. Source: [TIA ANSI/TIA-1057 Telecommunications IP Telephony Infrastructure Link Layer Discovery Protocol for Media Endpoint Devices (store listing)](https://store.accuristech.com/standards/tia-ansi-tia-1057?product_id=2591523), Store listing > document history / status fields. Checked 2026-09-24.
[^56]: ANSI/TIA-1057 (LLDP-MED) defines organizationally specific IEEE 802.1AB TLV extensions for media endpoints in four areas: network policy (VLAN ID, 802.1p priority, DSCP), location including emergency call service location, extended PoE power management, and inventory. Source: [TIA ANSI/TIA-1057 Telecommunications IP Telephony Infrastructure Link Layer Discovery Protocol for Media Endpoint Devices (store listing)](https://store.accuristech.com/standards/tia-ansi-tia-1057?product_id=2591523), Store listing > Scope. Checked 2026-09-24.
