123NOTE:• The default VLAN of a port is VLAN 1. You can change the default VLAN and assign a port to certainVLANs by using commands. For more information, see the chapter "VLAN configuration."• Use the display interface command to display the default VLAN of a port and the VLANs to which theport is assigned.Security mode and normal mode of voice VLANsDepending on their inbound packet filtering mechanisms, voice VLAN-enabled ports operate in thefollowing modes.• Normal mode: In this mode, voice VLAN-enabled ports receive packets carrying the voice VLANtag and forward packets in the voice VLAN without checking their source MAC addresses againstthe OUI addresses configured for the device. If the default VLAN of the port is the voice VLAN andthe port works in manual VLAN assignment mode, the port forwards all received untagged packetsin the voice VLAN. In normal mode, the voice VLANs are vulnerable to traffic attacks. Vicious usersmay forge a large amount of voice packets and send them to the device to consume the voice VLANbandwidth, affecting normal voice communication.• Security mode: In this mode, only voice packets whose source MAC addresses match therecognizable OUI addresses can pass through the voice VLAN-enabled inbound port, while allother packets are dropped.In a safe network, you can configure the voice VLANs to operate in normal mode, reducing theconsumption of system resources due to source MAC addresses checking.TIP:H3C does not recommend that you transmit both voice traffic and non-voice traffic in a voice VLAN. If youhave to, ensure that the voice VLAN security mode is disabled.Table 17 How a voice VLAN-enabled port processes packets in security/normal modeVoice VLANmode Packet type Packet processing modeSecurity modeUntagged packets If the source MAC address of a packet matches an OUIaddress configured for the device, it is forwarded in the voiceVLAN. Otherwise, it is dropped.Packets carrying thevoice VLAN tagPackets carrying othertagsForwarded or dropped depending on whether the port allowspackets of these VLANs to pass through.Normal modeUntagged packets The port does not check the source MAC addresses of inboundpackets. In this way, both voice traffic and non-voice trafficcan be transmitted in the voice VLAN.Packets carrying thevoice VLAN tagPackets carrying othertagsForwarded or dropped depending on whether the port allowspackets of these VLANs to pass through.