DHCP Oddities with Polycom VVX Phone

Hello,

I'll preface this by saying I'm still a MikroTik beginner (1 year), but I've been working in networking for about seven years, and this one has me completely stumped.

I have two buildings, each with its own router and switch.

Router A: CCR1009-7G-1C-1S+
Router B: RB5009UPr+S+

Connected to sfp-sfpplus1 on each router is a CRS354-48P-4S+2Q+ switch.

Router A serves 192.168.19.0/24, and Router B serves 192.168.21.0/24.

The environment is intentionally simple:

  • No separate VLANs for voice, printers, etc.
  • Router B is using essentially the default firewall filter rules. Router A has almost no firewall filter rules.
  • Each router runs its own DHCP server, bound directly to sfp-sfpplus1 (where the switch is connected).
  • The routers themselves do not use a bridge. The /24 is assigned directly to sfp-sfpplus1.
  • The switches each have a single bridge (bridge) containing every port. As far as I can tell, the switch configurations are effectively identical.

The problem is with our Polycom VVX phones.

If I plug one into any port on the switch in the 192.168.19.x building, it boots, gets a DHCP lease, and works normally.

In the 192.168.21.x building, however, the phones never receive a DHCP lease. Every other type of device I've tested (laptops, desktops, WAPs, tablets, etc.) receives a DHCP address without any issues.

To rule out the phones themselves, I took the exact same phones from the .19.x building and plugged them into the .21.x building. None of them received an IP. I've also tried every port on the switch with the same result.

I've spent far too long comparing the router and switch configurations line by line and have chased down non-existent leads that lead nowhere. After a lot of troubleshooting, here's what I've found:

  • Using the packet sniffer on Router B, I can clearly see the Polycom phones sending DHCPDISCOVER broadcasts.
  • The router never responds with a DHCPOFFER for those phones.
  • At the same time, I can see the router successfully completing DHCP exchanges with laptops and other devices on the same switch.
  • As a sanity test, I configured a completely separate DHCP server on Router B, assigned it to an unused ge3 interface with its own test subnet, and plugged a phone directly into that interface. The phone immediately received an IP address.

That seems to indicate:

  • The phones themselves are fine.
  • Router B's DHCP server is capable of serving the phones.
  • The problem only occurs when the phones are connected through the CRS354 switch.

I thought perhaps this thread might be related: ( DHCP sometimes ignores discover from Polycom phones ). Unfortunately, my DHCP server is not assigned to a bridge, and unlike that thread, my issue is completely consistent. I've been troubleshooting this on and off for months, and I have never once been able to get any Polycom phone to obtain an IP address through the CRS354 in the 192.168.21.x building, even though the exact same phones work immediately in the 192.168.19.x building.

At this point I'm running out of ideas. Is there anything specific to the CRS354, RouterOS, or DHCP processing that could explain why only these phones are ignored while every other DHCP client works normally?

Hi, can you post the configuration of CRS354?
Just /export from the terminal (or if CRS354 is RouterOS v6, use /export hide-sensitive) and the post it here (as a code block please - beginning with ```routeros and ending with three ` on a separate line).

You won't like this troubleshooting suggestion. :grimacing:

Try exchanging physically the two CRS354-48P-4S+2Q+ switches. :astonished_face:

If switch A works in building B BUT switch B doesn't work in building A there is a difference somewhere between the two switches (either in configuration or in some "hidden" settings, or in some "leftover cruft", or in actual hardware).

If switch A works in building B AND switch B works in building A (I doubt it) it is simply voodoo, now both works and you can call it a day.

If switch A doesn't work in building B BUT switch B works in building A the issue is somewhere in the network or devices in building B.

I was worried it would come to that. I will try it after hours and report back.

Unfortunately as a new user I can't add attachments, so I'll have to paste everything in-line here:

Switch A:

[admin@MikroTik] > export

2026-08-06 10:13:17 by RouterOS 7.14.2

software id = XU88-YHY0

model = CRS354-48P-4S+2Q+

serial number = HE408MH472Q

/interface bridgeadd admin-mac=48:A9:8A:5D:A3:04 auto-mac=no name=bridge port-cost-mode=short/interface wireless security-profilesset [ find default=yes ] supplicant-identity=MikroTik/ip hotspot profileset [ find default=yes ] html-directory=hotspot/portset 0 name=serial0/system logging actionset 1 disk-file-name=log/interface bridge portadd bridge=bridge comment=defconf interface=ether1 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether2 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether3 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether4 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether5 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether6 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether7 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether8 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether9 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether10 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether11 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether12 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether13 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether14 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether15 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether16 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether17 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether18 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether19 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether20 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether21 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether22 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether23 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether24 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether25 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether26 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether27 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether28 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether29 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether30 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether31 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether32 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether33 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether34 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether35 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether36 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether37 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether38 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether39 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether40 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether41 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether42 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether43 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether44 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether45 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether46 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether47 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether48 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=ether49 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus1-1 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus1-2 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus1-3 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus1-4 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus2-1 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus2-2 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus2-3 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=qsfpplus2-4 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=sfp-sfpplus3 internal-path-cost=10 path-cost=10add bridge=bridge comment=defconf interface=sfp-sfpplus4 internal-path-cost=10 path-cost=10/ip firewall connection trackingset udp-timeout=10s/ip dhcp-clientadd interface=bridge/ip serviceset telnet disabled=yesset ftp disabled=yesset www disabled=yesset ssh disabled=yesset api disabled=yesset api-ssl disabled=yes/radiusadd address=192.168.15.11 service=dot1x/system clockset time-zone-name=America/Phoenix/system identityset name=MikroTik/system noteset show-at-login=no/system routerboard settingsset boot-os=router-os enter-setup-on=delete-key

Switch B:

[admin@MikroTik] > export

1971-03-27 04:39:26 by RouterOS 7.14.3

software id = K2FC-V32Y

model = CRS354-48P-4S+2Q+

serial number = HGN09XP5X79

/interface bridgeadd admin-mac=D4:01:C3:E9:72:6A auto-mac=no comment=defconf name=bridge port-cost-mode=short/interface listadd name=WANadd name=LAN/ip hotspot profileset [ find default=yes ] html-directory=hotspot/portset 0 name=serial0/interface bridge portadd bridge=bridge comment=defconf interface=ether1add bridge=bridge comment=defconf interface=ether2add bridge=bridge comment=defconf interface=ether3add bridge=bridge comment=defconf interface=ether4add bridge=bridge comment=defconf interface=ether5add bridge=bridge comment=defconf interface=ether6add bridge=bridge comment=defconf interface=ether7add bridge=bridge comment=defconf interface=ether8add bridge=bridge comment=defconf interface=ether9add bridge=bridge comment=defconf interface=ether10add bridge=bridge comment=defconf interface=ether11add bridge=bridge comment=defconf interface=ether12add bridge=bridge comment=defconf interface=ether13add bridge=bridge comment=defconf interface=ether14add bridge=bridge comment=defconf interface=ether15add bridge=bridge comment=defconf interface=ether16add bridge=bridge comment=defconf interface=ether17add bridge=bridge comment=defconf interface=ether18add bridge=bridge comment=defconf interface=ether19add bridge=bridge comment=defconf interface=ether20add bridge=bridge comment=defconf interface=ether21add bridge=bridge comment=defconf interface=ether22add bridge=bridge comment=defconf interface=ether23add bridge=bridge comment=defconf interface=ether24add bridge=bridge comment=defconf interface=ether25add bridge=bridge comment=defconf interface=ether26add bridge=bridge comment=defconf interface=ether27add bridge=bridge comment=defconf interface=ether28add bridge=bridge comment=defconf interface=ether29add bridge=bridge comment=defconf interface=ether30add bridge=bridge comment=defconf interface=ether31add bridge=bridge comment=defconf interface=ether32add bridge=bridge comment=defconf interface=ether33add bridge=bridge comment=defconf interface=ether34add bridge=bridge comment=defconf interface=ether35add bridge=bridge comment=defconf interface=ether36add bridge=bridge comment=defconf interface=ether37add bridge=bridge comment=defconf interface=ether38add bridge=bridge comment=defconf interface=ether39add bridge=bridge comment=defconf interface=ether40add bridge=bridge comment=defconf interface=ether41add bridge=bridge comment=defconf interface=ether42add bridge=bridge comment=defconf interface=ether43add bridge=bridge comment=defconf interface=ether44add bridge=bridge comment=defconf interface=ether45add bridge=bridge comment=defconf interface=ether46add bridge=bridge comment=defconf interface=ether47add bridge=bridge comment=defconf interface=ether48add bridge=bridge comment=defconf interface=ether49add bridge=bridge comment=defconf interface=qsfpplus1-1add bridge=bridge comment=defconf interface=qsfpplus1-2add bridge=bridge comment=defconf interface=qsfpplus1-3add bridge=bridge comment=defconf interface=qsfpplus1-4add bridge=bridge comment=defconf interface=qsfpplus2-1add bridge=bridge comment=defconf interface=qsfpplus2-2add bridge=bridge comment=defconf interface=qsfpplus2-3add bridge=bridge comment=defconf interface=qsfpplus2-4add bridge=bridge comment=defconf interface=sfp-sfpplus1add bridge=bridge comment=defconf interface=sfp-sfpplus2add bridge=bridge comment=defconf interface=sfp-sfpplus3add bridge=bridge comment=defconf interface=sfp-sfpplus4/ip neighbor discovery-settingsset discover-interface-list=all lldp-med-net-policy-vlan=1/interface list memberadd interface=ether49 list=WANadd interface=ether1 list=LANadd interface=ether2 list=LANadd interface=ether3 list=LANadd interface=ether4 list=LANadd interface=ether5 list=LANadd interface=ether6 list=LANadd interface=ether7 list=LANadd interface=ether8 list=LANadd interface=ether9 list=LANadd interface=ether10 list=LANadd interface=ether11 list=LANadd interface=ether12 list=LANadd interface=ether13 list=LANadd interface=ether14 list=LANadd interface=ether15 list=LANadd interface=ether16 list=LANadd interface=ether17 list=LANadd interface=ether18 list=LANadd interface=ether19 list=LANadd interface=ether20 list=LANadd interface=ether21 list=LANadd interface=ether22 list=LANadd interface=ether23 list=LANadd interface=ether24 list=LANadd interface=ether25 list=LANadd interface=ether26 list=LANadd interface=ether27 list=LANadd interface=ether28 list=LANadd interface=ether29 list=LANadd interface=ether30 list=LANadd interface=ether31 list=LANadd interface=ether32 list=LANadd interface=ether33 list=LANadd interface=ether34 list=LANadd interface=ether35 list=LANadd interface=ether36 list=LANadd interface=ether37 list=LANadd interface=ether38 list=LANadd interface=ether39 list=LANadd interface=ether40 list=LANadd interface=ether41 list=LANadd interface=ether42 list=LANadd interface=ether43 list=LANadd interface=ether44 list=LANadd interface=ether45 list=LANadd interface=ether46 list=LANadd interface=ether47 list=LANadd interface=ether48 list=LANadd interface=qsfpplus1-1 list=LANadd interface=qsfpplus1-2 list=LANadd interface=qsfpplus1-3 list=LANadd interface=qsfpplus1-4 list=LANadd interface=qsfpplus2-1 list=LANadd interface=qsfpplus2-2 list=LANadd interface=qsfpplus2-3 list=LANadd interface=qsfpplus2-4 list=LANadd interface=sfp-sfpplus1 list=LANadd interface=sfp-sfpplus2 list=LANadd interface=sfp-sfpplus3 list=LANadd interface=sfp-sfpplus4 list=LAN/ip addressadd address=192.168.21.254/24 interface=bridge network=192.168.21.0/system noteset show-at-login=no/system routerboard settingsset boot-os=router-os enter-setup-on=delete-key

Thanks!

Not sure what happened (folks paste all the time - it's very common) but your config ran together on one line, rendering it unreadable. I suspect that someone will offer the "how-to" link shortly on adding it as a code block to omit text formatting that apparently tried to "fix" it for you.

OK, I managed to fix your paste (for anybody else who might be able to help also).
SwitchA.txt (6.2 KB)
SwitchB.txt (5.7 KB)

I am not 100% sure, but:

Check /ip neighbor discovery-settings on both switches, not the bridge config. The .21 switch almost certainly has lldp-med-net-policy-vlan=1 set (the .19 one will have it at the default disabled).

That makes the CRS354 advertise an LLDP-MED Network Policy TLV with voice VLAN 1. Polycom VVX phones honour LLDP-MED by default, so the phone starts 802.1Q-tagging everything it sends, including its DHCPDISCOVER. Your bridge has no vlan-filtering, so the tagged frames pass straight through to the router, which is exactly why your sniffer sees the DISCOVER. But the router's IP stack drops them, because sfp-sfpplus1 has no VLAN 1 sub-interface. Hence no DHCPOFFER, while untagged laptops on the same switch work fine, and the phone works when plugged directly into ge3 (no CRS354 in between = no LLDP-MED policy).

Confirm with:

/tool sniffer quick interface=sfp-sfpplus1 mac-protocol=vlan

Fix:

/ip neighbor discovery-settings set lldp-med-net-policy-vlan=disabled

on the .21 switch, then reboot the phone.

I don't see any firwall filter rules in these exports at all. And no dhcp server config. Hmm, this is too much for me. But michaldo's sounds legit (pwned by vlan1 :upside_down_face:). Wish you the best luck!

Thanks for fixing the output, I'll be sure to do it correctly next time.

The .21 switch indeed has "LLDP MED Network Policy VLAN" set to "1", and the .19 switch just doesn't have anything. I unplugged-replugged the phone, it is now working.

Thank you so much, so it turns it out it WAS the same concept/issue as the other post I linked, despite the other person having it work "sometimes" whereas it never worked for me.

Another (uncommon) reason why Rules #1 and #2 should be complied with?

The twelve Rules of Mikrotik Club