Polycom White Paper Sample
By segregating IP phones into their own VLAN(s), security filters can be implemented in the network to block all unnecessary traffic to or from those devices. This helps prevent disruption due to DoS attacks or attempts to compromise the devices. It also allows locking down access to configuration and signaling servers to only allow access from phones.
Using VLANs also allows placing IP phones on the public Internet while the connected PCs remain on a corporate intranet; this can facilitate using IP Centrex-type services from third parties without the complications of NAT between the phones and the Internet.