<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic auto smartports in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/auto-smartports/m-p/2259942#M136796</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Duplicate post.&amp;nbsp; &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 May 2013 21:59:23 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2013-05-08T21:59:23Z</dc:date>
    <item>
      <title>auto smartports</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-smartports/m-p/2259941#M136768</link>
      <description>&lt;DIV&gt;&lt;P&gt;We are trying to get our cisco&amp;nbsp; switches (2960) to handle 802.1x with MAB on or network.&amp;nbsp; We are wanting&amp;nbsp; our cisco phones to authenticate by MAB on our Microsoft NPS server and&amp;nbsp; return a AV pair with a smartport trigger.&amp;nbsp; We can only get the phones&amp;nbsp; to come up correctly if we pass the vlan VSA's back to the switch,&amp;nbsp; without the AV pair.&amp;nbsp; When only pass back the AV pair the switch sees&amp;nbsp; the trigger, but the macro ( we just map it to the builtin&lt;/P&gt;&lt;P&gt;CISCO_PHONE_AUTO_SMARTPORT ) doesn't run (or it fails during the run). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch Info: &lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 15.0(1)SE2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is an example of the config from an interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/6&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is: show shell triggers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User defined triggers&lt;/P&gt;&lt;P&gt;---------------------&lt;/P&gt;&lt;P&gt;Trigger Id: CRCSD_PHONE_MACRO&lt;/P&gt;&lt;P&gt;Trigger namespace: DEFAULT&lt;/P&gt;&lt;P&gt;Trigger description: CRCSD_PHONE_MACRO&lt;/P&gt;&lt;P&gt;Trigger mapping function: &lt;/P&gt;&lt;P&gt;Parameters: VOICE_VLAN=61&lt;/P&gt;&lt;P&gt;Current version: 1&lt;/P&gt;&lt;P&gt;Negotiated version: 1&lt;/P&gt;&lt;P&gt;Mapped Function: CISCO_PHONE_AUTO_SMARTPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like&amp;nbsp; I said the NPS server is authenticating everything correctly.&amp;nbsp; I've&amp;nbsp; enabled debugging macro auto all to see if it's knowing what to&amp;nbsp; process.&amp;nbsp; I can see the trigger name in the debug output so it's&amp;nbsp; authenticating correctly and passing back the vendor specifc attribute,&amp;nbsp; just not running the macro.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now&amp;nbsp; I did see that when you do enable auto smartports globally you get a&amp;nbsp; whole bunch of log/debug messages.&amp;nbsp; I'm assuming that it's CDP/MAC/LLDP&amp;nbsp; all seeing the device and trying to determine what kind of a device it&amp;nbsp; is.&amp;nbsp; Is there anyway to not have those protocols run or block them from&amp;nbsp; trying to run macros?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or ideas would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-B&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-smartports/m-p/2259941#M136768</guid>
      <dc:creator>bwedel1234</dc:creator>
      <dc:date>2019-03-11T03:24:38Z</dc:date>
    </item>
    <item>
      <title>auto smartports</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-smartports/m-p/2259942#M136796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Duplicate post.&amp;nbsp; &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 21:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-smartports/m-p/2259942#M136796</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2013-05-08T21:59:23Z</dc:date>
    </item>
  </channel>
</rss>

