<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1X on Etherchannels in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-on-etherchannels/m-p/2100794#M161122</link>
    <description>&lt;P&gt;We are deploying ISE and everything seems to be working just fine.&lt;/P&gt;&lt;P&gt;We have a series of servers accessing the network using etherchannels.&lt;/P&gt;&lt;P&gt;We are complete aware that 802.1X is not recommended for Servers but we would like to activate it for a proof of concept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way (or work around) to activate 802.1X in a port-channel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:29:49 GMT</pubDate>
    <dc:creator>vbuendia</dc:creator>
    <dc:date>2019-03-26T00:29:49Z</dc:date>
    <item>
      <title>802.1X on Etherchannels</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-etherchannels/m-p/2100794#M161122</link>
      <description>&lt;P&gt;We are deploying ISE and everything seems to be working just fine.&lt;/P&gt;&lt;P&gt;We have a series of servers accessing the network using etherchannels.&lt;/P&gt;&lt;P&gt;We are complete aware that 802.1X is not recommended for Servers but we would like to activate it for a proof of concept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way (or work around) to activate 802.1X in a port-channel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-etherchannels/m-p/2100794#M161122</guid>
      <dc:creator>vbuendia</dc:creator>
      <dc:date>2019-03-26T00:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on Etherchannels</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-etherchannels/m-p/2100795#M161168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A _jive_internal="true" href="https://community.cisco.com/people/vbuendia" id="jive-43396718154338285827786" rel="nofollow" style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; outline: none; color: #000000; font-weight: bold; font-family: Arial, verdana, sans-serif;"&gt;vbuendia&lt;/A&gt;, I wonder if we know each other? &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;802.1x is not supported on port-channels. You can potentially look into SGA for securing servers in your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a snip-it from the 15.x configuration guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;The 802.1x protocol is supported on Layer 2 static-access ports, voice VLAN ports, and Layer 3&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;routed ports, but it is not supported on these port types:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;– Trunk port—If you try to enable 802.1x authentication on a trunk port, an error message&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;appears, and 802.1x authentication is not enabled. If you try to change the mode of an&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;802.1x-enabled port to trunk, an error message appears, and the port mode is not changed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;– Dynamic ports—A port in dynamic mode can negotiate with its neighbor to become a trunk&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;port. If you try to enable 802.1x authentication on a dynamic port, an error message appears,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;and 802.1x authentication is not enabled. If you try to change the mode of an 802.1x-enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;port to dynamic, an error message appears, and the port mode is not changed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;– Dynamic-access ports—If you try to enable 802.1x authentication on a dynamic-access (VLAN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;Query Protocol [VQP]) port, an error message appears, and 802.1x authentication is not&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;enabled. If you try to change an 802.1x-enabled port to dynamic VLAN assignment, an error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;message appears, and the VLAN configuration is not changed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;– &lt;SPAN style="color: #ff0000;"&gt;EtherChannel port&lt;/SPAN&gt;—Do not configure a port that is an active or a not-yet-active member of an&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;EtherChannel as an 802.1x port. If you try to enable 802.1x authentication on an EtherChannel&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;port, an error message appears, and 802.1x authentication is not enabled.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;STRONG&gt;– Switched Port Analyzer (SPAN) and Remote SPAN (RSPAN) destination ports—You can&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;enable 802.1x authentication on a port that is a SPAN or RSPAN destination port. However,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;802.1x authentication is disabled until the port is removed as a SPAN or RSPAN destination&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt;"&gt;port. You can enable 802.1x authentication on a SPAN or RSPAN source port.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 03:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-etherchannels/m-p/2100795#M161168</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-01-30T03:06:35Z</dc:date>
    </item>
  </channel>
</rss>

