<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ip phone and pc VLAN security issue - ISE 1.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952335#M202437</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; On # 1&lt;/P&gt;&lt;P&gt;You have the make sure that &lt;/P&gt;&lt;P&gt;"authentication host-mode multi-domain" command is under each port&lt;/P&gt;&lt;P&gt;This will allow one voice vlan and only one PC vlan at any given time. If you disconnect a PC and connect onother PC mac address to it, the phone will reinitialize to accept or reject the new mac based on its profile.&lt;/P&gt;&lt;P&gt;On #2&lt;/P&gt;&lt;P&gt;I have not found a solution. But what I have found after deployment is that it has happend only on 2 VOIP phones, out of 70 that we have as of now. So it might to be related to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand we are not using Cisco phones but mitel. So this might be a whole issueon itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Jun 2013 13:20:10 GMT</pubDate>
    <dc:creator>cbecerrayr</dc:creator>
    <dc:date>2013-06-10T13:20:10Z</dc:date>
    <item>
      <title>ip phone and pc VLAN security issue - ISE 1.0</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952333#M202368</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;&lt;P&gt;We are about to implement IP phones to our current network and during testing I have found 2 issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- ip phone connects to a protected port using ISE mab authentication for the data network.&lt;/P&gt;&lt;P&gt;The voice VLAN is set up static on the port. The pc VLAN is given by ISE profiling.&lt;/P&gt;&lt;P&gt;Then the issue is that once the pc connects to the VLAN it belongs to from the ip phone it leaves open that vlan on that port which means that if I connect another pc it will get the original VLAN the port had open up the connection with. This is a big security issue as computers that should not be allowed on specific VLAN can access them this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- once the connection is up and running on the port for both the phone and the pc, there is re-authentication Happening every minute to ISE. The Authentication logs are getting so many messages for just one port. So once we convert from 2 ip phones to 500, that is definitely going to generate a lot of unnecessary traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know your thoughts...thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port config info....below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;description Extra port by Camilos Desk&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 220&lt;/P&gt;&lt;P&gt;srr-queue bandwidth share 1 30 35 5&lt;/P&gt;&lt;P&gt;priority-queue out &lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt;authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;authentication open&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;mls qos trust cos&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt;auto qos trust &lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952333#M202368</guid>
      <dc:creator>cbecerrayr</dc:creator>
      <dc:date>2019-03-11T02:07:34Z</dc:date>
    </item>
    <item>
      <title>ip phone and pc VLAN security issue - ISE 1.0</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952334#M202404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Camilo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you find a solution to your problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking at doing the same implementation as you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Philip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jun 2013 12:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952334#M202404</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2013-06-10T12:58:01Z</dc:date>
    </item>
    <item>
      <title>ip phone and pc VLAN security issue - ISE 1.0</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952335#M202437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; On # 1&lt;/P&gt;&lt;P&gt;You have the make sure that &lt;/P&gt;&lt;P&gt;"authentication host-mode multi-domain" command is under each port&lt;/P&gt;&lt;P&gt;This will allow one voice vlan and only one PC vlan at any given time. If you disconnect a PC and connect onother PC mac address to it, the phone will reinitialize to accept or reject the new mac based on its profile.&lt;/P&gt;&lt;P&gt;On #2&lt;/P&gt;&lt;P&gt;I have not found a solution. But what I have found after deployment is that it has happend only on 2 VOIP phones, out of 70 that we have as of now. So it might to be related to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand we are not using Cisco phones but mitel. So this might be a whole issueon itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jun 2013 13:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-phone-and-pc-vlan-security-issue-ise-1-0/m-p/1952335#M202437</guid>
      <dc:creator>cbecerrayr</dc:creator>
      <dc:date>2013-06-10T13:20:10Z</dc:date>
    </item>
  </channel>
</rss>

