<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PXE and 802.1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618622#M262632</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've defined 802.1x on all access-ports of our Catalyst 3560 (12.2.(53)SE2.&lt;/P&gt;&lt;P&gt;Everything works fine until it comes to PXE. I see from traces and "show"-cmds that the client using PXE is moved from the data-vlan (vlan_id 4) to the guest-vlan (vlan_id 996); it sends a DHCPREQUEST, but never gets an ip_address out of the defined scope. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drop&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt; 996&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/45&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********************************************&lt;/P&gt;&lt;P&gt;Configs:&lt;/P&gt;&lt;P&gt;Global:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;dot1x system-auth-control&lt;BR /&gt;dot1x guest-vlan supplicant&lt;BR /&gt;dot1x critical eapol&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Interface:&lt;BR /&gt;&lt;/SPAN&gt;interface GigabitEthernet0/45&lt;BR /&gt; switchport access vlan 4&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 504&lt;BR /&gt; switchport port-security maximum 5&lt;BR /&gt; switchport port-security aging time 360&lt;BR /&gt; switchport port-security aging type inactivity&lt;BR /&gt; srr-queue bandwidth share 10 10 60 20&lt;BR /&gt; srr-queue bandwidth shape 10 0 0 0&lt;BR /&gt; priority-queue out&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication event fail action authorize vlan 996&lt;BR /&gt; authentication event server dead action authorize vlan 996&lt;BR /&gt; authentication event no-response action authorize vlan 996&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate server&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout quiet-period 10&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; dot1x timeout supp-timeout 5&lt;BR /&gt; dot1x max-req 5&lt;BR /&gt; dot1x max-reauth-req 5&lt;BR /&gt; storm-control broadcast level 2.00 1.00&lt;BR /&gt; storm-control multicast level 3.00 0.50&lt;BR /&gt; storm-control action trap&lt;BR /&gt; no cdp enable&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt; service-policy input map_ipphone&lt;BR /&gt; ip dhcp snooping limit rate 25&lt;BR /&gt;end&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I disable dot1x the client immediately gets an ip_address out of the defines scope.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints are very much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roman&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:41:31 GMT</pubDate>
    <dc:creator>rhub</dc:creator>
    <dc:date>2019-03-11T00:41:31Z</dc:date>
    <item>
      <title>PXE and 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618622#M262632</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've defined 802.1x on all access-ports of our Catalyst 3560 (12.2.(53)SE2.&lt;/P&gt;&lt;P&gt;Everything works fine until it comes to PXE. I see from traces and "show"-cmds that the client using PXE is moved from the data-vlan (vlan_id 4) to the guest-vlan (vlan_id 996); it sends a DHCPREQUEST, but never gets an ip_address out of the defined scope. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drop&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt; 996&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/45&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********************************************&lt;/P&gt;&lt;P&gt;Configs:&lt;/P&gt;&lt;P&gt;Global:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;dot1x system-auth-control&lt;BR /&gt;dot1x guest-vlan supplicant&lt;BR /&gt;dot1x critical eapol&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Interface:&lt;BR /&gt;&lt;/SPAN&gt;interface GigabitEthernet0/45&lt;BR /&gt; switchport access vlan 4&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 504&lt;BR /&gt; switchport port-security maximum 5&lt;BR /&gt; switchport port-security aging time 360&lt;BR /&gt; switchport port-security aging type inactivity&lt;BR /&gt; srr-queue bandwidth share 10 10 60 20&lt;BR /&gt; srr-queue bandwidth shape 10 0 0 0&lt;BR /&gt; priority-queue out&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication event fail action authorize vlan 996&lt;BR /&gt; authentication event server dead action authorize vlan 996&lt;BR /&gt; authentication event no-response action authorize vlan 996&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate server&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout quiet-period 10&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; dot1x timeout supp-timeout 5&lt;BR /&gt; dot1x max-req 5&lt;BR /&gt; dot1x max-reauth-req 5&lt;BR /&gt; storm-control broadcast level 2.00 1.00&lt;BR /&gt; storm-control multicast level 3.00 0.50&lt;BR /&gt; storm-control action trap&lt;BR /&gt; no cdp enable&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt; service-policy input map_ipphone&lt;BR /&gt; ip dhcp snooping limit rate 25&lt;BR /&gt;end&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I disable dot1x the client immediately gets an ip_address out of the defines scope.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints are very much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roman&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618622#M262632</guid>
      <dc:creator>rhub</dc:creator>
      <dc:date>2019-03-11T00:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: PXE and 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618623#M262656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what's the output for the "show authentication session interface Gi0/45" when the problem happens?&lt;/P&gt;&lt;P&gt;I ask this as VLAN 996 is not only the guest VLAN but also the auth-fail and critical-auth VLANs as per your interface config, so you may want to check what caused the client to be assigned to that VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to collect further debugs so to follow the auth process, such as:&lt;/P&gt;&lt;P&gt; debug radius&lt;/P&gt;&lt;P&gt; debug dot1x all&lt;/P&gt;&lt;P&gt; debug aaa authentication&lt;/P&gt;&lt;P&gt; debug aaa authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 09:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618623#M262656</guid>
      <dc:creator>Federico Lovison</dc:creator>
      <dc:date>2011-01-12T09:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: PXE and 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618624#M262680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frederico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for replying to my question. The output of "show mac address-table int gi0/45" and "show authentication session int gi0/45" are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt; 996&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/45&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;BR /&gt;HAUO001#sh mac address-table int gi0/45&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt; 996&amp;nbsp;&amp;nbsp;&amp;nbsp; 001c.2343.b63b&amp;nbsp;&amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi0/45&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8pt;"&gt;Total Mac Addresses for this criterion: 1&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;HAUO001#sh authentication sessions int gi0/45&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet0/45&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; UNKNOWN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; in&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; AC1B0406000067E944DEF8F0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x0000804F&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xDF00078E&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Running&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did traces many times reflecting different situations and strange enough: sometimes the same client gets an IP address out of the guest VLAN 996 and sometimes it doesn't. In any case the clienst send the DHCPDISCOVER but not alwas get a DHCPOFFER.&lt;/P&gt;&lt;P&gt;I will run a test in a special environment this afternoon using another DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 10:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618624#M262680</guid>
      <dc:creator>bthuer</dc:creator>
      <dc:date>2011-01-12T10:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: PXE and 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618625#M262707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The show command shows that dot1x is still running at the time you got it.&lt;/P&gt;&lt;P&gt;I see that you use MDA on the port:&lt;/P&gt;&lt;P&gt;- Does this problem happen with and without an IP phone connected to the port?&lt;/P&gt;&lt;P&gt;- What does happen if you wait for few minutes before checking again the port status?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ask this as 12.2(53)SE is affected by bug CSCtg26941 which you may be hitting here.&lt;/P&gt;&lt;P&gt;In order to rule this out I would suggest to test the behavior with the latest 12.2(55)SE1 code.&lt;/P&gt;&lt;P&gt;If this doesn't fix the problem I would rather suggest to open a TAC case so to further investigate this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 13:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-and-802-1x/m-p/1618625#M262707</guid>
      <dc:creator>Federico Lovison</dc:creator>
      <dc:date>2011-01-12T13:43:51Z</dc:date>
    </item>
  </channel>
</rss>

