<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675908#M292533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your first question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device ID: SEP002584A27BC9&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Entry address(es):&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address: 10.130.10.171&lt;/P&gt;&lt;P&gt;Platform: Cisco IP Phone 7942,&amp;nbsp; Capabilities: Host Phone Two-port Mac Relay&lt;/P&gt;&lt;P&gt;Interface: FastEthernet6/35,&amp;nbsp; Port ID (outgoing port): Port 1&lt;/P&gt;&lt;P&gt;Holdtime : 127 sec&lt;/P&gt;&lt;P&gt;Second Port Status: Down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version :&lt;/P&gt;&lt;P&gt;SCCP42.8-4-4S&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advertisement version: 2&lt;/P&gt;&lt;P&gt;Duplex: full&lt;/P&gt;&lt;P&gt;Power drawn: 6.300 Watts&lt;/P&gt;&lt;P&gt;Power request id: 31689, Power management id: 3&lt;/P&gt;&lt;P&gt;Power request levels are:6300 0 0 0 0&lt;/P&gt;&lt;P&gt;Management address(es):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(No computer is plugged into the phone at the moment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im not sure what you mean that the second port feature enabled, isnt that on default?&amp;nbsp; Since I can connect to the network fine on the second network card I assume that is what you mean.&amp;nbsp; Ill check the mac address issue today!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jul 2011 11:28:45 GMT</pubDate>
    <dc:creator>sullyjman12</dc:creator>
    <dc:date>2011-07-06T11:28:45Z</dc:date>
    <item>
      <title>Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675903#M292524</link>
      <description>&lt;P&gt;I had dot1x working with a guest vlan, data vlan and voice vlan.&amp;nbsp; I have upgraded my IOS and now im having this issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; IP Phone can register with cisco call manager (Great)&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Plug in a computer on the domain with a certificate into the phone and dot1x allows it on the network (Great).&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Plug my macbook into the switch port of the IP Phone and it times out and doesnt kick the macbook into the guest vlan (Sucks)&amp;nbsp; It just gets an APIPA ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get these errors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Fa6/35 AuditSessionID 0A820C01000004CE1F6FCAE6&lt;/P&gt;&lt;P&gt;%AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client (Unknown MAC) on Interface Fa6/35 AuditSessionID 0A820C01000004CE1F6FCAE6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess its going off the mac address of the machine when its plugged into the phone is there any way to disable this and have it dump straight into the guest vlan if there is no suppliment or the suppliment fails?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had this working working perfectly before the IOS upgrade &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; I am running IOS verison cat4500-ipbasek9-mz.150-2.SG.bin&amp;nbsp; I am running the Cisco 4507 with dual supervisor boards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mod Ports Card Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;---+-----+--------------------------------------+------------------+-----------&lt;/P&gt;&lt;P&gt; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; Supervisor II+ 1000BaseX (GBIC)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4013+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; Supervisor II+ 1000BaseX (GBIC)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4013+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt; 3&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp; 10/100/1000BaseT (RJ45)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4548-GB-RJ45&amp;nbsp; &lt;/P&gt;&lt;P&gt; 4&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp; 10/100/1000BaseT (RJ45)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4548-GB-RJ45&lt;/P&gt;&lt;P&gt; 5&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp; 10/100/1000BaseT (RJ45)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4548-GB-RJ45&lt;/P&gt;&lt;P&gt; 6&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp; 10/100BaseTX (RJ45)V, Cisco/IEEE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4248-RJ45V&lt;/P&gt;&lt;P&gt; 7&amp;nbsp;&amp;nbsp;&amp;nbsp; 48&amp;nbsp; 10/100BaseTX (RJ45)V, Cisco/IEEE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-X4248-RJ45V&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have configured on my testing port:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet6/35&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 50&lt;/P&gt;&lt;P&gt; logging event link-status&lt;/P&gt;&lt;P&gt; authentication event fail retry 5 action authorize vlan 69&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 69&lt;/P&gt;&lt;P&gt; authentication host-mode multi-host&lt;/P&gt;&lt;P&gt; authentication order dot1x&lt;/P&gt;&lt;P&gt; authentication priority dot1x&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication timer restart 10800&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate 10800&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout quiet-period 5&lt;/P&gt;&lt;P&gt; dot1x timeout server-timeout 10&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; dot1x max-reauth-req 1&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is the kicker, if I unplug my phone and plug in my macbook pro into the port directly it bumps the port into VLAN 69 which is the guest vlan and what I wanted.&amp;nbsp; So it has something to do with the port not transitioning to the guest vlan while plugged into the IP Phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clues?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675903#M292524</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2019-03-13T00:39:28Z</dc:date>
    </item>
    <item>
      <title>Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675904#M292526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Auth fail vlan assignment is only supported on single host mode found here - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/15.02SG/configuration/guide/dot1x.html#wp1198927"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/15.02SG/configuration/guide/dot1x.html#wp1198927&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if you can set this port to single host and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 10:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675904#M292526</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-01T10:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675905#M292527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this information, ill look into this but this was working fine with a voice vlan and auth fail vlan assignment before I moved to the new IOS.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 13:47:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675905#M292527</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2011-07-01T13:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675906#M292529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is really odd is when I reboot the phone and plug the mac book into the second port the macbook gets dumped into the guest vlan (which is what I want).&amp;nbsp; If I unplug the macbook and plug in a computer that is on our domain (and uses dot1x to authenicate) It gets dumped into the data vlan (which is what I want).&amp;nbsp; Now if I unplug the domain laptop and plug my macbook back into that port I get an APIPA address.&amp;nbsp; If I reboot the phone again plug the macbook in it gets dumped to the guest vlan.&amp;nbsp; I unplug the macbook and wait a few minutes and plug the macbook in again I get dumped into the guest vlan again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it works until I remove the guest machine and plug in a domain computer, its like the port doesnt transition back to an unauthenicated port.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 16:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675906#M292529</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2011-07-05T16:02:34Z</dc:date>
    </item>
    <item>
      <title>Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675907#M292531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of phone are you running on this port (show cdp&amp;nbsp; neighbors detail) keep in mind that these phones need to be deployed&amp;nbsp; with the 2nd port feature enabled. Also if you do show mac address&amp;nbsp; interface type x/x, do you still see the mac address of the previous&amp;nbsp; laptop/macbook, still on the port?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 05:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675907#M292531</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-06T05:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675908#M292533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To answer your first question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device ID: SEP002584A27BC9&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Entry address(es):&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address: 10.130.10.171&lt;/P&gt;&lt;P&gt;Platform: Cisco IP Phone 7942,&amp;nbsp; Capabilities: Host Phone Two-port Mac Relay&lt;/P&gt;&lt;P&gt;Interface: FastEthernet6/35,&amp;nbsp; Port ID (outgoing port): Port 1&lt;/P&gt;&lt;P&gt;Holdtime : 127 sec&lt;/P&gt;&lt;P&gt;Second Port Status: Down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version :&lt;/P&gt;&lt;P&gt;SCCP42.8-4-4S&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advertisement version: 2&lt;/P&gt;&lt;P&gt;Duplex: full&lt;/P&gt;&lt;P&gt;Power drawn: 6.300 Watts&lt;/P&gt;&lt;P&gt;Power request id: 31689, Power management id: 3&lt;/P&gt;&lt;P&gt;Power request levels are:6300 0 0 0 0&lt;/P&gt;&lt;P&gt;Management address(es):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(No computer is plugged into the phone at the moment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im not sure what you mean that the second port feature enabled, isnt that on default?&amp;nbsp; Since I can connect to the network fine on the second network card I assume that is what you mean.&amp;nbsp; Ill check the mac address issue today!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 11:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675908#M292533</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2011-07-06T11:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675909#M292534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i think you shoudl have this configured : dot1x port-control auto&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 03:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675909#M292534</guid>
      <dc:creator>gerald.suiza</dc:creator>
      <dc:date>2011-07-12T03:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675910#M292535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The new IOS doesnt support that command, what you are talking about is done by issuing the command "&lt;SPAN style="border-collapse: collapse;"&gt;authentication port-control auto" which I have done.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 16:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues/m-p/1675910#M292535</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2011-07-12T16:45:05Z</dc:date>
    </item>
  </channel>
</rss>

