<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looking for options for in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270803#M323399</link>
    <description>&lt;P&gt;Looking for options for similar options...&lt;/P&gt;&lt;P&gt;I have 802.1x working fine, need to work around the Avaya IP phones for a remote office..&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan xxx&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan yyy&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event fail retry 5 action authorize vlan zzz&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan xxx&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan xxx&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate 4000&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Dec 2014 21:34:54 GMT</pubDate>
    <dc:creator>thompson318</dc:creator>
    <dc:date>2014-12-08T21:34:54Z</dc:date>
    <item>
      <title>801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270797#M323393</link>
      <description>&lt;P&gt;Hey everyone, I was wondering if someone could help me. I am trying to implement 801.x port security in my network. In our switch ports we have an IP AVAYA phone connected and a workstation connected to the IP phone. I enable dot1x authentication on the ports specifying the data vlan and the voice vlan. I configure the avaya phone 1608 in pass-thru mode, so that the authetication is forwaded to the PC. Supposedly, the phone would be able to connect without any authentication but it doesn't! I can't communicate with the dhcp server to get an ip:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is what I configure on the switch ports:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/2&lt;/P&gt;&lt;P&gt;switchport access vlan 200&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 45&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;dot1x host-mode multi-host&lt;/P&gt;&lt;P&gt;dot1x violation-mode protect&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanx for the help!!!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270797#M323393</guid>
      <dc:creator>lel_chavez</dc:creator>
      <dc:date>2019-03-13T00:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: 801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270798#M323394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way I can exclude any authentication on the voice VLAN but implement the dot1x for the data vlan on the same port? I would like to have authentication only for the workstation attached to the phone...\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx so much for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 17:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270798#M323394</guid>
      <dc:creator>lel_chavez</dc:creator>
      <dc:date>2009-11-06T17:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: 801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270799#M323395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can go for Multiple-Hosts Mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In multiple-hosts mode, you can attach multiple hosts to a single 802.1X-enabled port. Figure 39-4 shows 802.1X port-based authentication in a wireless LAN. In this mode, only one of the attached clients must be authorized for all clients to be granted network access. If the port becomes unauthorized (re-authentication fails or an EAPOL-logoff message is received), the switch denies network access to all of the attached clients. In this topology, the wireless access point is responsible for authenticating the clients attached to it, and it also acts as a client to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With multiple-hosts mode enabled, you can use 802.1X authentication to authenticate the port and port security to manage network access for all MAC addresses, including that of the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/dot1x.html#wp1308773" target="_blank"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/dot1x.html#wp1308773&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 18:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270799#M323395</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-11-06T18:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: 801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270800#M323396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to configure the port for multi-domain-authentication host-mode and authenticate the workstation *and* the Avaya phone via 802.1X or MAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link for configuring MDA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/sw8021x.html#wp1335550" target="_blank"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/sw8021x.html#wp1335550&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 20:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270800#M323396</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2009-11-06T20:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: 801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270801#M323397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you stated in your second post that you only want to authenticate your pc behind the phone so I would suggest you to configure ports with multi-host command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for Phone you need to configure MAB (mac authentication bypass)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the radius\ACS server you need to add the phone mac address as username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username:aabbcc112233&lt;/P&gt;&lt;P&gt;password:aabbcc112233&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mac format: aabbcc112233&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you want to authenticate your Phone and PC via 802.1x then you may go through this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a00808abf2d.shtml#MDA" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a00808abf2d.shtml#MDA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring Avaya phone for MDA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.avaya.com/usa/resource/assets/applicationnotes/802_1x_ciscomda.pdf" target="_blank"&gt;http://www.avaya.com/usa/resource/assets/applicationnotes/802_1x_ciscomda.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 21:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270801#M323397</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-11-06T21:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: 801.x and AVAYA</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270802#M323398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey JK, thanx for your help. Is there a way that the phone doesn't even have to do the MAB? just plugit in and then voila!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanx!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 23:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270802#M323398</guid>
      <dc:creator>lel_chavez</dc:creator>
      <dc:date>2009-11-06T23:16:16Z</dc:date>
    </item>
    <item>
      <title>Looking for options for</title>
      <link>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270803#M323399</link>
      <description>&lt;P&gt;Looking for options for similar options...&lt;/P&gt;&lt;P&gt;I have 802.1x working fine, need to work around the Avaya IP phones for a remote office..&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan xxx&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan yyy&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event fail retry 5 action authorize vlan zzz&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan xxx&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan xxx&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate 4000&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2014 21:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/801-x-and-avaya/m-p/1270803#M323399</guid>
      <dc:creator>thompson318</dc:creator>
      <dc:date>2014-12-08T21:34:54Z</dc:date>
    </item>
  </channel>
</rss>

