<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x multidomain not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560611#M346664</link>
    <description>&lt;P&gt;Hello team:&lt;/P&gt;&lt;P&gt;I configured multidomain on a Cisco 3650 port (12.2(53)SE1), and connected a 7941 Phone and laptop behind it. The phone gets successfully authenticated but the PC does not get fully connected. The PC adapter´s icon shows a "authentication error" message.&lt;/P&gt;&lt;P&gt;The same PC, connected to another port (same commands except "authentication host-mode multi-domain") works perfect, including new VLAN and ACL assigned from ACS.&lt;/P&gt;&lt;P&gt;¿Any ideas of what I could be doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration on the switch port where the PC chained to the phone fails:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/6&lt;BR /&gt; switchport access vlan 701&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 123&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 704&lt;BR /&gt; authentication event no-response action authorize vlan 701&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication open&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 60&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration on the switch port where the PC without a phone works OK (exactly the same config, except for multidomain):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/7&lt;BR /&gt; switchport access vlan 701&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 123&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 704&lt;BR /&gt; authentication event no-response action authorize vlan 701&lt;BR /&gt; authentication open&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 60&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;When the PC fails to get connected, I see the following messages on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sep 17 18:36:18: %DOT1X-5-SUCCESS: Authentication successful for client (0023.ae&lt;BR /&gt;b8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-7-RESULT: Authentication result 'success' from 'dot1x'&lt;BR /&gt; for client (0023.aeb8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310&lt;BR /&gt;080FDFC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-5-FAIL: Authorization failed for client (0023.aeb8.ce4&lt;BR /&gt;4) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;BR /&gt;Sep 17 18:36:18: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for&lt;BR /&gt;client (0023.aeb8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FD&lt;BR /&gt;FC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0023.ae&lt;BR /&gt;b8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards, Rogelio&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:25:05 GMT</pubDate>
    <dc:creator>rogelioalvez</dc:creator>
    <dc:date>2019-03-11T00:25:05Z</dc:date>
    <item>
      <title>802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560611#M346664</link>
      <description>&lt;P&gt;Hello team:&lt;/P&gt;&lt;P&gt;I configured multidomain on a Cisco 3650 port (12.2(53)SE1), and connected a 7941 Phone and laptop behind it. The phone gets successfully authenticated but the PC does not get fully connected. The PC adapter´s icon shows a "authentication error" message.&lt;/P&gt;&lt;P&gt;The same PC, connected to another port (same commands except "authentication host-mode multi-domain") works perfect, including new VLAN and ACL assigned from ACS.&lt;/P&gt;&lt;P&gt;¿Any ideas of what I could be doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration on the switch port where the PC chained to the phone fails:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/6&lt;BR /&gt; switchport access vlan 701&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 123&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 704&lt;BR /&gt; authentication event no-response action authorize vlan 701&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication open&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 60&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration on the switch port where the PC without a phone works OK (exactly the same config, except for multidomain):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/7&lt;BR /&gt; switchport access vlan 701&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 123&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 704&lt;BR /&gt; authentication event no-response action authorize vlan 701&lt;BR /&gt; authentication open&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 60&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;When the PC fails to get connected, I see the following messages on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sep 17 18:36:18: %DOT1X-5-SUCCESS: Authentication successful for client (0023.ae&lt;BR /&gt;b8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-7-RESULT: Authentication result 'success' from 'dot1x'&lt;BR /&gt; for client (0023.aeb8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310&lt;BR /&gt;080FDFC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-5-FAIL: Authorization failed for client (0023.aeb8.ce4&lt;BR /&gt;4) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;BR /&gt;Sep 17 18:36:18: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for&lt;BR /&gt;client (0023.aeb8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FD&lt;BR /&gt;FC&lt;BR /&gt;Sep 17 18:36:18: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0023.ae&lt;BR /&gt;b8.ce44) on Interface Fa0/6 AuditSessionID 0A01460A000000310080FDFC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards, Rogelio&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560611#M346664</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2019-03-11T00:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560612#M346665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys, I found the context in which it fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch fails to authorize (but authentication is still OK) &lt;STRONG&gt;if CiscoSecure ACS sends the contents of an ACL&lt;/STRONG&gt; &lt;STRONG&gt;when the port is configured in multidomain&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not matter whether the PC is directly attached to the port or behind a phone. As soon as I include the multidomain command, the switch fails to grant the PC the right to get into the port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I remove the ACL information (either downloadable ACL or inacl# entries), the PC is successfully authenticated and moved to the VLAN ordered by ACS to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By other hand, as I mentioned in my previous note, the ACL is succesfully loaded to the port if this port is not configured is not in multidomain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the problem is with ACLs or ACL entries. ¿Shouldn´t this be supported on multidomain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;Regards, Rogelio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Sep 2010 20:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560612#M346665</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2010-09-17T20:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560613#M346666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rogelio&lt;/P&gt;&lt;P&gt;Can you check this on you configration:&lt;/P&gt;&lt;P&gt;1. Remove authentication open from port config&lt;/P&gt;&lt;P&gt;2. Add ACL (some general ACL with few entries) to port&lt;/P&gt;&lt;P&gt;3. Add ip device tracking to global config&lt;/P&gt;&lt;P&gt;4. After authentication check following: sh ip acccess-l and sh ip access-l int fax/x. If output from second command is empty try execute sh auth session int fax/x detail. Switch should correctly recognize ip address for ip phone and PC. If not this is a bug in IOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Stas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 21:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560613#M346666</guid>
      <dc:creator>kuchma.stanislav</dc:creator>
      <dc:date>2010-09-20T21:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560614#M346667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stan, thank you very much for your advice.&lt;/P&gt;&lt;P&gt;I will check on this tomorrow when I test in the customer site, and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 21:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560614#M346667</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2010-09-20T21:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560615#M346668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stas:&lt;/P&gt;&lt;P&gt;I tested as suggested, without success. Basically, I removed the "authentication open" command, added an ACL to the port (permit ip any any), and the "ip device tracking" command.&lt;/P&gt;&lt;P&gt;Now the switch failed to authorize BOTH ports (PC and Phone). Just in case of interest:&lt;/P&gt;&lt;P&gt;1. The output of the "show ip access-list interface Fa0/6" commands is empty&lt;/P&gt;&lt;P&gt;2. The output of the "show auth session int fa 0/6" command is the following&lt;/P&gt;&lt;P&gt;Switch# sh auth session int fa0/6&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/6&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; UNRESPONSIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Guest Vlan&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; 701&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A01460A0000009814F3D712&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x000000A2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xAB000098&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;/P&gt;&lt;P&gt;Switch#&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;Finally, I collecte a set of syslog messages, just in case someone would like to take a look. 001e.138c.5bf5 is the Phone`s MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Regards, Rogelio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 18:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560615#M346668</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2010-09-21T18:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560616#M346669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rogelio&lt;/P&gt;&lt;P&gt;Could you also remove from fa0/6 following strings:&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize vlan 704&lt;BR /&gt; authentication event no-response action authorize vlan 701&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;Also if you can't use Downloadable ACL please remove ACL from fa0/6.&lt;/P&gt;&lt;P&gt;Next chek port settings. In output from sh auth sess int fa0/6 Oper host mode is multi-host. This is incorrect. It should be multi-domain.&lt;/P&gt;&lt;P&gt;Next in first message you wrote that you have phone and PC behind phone. How you phone authenticated? By dot1x or MAB? In multidomain mode ACS should provide for switch av-pair for voice vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example from 3750 with MAB for phone and open auth for PC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh authentication sessions interface gigabitEthernet 3/0/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet3/0/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 0001.0001.0001&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp;&amp;nbsp; x.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 000100010001&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; VOICE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; AC112E6A000002B5DA302795&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x000007AE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x590002B5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Stas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 19:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560616#M346669</guid>
      <dc:creator>kuchma.stanislav</dc:creator>
      <dc:date>2010-09-21T19:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560617#M346670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Stas:&lt;/P&gt;&lt;P&gt;I am also confused about the output of the switch, since the configuration of the port says "multidomain".I will start it over from zero and let you know the results.&lt;/P&gt;&lt;P&gt;With respect to the phone, I am authenticating it with 802.1X. This works OK. I am not using MAB for it.&lt;/P&gt;&lt;P&gt;I have never used Downloadable ACLs. Instead, I have been using Cisco avpairs ip:inacl#xx=permit ip &lt;FROM&gt; &lt;TO&gt;. They work OK when not in multidomain.&lt;/TO&gt;&lt;/FROM&gt;&lt;/P&gt;&lt;P&gt;I plan to visit the customer site in two or three days. I will let you know as soon as I get new output.&lt;/P&gt;&lt;P&gt;Thank you for your support.&lt;/P&gt;&lt;P&gt;Rogelio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Sep 2010 01:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560617#M346670</guid>
      <dc:creator>rogelioalvez</dc:creator>
      <dc:date>2010-09-22T01:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560618#M346671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;I have experiensed the same problem and it has to be a BUG, I have a C4506 with gig access-ports, I have ACS5.1 and Cisco 7940 phones, if i run multi-host it works fine but then i have security issues, if i switch to multi-domain al looks fine (success in ACS loggs and debug output) but the phone and client are not able to communicate (ex can´t ping the default gw), the phone and client recieves an ip address.&lt;/P&gt;&lt;P&gt;I have logged a case at cisco TAC and are wating for an answer.&lt;/P&gt;&lt;P&gt;/Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 08:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560618#M346671</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2010-10-01T08:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560619#M346672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever get an answer for this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 15:08:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560619#M346672</guid>
      <dc:creator>sullyjman12</dc:creator>
      <dc:date>2011-07-05T15:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x multidomain not working</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560620#M346673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Bug with Multi Domain Authentication was fixed in Catalyst IOS since 12.5.50&lt;STRONG&gt;SE5&lt;/STRONG&gt; (Oct, 2010). I think most IOS's released after Oct,2010 include fix, but for me problem in 3750-48PSS was gone after I updated to 12.2.50&lt;STRONG&gt;SE5&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 20:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multidomain-not-working/m-p/1560620#M346673</guid>
      <dc:creator>kuchma.stanislav</dc:creator>
      <dc:date>2011-07-05T20:51:00Z</dc:date>
    </item>
  </channel>
</rss>

