<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1X and multi-domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556380#M361734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Magnus for keeping us posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Oct 2010 15:01:31 GMT</pubDate>
    <dc:creator>Yudong Wu</dc:creator>
    <dc:date>2010-10-18T15:01:31Z</dc:date>
    <item>
      <title>dot1X and multi-domain</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556376#M361730</link>
      <description>&lt;P&gt;I have an C4506 with a&amp;nbsp; WS-X4548-GB-RJ45V module. I am running version&amp;nbsp; Version 12.2(54)SG, I have implementet 802.1X on the access-ports but I can´t get multi-domain configuration to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mostly the PC-client is connected to the phone and the phone is connected to the switchport. In the ACS5.1 loggs the client and telephone are authenticated correctly, The client runns EAP-TLS and the phone does MAB. The PC gets an IP address but it can´t reach anything, not even his default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I switch to multi-host it works and the client , and phone is able to communicate, but then I have security issues and timeout problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DOES ANY ONE OUT THERE HAVE THE SAME PROBLEM ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is my portconfiguration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet6/40&lt;BR /&gt; description 802.1X enablad port&amp;nbsp; ANC70101D03&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 94&lt;BR /&gt; qos trust device cisco-phone&lt;BR /&gt; authentication event fail action authorize vlan 229&lt;BR /&gt; authentication event server dead action authorize vlan 229&lt;BR /&gt; authentication event no-response action authorize vlan 229&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate server&lt;BR /&gt; mab&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout quiet-period 5&lt;BR /&gt; dot1x timeout tx-period 5&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt; service-policy input voice-services&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556376#M361730</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2019-03-11T00:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: dot1X and multi-domain</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556377#M361731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please collect "&lt;SPAN class="cExBold"&gt;sh dot1x int Gx/y details" in both multi-host and multi-domain mode after the authentication?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;By the way, are you using vlan 1 as data vlan?&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 21:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556377#M361731</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2010-09-30T21:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: dot1X and multi-domain</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556378#M361732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , It has to be a bug, I have logged a case with TAC " CaseID:615560039. The thing is that if I run multi-host mode everythning works , but then you have security issues, if I run multi-domain the client and phone gets an IP address but are not able to communicate (ex ping there default GW). The output of the commands you requested looks okej, in multi-domain you have one voice and one data , and in multi-host you have one data....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 07:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556378#M361732</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2010-10-01T07:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: dot1X and multi-domain</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556379#M361733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now Cisco TAC has find out that there is a bug in the 12.2 (54) SG release regarding multi-domain and C4506. I have now downgraded the IOS to 12.2 (53) SG3. And now it works.&lt;/P&gt;&lt;P&gt;Bug ID is: CSCtj56811 (It was just posted).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 13:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556379#M361733</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2010-10-18T13:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: dot1X and multi-domain</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556380#M361734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Magnus for keeping us posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Oct 2010 15:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-and-multi-domain/m-p/1556380#M361734</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2010-10-18T15:01:31Z</dc:date>
    </item>
  </channel>
</rss>

