<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB with Cisco Phone - Authorization failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245277#M399046</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please provide the below mentioned info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug mab all&lt;/P&gt;&lt;P&gt;debug radius&lt;/P&gt;&lt;P&gt;show authentication session interface &lt;INTERFACE-ID&gt;&lt;/INTERFACE-ID&gt;&lt;/P&gt;&lt;P&gt;error message from the NPS &amp;gt; event viewer&lt;/P&gt;&lt;P&gt;show mac address-table interface &lt;INTERFACE-ID&gt;&lt;/INTERFACE-ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I beleive the mac address of the phone is 442b.03a2.f9e8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 May 2013 14:29:08 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-07T14:29:08Z</dc:date>
    <item>
      <title>MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245276#M399042</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using MAB to authenticate clients and Cisco IP Phones against a Microsoft NPS Radius server. Everything is working perfectly, except for 1 Cisco phone. The phone is successfully authentication, but authorization fails. The switch port has the following configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt; switchport access vlan 500&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport nonegotiate&lt;/P&gt;&lt;P&gt; switchport voice vlan 92&lt;/P&gt;&lt;P&gt; no logging event link-status&lt;/P&gt;&lt;P&gt; srr-queue bandwidth share 1 30 35 5&lt;/P&gt;&lt;P&gt; priority-queue out&lt;/P&gt;&lt;P&gt; authentication control-direction in&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize voice&lt;/P&gt;&lt;P&gt; authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate 10800&lt;/P&gt;&lt;P&gt; authentication timer inactivity 1800&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; mls qos trust device cisco-phone&lt;/P&gt;&lt;P&gt; mls qos trust cos&lt;/P&gt;&lt;P&gt; macro description mab&lt;/P&gt;&lt;P&gt; auto qos voip cisco-phone&lt;/P&gt;&lt;P&gt; storm-control broadcast level 5.00&lt;/P&gt;&lt;P&gt; storm-control action shutdown&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt; service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I receive the following RADIUS logging from the client authentication process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.349: RADIUS:&amp;nbsp;&amp;nbsp; 4D 8F 05 AB 00 00 01 37 00 01 02 00 0A 19 0A 84 00 00 00 00 00 00 00 00 00 00 00 00 01 CE 47 DF 2A A4 B3 70 00 00 00 00 00 00 5F 79&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ M7G*p_y]&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.349: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 34&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.349: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 28&amp;nbsp; "device-traffic-class=voice"&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.358: RADIUS(00002749): Received from id 1645/128&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.366: %MAB-5-SUCCESS: Authentication successful for client (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002706ED82EB13&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.374: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002706ED82EB13&lt;/P&gt;&lt;P&gt;SER-02-SW01#clear authentication&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 15:24:53.383: &lt;STRONG&gt;%AUTHMGR-5-FAIL: Authorization failed or unapplied for client&lt;/STRONG&gt; (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002706ED82EB13&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;I checked online and blog posts and forums suggest to check the usage of downloadable access-list, but they aren't used in the switch. As mentioned, all Cisco IP Phones work perfectly, except this one. I already removed the object from Active Directory and created a new object from scratch, but the same result. I also tried another port on the switch, still an authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I have no idea where to look further, so maybe some of you can help me!!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245276#M399042</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2019-03-11T03:24:13Z</dc:date>
    </item>
    <item>
      <title>MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245277#M399046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please provide the below mentioned info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug mab all&lt;/P&gt;&lt;P&gt;debug radius&lt;/P&gt;&lt;P&gt;show authentication session interface &lt;INTERFACE-ID&gt;&lt;/INTERFACE-ID&gt;&lt;/P&gt;&lt;P&gt;error message from the NPS &amp;gt; event viewer&lt;/P&gt;&lt;P&gt;show mac address-table interface &lt;INTERFACE-ID&gt;&lt;/INTERFACE-ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I beleive the mac address of the phone is 442b.03a2.f9e8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 14:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245277#M399046</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T14:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245278#M399047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached the output of the debug and show commands. The NPS logging only shows a succesfull login, so nothing special there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 16:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245278#M399047</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-07T16:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245279#M399048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rene, the debugs shows that radius successfully authenticated the access-request and did send the required attribute to put the phone in voice vlan but it seems like some restriction is preventing the authorization part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 18:30:26.724: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 28&amp;nbsp; "device-traffic-class=voice"&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 18:30:26.724: RADIUS(00002766): Received from id 1645/81&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 18:30:26.732: mab-ev(Gi1/0/39): MAB received an Access-Accept for 0x1A00005F (442b.03a2.f9e8)&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 18:30:26.732: %MAB-5-SUCCESS: Authentication successful for client (442b.03a2.f9e8) on Interface Gi1/0/39&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You wrote that you have tried other ports as well and same issue. Do we have any phone connected to a different interface/port working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 17:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245279#M399048</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T17:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245280#M399049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problems only occurs with this specific Cisco IP Phone and only on this specific Cisco Catalyst 3750X switch / stack. All other Cisco IP Phones are working fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We patched the specific phone to another 3750X switch (with the same IOS firmware) and authentication and authorization is working fine on that switch. So it seems like a bug, but a bug for only one Cisco IP Phone?!?!?!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 17:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245280#M399049</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-07T17:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245281#M399050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please share the interface configuration of another 3750X where you patch the IP phone and it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 18:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245281#M399050</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T18:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245282#M399051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configuration of all MAB-enabled switch ports are exactly the same as in the first post. We use a macro configuration to configure the switch ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 18:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245282#M399051</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-07T18:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245283#M399052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;let's try this&lt;/P&gt;&lt;P&gt;unplug the phone&lt;/P&gt;&lt;P&gt;clear the mac address table for that interface.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;clear mac address-table interface &lt;INT id=""&gt;&lt;/INT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Plug the phone back to the interface&lt;/P&gt;&lt;P&gt;Go to the interface execute&lt;/P&gt;&lt;P&gt; shut and no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;share the results plz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 18:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245283#M399052</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T18:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245284#M399053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still get the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;00 00 00 00 00 01 CE 47 DF 2A A4 B3 70 00 00 00 00 00 00 66 CA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ M7G*pf]&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.722: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 34&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.722: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 28&amp;nbsp; "device-traffic-class=voice"&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: RADIUS(00002769): Received from id 1645/205&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: mab-ev(Gi1/0/39): MAB received an Access-Accept for 0xE601003B (442b.03a2.f9e8)&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: %MAB-5-SUCCESS: Authentication successful for client (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002722EEA070B8&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: mab-sm(Gi1/0/39): Received event 'MAB_RESULT' on handle 0xE601003B&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab : during state mab_authorizing, got event 5(mabResult)&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: @@@ mab : mab_authorizing -&amp;gt; mab_terminate&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: mab-ev(Gi1/0/39): Deleted credentials profile for 0xE601003B (dot1x_mac_auth_442b.03a2.f9e8)&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: mab-ev(Gi1/0/39): Sending event (2) to AuthMGR for 442b.03a2.f9e8&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.739: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002722EEA070B8&lt;/P&gt;&lt;P&gt;SER-02-SW01#&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:27.747: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (442b.03a2.f9e8) on Interface Gi1/0/39 AuditSessionID 0A194B0400002722EEA070B8&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:28.728: %SWITCH_QOS_TB-5-TRUST_DEVICE_DETECTED: cisco-phone detected on port Gi1/0/39, port's configured trust state is now operational.&lt;/P&gt;&lt;P&gt;SER-02-SW01#&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 7 20:18:29.668: %SWITCH_QOS_TB-5-TRUST_DEVICE_DETECTED: cisco-phone detected on port Gi1/0/39, port's configured trust state is now operational.&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 18:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245284#M399053</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-07T18:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245285#M399054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is strange. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to see more debugs to narrow it down. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dot1x all&lt;/P&gt;&lt;P&gt;debug mab all&lt;/P&gt;&lt;P&gt;debug radius&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shut/ no shut the interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch# show mab int &lt;INT id=""&gt; details&lt;/INT&gt;&lt;/P&gt;&lt;P&gt;switch# show dot1x int &lt;INT id=""&gt; details&lt;/INT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also send me a scree shot of the error message and policy we are hitting on the radius server&lt;/P&gt;&lt;P&gt;go to NPS &amp;gt; administrative tools &amp;gt; event viewer &amp;gt; Custom views &amp;gt; server roles &amp;gt; network policy and access-services.&lt;/P&gt;&lt;P&gt;go to NPS &amp;gt; administrative tools &amp;gt; NPS &amp;gt; policies &amp;gt; network policies &amp;gt; edit policy &amp;gt; radius attributes &amp;gt; standard and vendor specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 23:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245285#M399054</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T23:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245286#M399055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tell me something. Strange is an understatement &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached the requested information. The NPS event logging only shows "access granted" messages for the client, which relate to the Authentication succeed messages from MAB.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 07:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245286#M399055</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-08T07:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245287#M399056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Again analysed the debug you sent over. Unfortunately, nothing new in that too. The Mab session JUST shows authentication status success and not authorized. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAB SM state&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = TERMINATE&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Authen Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = SUCCESS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have a different phone working fine with the same switch on a &lt;SPAN style="text-decoration: underline;"&gt;different port/interface&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no, than please share the following info from the &lt;STRONG&gt;working&lt;/STRONG&gt; and &lt;STRONG&gt;non-working&lt;/STRONG&gt; switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run | in aaa&lt;/P&gt;&lt;P&gt;show ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it doesn't help us, two things I'd be interested in here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Sniffer traces of the Radius packet exchange between this switch and the server (having the shared secret would be ideal but isn't strictly&amp;nbsp; needed) and&lt;/P&gt;&lt;P&gt;- It may be worthwhile to run the same debugs on one of the working switches so I can double-check to make sure there isn't a slight difference in the authorization response we received.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dot1x all&lt;/P&gt;&lt;P&gt;debug mab all&lt;/P&gt;&lt;P&gt;debug radius&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last restore would be to reload the switch (in case it's possible &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 13:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245287#M399056</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T13:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245288#M399057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other phones work on the same switch on the same port, on the same switch on different port and on different switches. I am thinking about a bug, so we will schedule a reload of the switch to see if this solves the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 13:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245288#M399057</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-08T13:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245289#M399058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alrighty...I did see the similar issue for someother customer couple of years ago and we finally reloaded the switch to get that resolved. I wish this may do magic in your case as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 13:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245289#M399058</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T13:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245290#M399059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you must have observed that it's just an issue with&amp;nbsp; this particular model of Cisco IP phone, hence I would recommend&amp;nbsp; checking the various conditions that have been specified on the radius&amp;nbsp; server for the Cisco IP phone, as usually the dACL's/conditions ( rules)&amp;nbsp; are a reason for the authorization failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May I know if there's any other Authenticator in the Network such as Cisco ISE ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 20:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245290#M399059</guid>
      <dc:creator>msonnie</dc:creator>
      <dc:date>2013-05-08T20:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245291#M399060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Before we reload try &lt;/P&gt;&lt;P&gt;try disabling dot1x globally and re-apply it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; no dot1x system auth control&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; dot1x system auth control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 20:23:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245291#M399060</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T20:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245292#M399061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Didn't help either. A reboot of the switch solved the problem. So I guess some kind of bug or something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx for all the support&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 14:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245292#M399061</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-09T14:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245293#M399062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mohit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A reboot of the switch did the trick!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 14:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245293#M399062</guid>
      <dc:creator>Rene Jorissen</dc:creator>
      <dc:date>2013-05-09T14:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245294#M399063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for updating Rene. I suggested for disabling and re-enabling the dot1x globally to see in case it got stuck somewhere. However, it looks the thought didn't go well. Would appreciate if you mark it resolved so that someone else can take benefits out of it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your welcome &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a nice day!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 15:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245294#M399063</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-09T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: MAB with Cisco Phone - Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245295#M399064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mohit, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks for Joining the discussion. Actually, I thought the same thing initially that we might need to apply port-based ACL. We did clarify this piece in this post &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3931416#3931416"&gt;https://supportforums.cisco.com/message/3931416#3931416&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screen shots are attached from NPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 15:04:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-with-cisco-phone-authorization-failed/m-p/2245295#M399064</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-09T15:04:50Z</dc:date>
    </item>
  </channel>
</rss>

