<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi Auth - data device on Voice domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multi-auth-data-device-on-voice-domain/m-p/3882737#M471816</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a handful of HP printers in the voice domain even their IP from data VLAN and their authorization is correct, they are directly connected to the switch(no phone in between) and we are using multi-auth, below the config and the details, any idea why not in data domain?&lt;/P&gt;&lt;P&gt;hardware cat 4510 with sup 8, running version 3.8.5&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4510#show authentication sessions int gig 1/36 det&lt;BR /&gt;Interface: GigabitEthernet1/36&lt;BR /&gt;MAC Address: ace2.d3xx.xxxx&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.100.x.x&lt;BR /&gt;User-Name: AC-E2-D3-xx-xx-xx&lt;BR /&gt;Status: Authorized&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Domain: VOICE&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: 0A640B0400004D707A17E108&lt;BR /&gt;Acct Session ID: 0x000063FD&lt;BR /&gt;Handle: 0xFB00007D&lt;BR /&gt;Current Policy: POLICY_Gi1/36&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;/P&gt;&lt;P&gt;ACS ACL: xACSACLx-IP-PRINTERS-5cf86881&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;4510#show run int gig 1/36&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 937 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/36&lt;BR /&gt;description USER DATA and VOIP PHONES&lt;BR /&gt;switchport access vlan 105&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport block multicast&lt;BR /&gt;switchport voice vlan 115&lt;BR /&gt;ip device tracking maximum 10&lt;BR /&gt;no logging event link-status&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action reinitialize vlan 105&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;storm-control broadcast level 0.50&lt;BR /&gt;storm-control action trap&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;spanning-tree guard root&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;4510#&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 17:36:56 GMT</pubDate>
    <dc:creator>mustafa83</dc:creator>
    <dc:date>2019-07-01T17:36:56Z</dc:date>
    <item>
      <title>Multi Auth - data device on Voice domain</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-auth-data-device-on-voice-domain/m-p/3882737#M471816</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a handful of HP printers in the voice domain even their IP from data VLAN and their authorization is correct, they are directly connected to the switch(no phone in between) and we are using multi-auth, below the config and the details, any idea why not in data domain?&lt;/P&gt;&lt;P&gt;hardware cat 4510 with sup 8, running version 3.8.5&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4510#show authentication sessions int gig 1/36 det&lt;BR /&gt;Interface: GigabitEthernet1/36&lt;BR /&gt;MAC Address: ace2.d3xx.xxxx&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.100.x.x&lt;BR /&gt;User-Name: AC-E2-D3-xx-xx-xx&lt;BR /&gt;Status: Authorized&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Domain: VOICE&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: 0A640B0400004D707A17E108&lt;BR /&gt;Acct Session ID: 0x000063FD&lt;BR /&gt;Handle: 0xFB00007D&lt;BR /&gt;Current Policy: POLICY_Gi1/36&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;/P&gt;&lt;P&gt;ACS ACL: xACSACLx-IP-PRINTERS-5cf86881&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;4510#show run int gig 1/36&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 937 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/36&lt;BR /&gt;description USER DATA and VOIP PHONES&lt;BR /&gt;switchport access vlan 105&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport block multicast&lt;BR /&gt;switchport voice vlan 115&lt;BR /&gt;ip device tracking maximum 10&lt;BR /&gt;no logging event link-status&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action reinitialize vlan 105&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;storm-control broadcast level 0.50&lt;BR /&gt;storm-control action trap&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;spanning-tree guard root&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;4510#&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 17:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-auth-data-device-on-voice-domain/m-p/3882737#M471816</guid>
      <dc:creator>mustafa83</dc:creator>
      <dc:date>2019-07-01T17:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multi Auth - data device on Voice domain</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-auth-data-device-on-voice-domain/m-p/3882759#M471817</link>
      <description>The first step would be to look at the mac in the context visibility database, are they being profiled as phones?  If yes, then you need to correct the profiling issue.&lt;BR /&gt;&lt;BR /&gt;If they are not being profiled as phones, you will have to check the authorization rule they are hitting, then from there confirm the authorization profile result doesn't include the check box for "Voice Domain Permission", aka cisco-av-pair = device-traffic-class=voice.</description>
      <pubDate>Mon, 01 Jul 2019 18:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-auth-data-device-on-voice-domain/m-p/3882759#M471817</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-01T18:15:42Z</dc:date>
    </item>
  </channel>
</rss>

