<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic port  disabled in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810418#M484795</link>
    <description>&lt;P&gt;I have this issue and could not figure out why it is happening&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;sho int Gi4/0/16 &lt;BR /&gt;GigabitEthernet4/0/16 is down, line protocol is down&lt;STRONG&gt; (err-disabled)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;interface GigabitEthernet4/0/16&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 50&lt;BR /&gt;device-tracking&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;trust device cisco-phone&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;storm-control broadcast level 0.10&lt;BR /&gt;storm-control multicast level 0.10&lt;BR /&gt;auto qos voip cisco-phone &lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input AutoQos-4.0-CiscoPhone-Input-Policy&lt;BR /&gt;service-policy output AutoQos-4.0-Output-Policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;switch log&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Feb 26 12:25:33.129: %PM-4-ERR_DISABLE: security-violation error detected on Gi4/0/16, putting Gi4/0/16 in err-disable state&lt;/LI&gt;
&lt;LI&gt;Feb 26 12:25:33.133: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet4/0/16, new MAC address (9890.96c2.2eed) is seen.AuditSessionID Unassigned&lt;/LI&gt;
&lt;LI&gt;Feb 26 12:25:34.130: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet4/0/16, changed state to down&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 26 Feb 2019 22:56:46 GMT</pubDate>
    <dc:creator>BigK</dc:creator>
    <dc:date>2019-02-26T22:56:46Z</dc:date>
    <item>
      <title>port  disabled</title>
      <link>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810418#M484795</link>
      <description>&lt;P&gt;I have this issue and could not figure out why it is happening&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;sho int Gi4/0/16 &lt;BR /&gt;GigabitEthernet4/0/16 is down, line protocol is down&lt;STRONG&gt; (err-disabled)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;interface GigabitEthernet4/0/16&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 50&lt;BR /&gt;device-tracking&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;trust device cisco-phone&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;storm-control broadcast level 0.10&lt;BR /&gt;storm-control multicast level 0.10&lt;BR /&gt;auto qos voip cisco-phone &lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input AutoQos-4.0-CiscoPhone-Input-Policy&lt;BR /&gt;service-policy output AutoQos-4.0-Output-Policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;switch log&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Feb 26 12:25:33.129: %PM-4-ERR_DISABLE: security-violation error detected on Gi4/0/16, putting Gi4/0/16 in err-disable state&lt;/LI&gt;
&lt;LI&gt;Feb 26 12:25:33.133: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet4/0/16, new MAC address (9890.96c2.2eed) is seen.AuditSessionID Unassigned&lt;/LI&gt;
&lt;LI&gt;Feb 26 12:25:34.130: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet4/0/16, changed state to down&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 26 Feb 2019 22:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810418#M484795</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-02-26T22:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: port  disabled</title>
      <link>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810532#M484797</link>
      <description>&lt;P&gt;Hi,please shut the port than on the port type no switchport port-security and no shut the port.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 05:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810532#M484797</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2019-02-27T05:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: port disabled</title>
      <link>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810549#M484830</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you try the command 'authentication mac-move permit'?&lt;BR /&gt;&lt;BR /&gt;**** Please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Feb 2019 06:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810549#M484830</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-27T06:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: port  disabled</title>
      <link>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810569#M484831</link>
      <description>&lt;P&gt;I had the same issue where I was doing dot1x for an endpoint where was behind an IP&amp;nbsp;phone. My workaround is to add:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;authentication violation replace&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 06:54:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-disabled/m-p/3810569#M484831</guid>
      <dc:creator>socratesp1980</dc:creator>
      <dc:date>2019-02-27T06:54:30Z</dc:date>
    </item>
  </channel>
</rss>

