<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE PC behind the phone issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736484#M488828</link>
    <description>&lt;P&gt;Hi Ditter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think that once you configure a port to authenticate the endpoints, there is no way to authenticate just the phone and not the PC.&lt;/P&gt;
&lt;P&gt;But I'm ready to be corrected if I'm wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tmsna&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 14:05:18 GMT</pubDate>
    <dc:creator>Tmsna</dc:creator>
    <dc:date>2018-10-31T14:05:18Z</dc:date>
    <item>
      <title>Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736477#M488826</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am facing the following issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a cisco 7841 ip phone and i am using its switch in order to connect the user PC behind the phone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to execute MAB (not 802.1x) through ISE but &lt;U&gt;&lt;STRONG&gt;only&lt;/STRONG&gt; &lt;/U&gt;for the phone and not for the PC (i need PC to be freely connect to the DHCP VLAN).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So i thought if i use the switch command : &lt;U&gt;&lt;STRONG&gt;authentication host-mode multi-host &lt;/STRONG&gt;&lt;/U&gt; then the phone could get authorized through ISE &amp;amp; MAB and then the PC could connect without the need to pass the authentication/authorization process).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i have the command &lt;U&gt;&lt;STRONG&gt;authentication host-mode multi-domain &lt;/STRONG&gt;&lt;/U&gt;then the phone gets authorized from ISE but the PC does not get authorized ( i suppose that it has to do with ISE configuration) &lt;STRONG&gt;&lt;U&gt;but the problem is that&amp;nbsp; &lt;/U&gt;&lt;/STRONG&gt;as i mentioned i prefer this PC to be connected without passing any mab process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas how to do this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switch config is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet4/23&lt;BR /&gt;&amp;nbsp;switchport access vlan XXX&amp;nbsp; &amp;lt;--- DHCP VLAN&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan VVV&amp;nbsp; &amp;lt;-- Voice VLAN&lt;BR /&gt;&amp;nbsp;no logging event link-status&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 14:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736477#M488826</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-31T14:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736484#M488828</link>
      <description>&lt;P&gt;Hi Ditter,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think that once you configure a port to authenticate the endpoints, there is no way to authenticate just the phone and not the PC.&lt;/P&gt;
&lt;P&gt;But I'm ready to be corrected if I'm wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tmsna&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 14:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736484#M488828</guid>
      <dc:creator>Tmsna</dc:creator>
      <dc:date>2018-10-31T14:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736688#M488830</link>
      <description>&lt;P&gt;Following is the explanation of the multi-host and multi-domain:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;multi-host allows multiple mac addresses in DATA domain. Only first one is authenticated.&lt;/P&gt;
&lt;P&gt;multi-domain allows Only 1 mac address in DATA domain and only 1 mac address in VOICE domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is happening when you use multi-host?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 17:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736688#M488830</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-31T17:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736857#M488831</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As i look it now i also think the same as you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What i did a little while ago (after having posted this thread) in order to have the PC also authenticate through MAB was to let the PC to be authorized by the last rule in the authorization tree which is permit access. So now the phone is authorized by MAB and the PC behind the phone is authorized by the default permit.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 20:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736857#M488831</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-31T20:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736866#M488832</link>
      <description>&lt;P&gt;Hi Pan, as mentioned above i finally made it to work with MDA&amp;nbsp; but now both devices are authorized with MAB (as mentioned in the beginning of my email , i wanted only the phone to authorize via MAB and not the PC). Now by passing the default permit access i can have also the PC authorized by using MDA on the port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What i can not understand is how the switch behaves when a port is in MDA mode?&amp;nbsp; How the switch understands that a client is voip phone?&amp;nbsp; By CDP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 21:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3736866#M488832</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-31T21:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737121#M488833</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it seems that the best way of ensuring everything works is by using multi-auth instead of MDA just because of the fact that a vm running on the PC will shutdown the port!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is your opinion?&amp;nbsp; What we lose if we use multi-auth instead of MDA for a Phone and a PC behind the phone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 09:44:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737121#M488833</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-11-01T09:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737362#M488834</link>
      <description>&lt;P&gt;Yeah, I agree with you.&lt;/P&gt;
&lt;P&gt;Cisco IOS platforms added multi-auth to support more flexibility. MDA is good if strictly enforcing one voice and one data endpoints.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 16:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737362#M488834</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-01T16:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737561#M488835</link>
      <description>&lt;P&gt;Multi-Auth includes all features of MDA plus allows multiple data MAC addresses to connect. For MDA if you want to prevent interface from disabling you can use 'authentication violation' interface command. Default is shutdown and difference between protect and restrict is whether event is logged or not. Restrict will log and alert the event when violation occurs while protect does not, however behavior is the same between the two in terms of access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;3560CX(config-if)#authentication violation ?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; protect&amp;nbsp;&amp;nbsp; Protect the port&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; replace&amp;nbsp;&amp;nbsp; Replace the existing session&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; restrict&amp;nbsp; Restrict the port&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; shutdown&amp;nbsp; SHUTDOWN the port&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 21:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737561#M488835</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-11-01T21:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737761#M488890</link>
      <description>&lt;P&gt;Hi Howon,&lt;/P&gt;
&lt;P&gt;thank you for your answer.&lt;/P&gt;
&lt;P&gt;What confuses me is the following:&lt;BR /&gt;Suppose that my switch configuration is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet4/23&lt;BR /&gt;&amp;nbsp;switchport access vlan XXX&amp;nbsp; &amp;lt;--- DHCP VLAN&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan VVV&amp;nbsp; &amp;lt;-- Voice VLAN&lt;BR /&gt;&amp;nbsp;no logging event link-status&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see the port configuration is ready to accept the voice and data devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The confusing thing for me is the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In ISE there is the option (in Common Tasks section) to define in an authorization profile the two following option:&lt;/P&gt;
&lt;P&gt;1.Vlan&lt;/P&gt;
&lt;P&gt;2. Voice Domain Permission&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See also attached png.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question is what is the meaning of these two options in ISE Authorization profile&amp;nbsp; if you have already programmed the switch port with the appropriate voice vlan commads?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thnaks,&lt;/P&gt;
&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 08:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737761#M488890</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-11-02T08:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737827#M488892</link>
      <description>&lt;P&gt;The Voice Domain option authorizes the device to use the voice domain(vlan) that is set on the port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VLAN Setting dynamically sets the &lt;STRONG&gt;Data&lt;/STRONG&gt; VLAN on the port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The two options should not be used in the same authorization profile. The VLAN setting should only be used it you want to change the VLAN from what is configured on the port.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 11:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737827#M488892</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2018-11-02T11:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737980#M488895</link>
      <description>&lt;P&gt;Thank you Cory,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so that means that even if a port is configured with voice vlan , the phone will not be able to use it unless in the authorization profile the VOICE DOMAIN PERMISSION is checked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can confirm that , i tested and works the way you described.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can also confirm that if VLAN and VOICE DOMAIN PERMISSION are both checked in the same authorization profile the data vlan does not seem to change as you also describe.&amp;nbsp; Any idea why is this happening? Why i am not able to do both changes in the same authorization profile?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3737980#M488895</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-11-02T14:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3738103#M488896</link>
      <description>&lt;P&gt;As Cory described voice domain permission allows access to the voice VLAN configured on the switch. When you send down VLAN ID along with the voice domain permission, the switch will dynamically assign voice VLAN for the phone. For older IOS versions (My guess is anything lower than 15.1), this was not the case and assigning both voice vlan permission and VLAN ID would not work on the switch and end up with authorization failure if I recall.&lt;/P&gt;
&lt;P&gt;Reading through the notes, it sounds like you are trying to assign permission for the PC behind the phone based on the phone's authentication. This is not possible as authorization profile is applied to the session (Or specific MAC address depending on how you look at it) not to the whole interface. In other words, the set of settings you defined on the phone authorization profile only applies to the phone's session/MAC. The PC has to be assigned its own authorization profile independent of phone's authorization profile by going through authentication on its own.&lt;/P&gt;
&lt;P&gt;Now, I technology aside, I do not understand the use case here to permit data access based on phone, but if you share the business requirement, there may be better ways to meet the requirement.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 17:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3738103#M488896</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-11-02T17:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE PC behind the phone issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3742077#M488897</link>
      <description>&lt;P&gt;Hi Howon, sorry for the delay in updating the thread...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My initial intention was&amp;nbsp; the PC to connect to the network without having to pass through a new authorization process. I understood that it was not possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did some tests with a switch running&amp;nbsp; 15.0.2 and i can send in an attached voip phone &lt;U&gt;both Voice Domain parmition as well as change the vlanid where it belongs.&lt;/U&gt;&amp;nbsp; Both actions can occur in the same autorization profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In another auth profile (only for data this time) i authorize attached PCs connected to the switch port of the voip phone and in this second authorization profile i can also assign dynamically a vlan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you all&amp;nbsp; for your contributions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 13:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pc-behind-the-phone-issue/m-p/3742077#M488897</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-11-08T13:54:18Z</dc:date>
    </item>
  </channel>
</rss>

