<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Shoretel Phones in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693836#M495055</link>
    <description>&lt;P&gt;Wondering if anyone has any experience implementing ISE with Shoretel phones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most of our end users have their PC connected through their Shoretel phone switch. We've had a range of issues trying to implement ISE 2.2 in our environment and most seem related to the phones. We run 2960s switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping someone has some experience they could share ....&lt;/P&gt;</description>
    <pubDate>Thu, 23 Aug 2018 16:08:09 GMT</pubDate>
    <dc:creator>FredW</dc:creator>
    <dc:date>2018-08-23T16:08:09Z</dc:date>
    <item>
      <title>Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693836#M495055</link>
      <description>&lt;P&gt;Wondering if anyone has any experience implementing ISE with Shoretel phones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most of our end users have their PC connected through their Shoretel phone switch. We've had a range of issues trying to implement ISE 2.2 in our environment and most seem related to the phones. We run 2960s switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoping someone has some experience they could share ....&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 16:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693836#M495055</guid>
      <dc:creator>FredW</dc:creator>
      <dc:date>2018-08-23T16:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693867#M495056</link>
      <description>&lt;P&gt;If you can provide more details about the issues, it would be helpful. But here are some information that may help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-with-shoretel-ip-phone/td-p/3566895" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-with-shoretel-ip-phone/td-p/3566895&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/ise-mab-and-shoretel-phones/td-p/2687440" target="_blank"&gt;https://community.cisco.com/t5/policy-and-access/ise-mab-and-shoretel-phones/td-p/2687440&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 16:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693867#M495056</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-23T16:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693941#M495057</link>
      <description>&lt;P&gt;Thanks for the response, Howon. I have seen the two Shoretel specific posts you referred to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Here is more detail on our main issue:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have Shoretel phone connected to 2960s switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Behind phone is Windows 10 PC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using dot1.x with cert for computer authentication and MAB for phone and printers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phone will have connectivity and service but PC will not have ethernet connectivity. Logs report dot1x and MAB are authorized, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only way to get PC on network is to remove the dot1.x/mab config from switchport.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Port interface configuration:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;switchport access vlan 10&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 200&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;
&lt;P&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 17:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3693941#M495057</guid>
      <dc:creator>FredW</dc:creator>
      <dc:date>2018-08-23T17:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694063#M495058</link>
      <description>&lt;P&gt;Are you saying the switch shows both Phone and PC authorized but only Phone is functional? Can you share the output of 'show authentication session interface Gig x/y/z detail'?&amp;nbsp;Also, post the authentication details on the ISE for both the phone and the PC.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 21:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694063#M495058</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-23T21:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694070#M495119</link>
      <description>&lt;P&gt;Yes, that is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the switchport output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show authentication sessions int gigabitEthernet 2/0/37&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; Domain&amp;nbsp; Status Fg Session ID&lt;/P&gt;
&lt;P&gt;----------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Gi2/0/37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; c434.6b6f.534b dot1x&amp;nbsp;&amp;nbsp; DATA&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0A1911130000015E194F292F&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Within the ISE log I can see both the phone and PC successfully connecting.&lt;/P&gt;
&lt;P&gt;Gi2/0/37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0010.491e.992c mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOICE&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0A1911130000003700020106&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 21:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694070#M495119</guid>
      <dc:creator>FredW</dc:creator>
      <dc:date>2018-08-23T21:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Shoretel Phones</title>
      <link>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694131#M495120</link>
      <description>&lt;P&gt;Looks like both the PC and phone authenticated properly from the summary result. If you use the 'detail' keyword for the show authentication command it will also show you any permissions (VLAN, ACL, timers) and IP address for the endpoint as well. If the PC can't access the network even after reviewing the details, you may need to perform packet captures on the PC and on the switch to see where the traffic is getting dropped. Are there any settings you can alter on the phone?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 00:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shoretel-phones/m-p/3694131#M495120</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-24T00:35:50Z</dc:date>
    </item>
  </channel>
</rss>

