<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent Connectivity Issues w/DOT1X MDA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678461#M495742</link>
    <description>One of the things I've seen in the past is that QoS could be causing the problem.  Have you tried removing the QoS config and retest?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tim</description>
    <pubDate>Tue, 31 Jul 2018 16:47:51 GMT</pubDate>
    <dc:creator>Timothy Abbott</dc:creator>
    <dc:date>2018-07-31T16:47:51Z</dc:date>
    <item>
      <title>Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678430#M495741</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am seeing a strange intermittent connectivity issue for a dot1x session I'm testing out.&amp;nbsp; We are currently using ISE 2.3 with patch 4.&amp;nbsp; I'm testing out MDA for a Win10 machine and a Mitel 5320e IP phone.&amp;nbsp; Each receive it's own authorization profile.&amp;nbsp; The PC authenticates in the DATA domain (via dot1x) and the phone in the VOICE domain (via MAB).&amp;nbsp; Each works as expected when connected to it's own port.&amp;nbsp; However, when I place the PC behind the phone so that they both authenticate on the same port, I tend to lose connectivity randomly.&amp;nbsp; I ran a constant ping on both tests and get no packet loss on separate ports but around 1% when on the same port.&amp;nbsp; I also notice a brief bump in my connection to network applications.&amp;nbsp; I have the machine authorization policy common task configured to reauthenticate every 4 hours but no reauthentication for the IP phone authZ profile.&amp;nbsp; Here is a copy of the port config:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/1&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport nonegotiate&lt;BR /&gt; switchport voice vlan 30&lt;BR /&gt; ip device tracking probe count 1&lt;BR /&gt; ip device tracking probe interval 30&lt;BR /&gt; ip device tracking maximum 2&lt;BR /&gt; srr-queue bandwidth share 1 30 35 5&lt;BR /&gt; priority-queue out&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize&lt;BR /&gt; authentication event server dead action authorize voice&lt;BR /&gt; authentication event server alive action reinitialize&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate server&lt;BR /&gt; authentication violation restrict&lt;BR /&gt; mab&lt;BR /&gt; mls qos trust cos&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; auto qos trust&lt;BR /&gt; spanning-tree portfast edge&lt;BR /&gt; spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As stated before, they work as expected with no drops in connectivity when on separate ports but when together, that's when intermittent connectivity issues occur.&amp;nbsp; Let me know if you have any additional questions or need any further info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terence&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 16:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678430#M495741</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T16:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678461#M495742</link>
      <description>One of the things I've seen in the past is that QoS could be causing the problem.  Have you tried removing the QoS config and retest?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tim</description>
      <pubDate>Tue, 31 Jul 2018 16:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678461#M495742</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-07-31T16:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678463#M495743</link>
      <description>&lt;P&gt;Sure.&amp;nbsp; I'll give that a try right now.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 16:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678463#M495743</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T16:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678469#M495744</link>
      <description>&lt;P&gt;Ok so I have auto QoS removed from the interface I'm testing from and will monitor for about an hour.&amp;nbsp; My last constant ping results sent 1,459 packets and lost 21.&amp;nbsp; I've started a new continuous ping and will check the results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the meantime, if auto QoS is causing an issue, what alternative do I have to making sure voice traffic still gets priority over other data traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Terence&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 16:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678469#M495744</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T16:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678470#M495745</link>
      <description>&lt;P&gt;Looks like I'm still dropping packets and getting the same results.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 16:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678470#M495745</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T16:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678471#M495746</link>
      <description>If it does turn out to be QoS,  I would look to see if there is a defect for the switch code you are using and if it is resolved in a newer release.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;timn</description>
      <pubDate>Tue, 31 Jul 2018 16:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678471#M495746</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-07-31T16:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678472#M495747</link>
      <description>&lt;P&gt;I've just completed an IOS upgrade of all of our switches and dot1x issues were the main thing I looked for in the release notes.&amp;nbsp; My 4500E switches are running 3.8.6 for Sup-8E and 3.6.6 for Sup-7E.&amp;nbsp; My 3560CX test switch is running&amp;nbsp;15.2(4)E4 while our 2960X switches are running&amp;nbsp;15.2(2)E7.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 16:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678472#M495747</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T16:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678474#M495748</link>
      <description>Just out of curiosity, are you seeing the issue across all switch types?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Tim</description>
      <pubDate>Tue, 31 Jul 2018 17:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678474#M495748</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-07-31T17:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678475#M495749</link>
      <description>&lt;P&gt;So far just my 3560CX and one of the 4500E switches running the Sup-8E.&amp;nbsp; I haven't deployed campus wide in fear of what I'm experiencing now.&amp;nbsp; I'm testing various setups we have in our network to get an idea of what our users may or may not experience.&amp;nbsp; So far, the MDA on a single port appears to cause random drops which will be frustrating for our end users.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 17:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3678475#M495749</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2018-07-31T17:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Connectivity Issues w/DOT1X MDA</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3750837#M495751</link>
      <description>&lt;P&gt;Just a blind shot but check this out:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ip-device-tracking/m-p/3750828#M20916" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ip-device-tracking/m-p/3750828#M20916&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP device tracking probes can cause endpoints to learn IP address of gateway ( depending on configuraiton you have ) with mac address of switchport causing packets to be dropped. You can see some intermittent connectivity issues.&lt;/P&gt;
&lt;P&gt;Check endpoint arp table for default gw if you can se mac address changing there.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 15:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-connectivity-issues-w-dot1x-mda/m-p/3750837#M495751</guid>
      <dc:creator>dawid.karol.bednarczyk</dc:creator>
      <dc:date>2018-11-21T15:29:25Z</dc:date>
    </item>
  </channel>
</rss>

