<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic double arp entries for the same mac address problem. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708025#M507603</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem relating to my client switch.&lt;/P&gt;
&lt;P&gt;In my L3 Switch there is two entries for the same mac address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my network the ISE authenticate endpoints using 802.1x.if the endpoint failes to&amp;nbsp;authenticate it will land in a quarante VLAN and get an&amp;nbsp;&lt;SPAN&gt;quarante&amp;nbsp;IP from&amp;nbsp;quarante DHCP server&lt;/SPAN&gt; and if they succeeded they will access the Fatclient VLAN. with a differnct IP from the&amp;nbsp;&lt;SPAN&gt;Fatclient&amp;nbsp;DHCP server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sometimes the PC takes a long time to&amp;nbsp;authenticate&amp;nbsp;so it gets its IP from&amp;nbsp;quarante&amp;nbsp;and after a time it get the right IP from the&amp;nbsp;Fatclient&amp;nbsp;DHCP server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;fyi i am using L3 switch for my fatclients and a routed based network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the Problem is I see in the show arp-cache in my L3 Switch two different&amp;nbsp;IPs for the same MAC address in two diffrent VLANs and the PC does not have a network access untill i clear the arp cache.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;is there a way to automate this using ISE?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or is the problem soultion is somewhere else.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for reading&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 12:12:19 GMT</pubDate>
    <dc:creator>amhish@netfox.de</dc:creator>
    <dc:date>2018-09-17T12:12:19Z</dc:date>
    <item>
      <title>double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708025#M507603</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem relating to my client switch.&lt;/P&gt;
&lt;P&gt;In my L3 Switch there is two entries for the same mac address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my network the ISE authenticate endpoints using 802.1x.if the endpoint failes to&amp;nbsp;authenticate it will land in a quarante VLAN and get an&amp;nbsp;&lt;SPAN&gt;quarante&amp;nbsp;IP from&amp;nbsp;quarante DHCP server&lt;/SPAN&gt; and if they succeeded they will access the Fatclient VLAN. with a differnct IP from the&amp;nbsp;&lt;SPAN&gt;Fatclient&amp;nbsp;DHCP server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sometimes the PC takes a long time to&amp;nbsp;authenticate&amp;nbsp;so it gets its IP from&amp;nbsp;quarante&amp;nbsp;and after a time it get the right IP from the&amp;nbsp;Fatclient&amp;nbsp;DHCP server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;fyi i am using L3 switch for my fatclients and a routed based network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the Problem is I see in the show arp-cache in my L3 Switch two different&amp;nbsp;IPs for the same MAC address in two diffrent VLANs and the PC does not have a network access untill i clear the arp cache.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;is there a way to automate this using ISE?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or is the problem soultion is somewhere else.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for reading&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 12:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708025#M507603</guid>
      <dc:creator>amhish@netfox.de</dc:creator>
      <dc:date>2018-09-17T12:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708061#M507604</link>
      <description>&lt;P&gt;In my opinion, using a quarantine VLAN for unknown devices is setting yourself up for problems like this.&amp;nbsp;&amp;nbsp;VLAN moves in general can be problematic with DHCP devices.&amp;nbsp; If the device gets an IP address in one VLAN and then is sent to another VLAN by ISE you can strand the device.&amp;nbsp; I generally avoid doing VLAN assignments in favor of DACLs/SGTs.&amp;nbsp; If the devices have static IP then VLAN moves are not a problem.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are going to keep doing a VLAN move what is your switchport config?&amp;nbsp; Are you doing dot1x first then MAB for order?&amp;nbsp; If so what is your Dot1x timeout.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The layer 3 switch have two ARP entries for the same MAC address is correct.&amp;nbsp; The ARP tables are maintained per interface/VLAN.&amp;nbsp; So if it sees the MAC on VLAN X and it moves to VLAN Y it will have ARP entries on both VLANs.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 13:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708061#M507604</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-17T13:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708115#M507605</link>
      <description>&lt;P&gt;Hello Paul&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First thank you for taking the time to answer my question.&lt;/P&gt;
&lt;P&gt;the Problem is i cant really propose a different topology for my client for his exsiting network all i can do is trying to find a work around where he does not generate a ticket for each time one of his PCs is not getting a network access .&lt;/P&gt;
&lt;P&gt;the config for my port is a standerd 802.1x&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;interface GigabitEthernet1/0/1&lt;BR /&gt;&amp;nbsp;network-policy 20&lt;BR /&gt;&amp;nbsp;switchport access vlan 15&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;device-tracking attach-policy DEVICE_TRACK&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;access-session port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;storm-control broadcast level pps 100 90&lt;BR /&gt;&amp;nbsp;storm-control action trap&lt;BR /&gt;&amp;nbsp;auto qos trust dscp&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;service-policy type control subscriber 802.1X_POLICY&lt;BR /&gt;&amp;nbsp;service-policy input AutoQos-4.0-Trust-Dscp-Input-Policy&lt;BR /&gt;&amp;nbsp;service-policy output AutoQos-4.0-Output-Policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;and thank you agian!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 14:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708115#M507605</guid>
      <dc:creator>amhish@netfox.de</dc:creator>
      <dc:date>2018-09-17T14:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708128#M507606</link>
      <description>Ohh no you are using CPL which is going to make your problem even worse.  In CPL, MAB and Do1x happen at the same time.  MAB happens almost instantly so the devices have a good chance to getting moved to the quarantine VLAN.  If I were walking into this customer, I would explain they have set themselves up for failure with the quarantine VLAN concept.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you don't want to do that you can using profiling, like the AD profiler, to profile the domain computers and have them not get sent to the quarantine VLAN.  You don't have to give them network access, just don't send them to the quarantine VLAN.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Sep 2018 14:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708128#M507606</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-17T14:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708663#M507607</link>
      <description>&lt;P&gt;Hello Paul&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I forgot to mention that we are not using mab even though it is present in the config.&lt;/P&gt;
&lt;P&gt;we are using a centeral CA which is using the certificate to authenticate the PCs.&lt;/P&gt;
&lt;P&gt;and i didnt understand your alternate soution for quarantine VLAN.&lt;/P&gt;
&lt;P&gt;Would you explain or refer me to some links?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 11:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708663#M507607</guid>
      <dc:creator>amhish@netfox.de</dc:creator>
      <dc:date>2018-09-18T11:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708702#M507608</link>
      <description>&lt;P&gt;The switch is going to run a MAB transaction.&amp;nbsp; What does ISE do with it?&amp;nbsp; Deny it?&amp;nbsp; Or is that what gets the device sent to the quarantine VLAN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the different profilers.&amp;nbsp; The AD profiler can take the DHCP hostname of the device of the FQDN (currently broken in 2.4) and check it against AD to see if the hostname exists in AD.&amp;nbsp; If it exists you have a decent idea that the device is a domain joined computer and maybe don't quarantine VLAN it.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708702#M507608</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-18T12:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: double arp entries for the same mac address problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708703#M507609</link>
      <description>&lt;P&gt;Also you could use the MAR cache as well.&amp;nbsp; If the PC does do computer authentication correctly you can set the MAR cache entry and use that in MAB rules to allow the device not to get quarantined.&amp;nbsp; Set your MAR cache timer to something like 30 days.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-arp-entries-for-the-same-mac-address-problem/m-p/3708703#M507609</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-18T12:42:28Z</dc:date>
    </item>
  </channel>
</rss>

