<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Computer behind IP phone does not work in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552219#M508772</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It turned out that the switch in question was running an unsupported version of iOS, 15.0(2) EX4.&lt;/P&gt;&lt;P&gt;So, I think it might be hitting the bug here, &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred" title="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred&lt;/A&gt;, although this version if iOS is not mentioned in the bug...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, I have requested to upgrade the version of iOS to supported version of, IOS 15.2(2) E6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post that we would run the tests again and capture the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2018 08:22:12 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2018-07-05T08:22:12Z</dc:date>
    <item>
      <title>Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552211#M508764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Hi Experts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;There is this small set of users that we are moving to closed mode, but keeping the posture checks in audit mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;The setup we are using is as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;ISE:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Version: 2.3.0.298&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Patch: 2,3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino; font-size: 10pt;"&gt;AnyConnect with NAM: 4.5.04029&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Now what is happening is that, when I connect just the computer to the port, everything works fine as it should.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Authentication happens and posture runs no issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Now, I bring in the IP phone and connect the computer behind the IP phone:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;The phone registers, but the computer stays in limited connectivity.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Now here I have to manually select the Wired profile from the drop down.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;After that only, it authenticates and run the posture check.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;I have tested this &lt;SPAN style="font-size: 13.3333px;"&gt;multiple&lt;/SPAN&gt; times, but the issue stays as it is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;This is the switch configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/8&lt;/P&gt;&lt;P&gt; description ** DSI| Prise C0-099 | Salle 0.134 **&lt;/P&gt;&lt;P&gt; switchport access vlan 242&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 260&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 230&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize voice&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Has anyone observed this &lt;SPAN style="font-size: 13.3333px;"&gt;behavior&lt;/SPAN&gt; before?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 06:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552211#M508764</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-04T06:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552212#M508765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is another update to this issue:&lt;/P&gt;&lt;P&gt;This was a laptop that we were testing with.. So it has two profiles on NAM, one for the Wired and another for the Wifi access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, when we disabled the Wifi, and then connected to the port behind the IP phone, it just worked without any issues.&lt;/P&gt;&lt;P&gt;We verified this multiple times and it worked right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the question here is, is NAM unable to select from profile when user is already connected to Wifi?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 10:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552212#M508765</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-04T10:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552213#M508766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to configure NAM properly and will be work ,and why you need&amp;nbsp; NAM ,in mine deployment all profiles for PC,notebooks coming from Active directory ,wired PC take GPO for wired and Wireless take GPO for wireless.&lt;/P&gt;&lt;P&gt;One more thing ,are LAN WAN switching work on this PC correctly ,if yes i think NAM will auto switch profiles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 11:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552213#M508766</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-07-04T11:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552214#M508767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using NAM to allow for EAP-Chaining, we have a requirement for user and computer authentication, thus NAM was the only option to go with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prior to deploying ISE and NAM, it was working fine.&lt;/P&gt;&lt;P&gt;Then when we were running WiFi and Wired connections in open mode, there were no issues reported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And when we now moved to closed mode, we have started to see these issues when a wifi user connects to the wired port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 12:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552214#M508767</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-04T12:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552215#M508768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YOu can use computer and user authentication without NAM ,and i am sure of that.In mine deployment is without NAM and working machine and user authentication via Eap-chaining &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 17:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552215#M508768</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-07-04T17:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552216#M508769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is new to me, I wasn't aware that there were native supplicants capable of eap-chaining.&amp;nbsp; Do you have a reference link for this functionality?&amp;nbsp; I know windows gave the option for computer and user auth but that only ever chose one or the other, not both at once. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jul 2018 17:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552216#M508769</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-07-04T17:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552217#M508770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is a mix-up.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;You are correct that only AnyConnect NAM can perform EAP Chaining but not Windows native 802.1X supplicants. Windows native supplicants can have computer or user authentication one or the other and ISE admin may choose to use Machine Access Restriction (MAR) in AD and condition on WasMachineAuthenticated to enforce the user auth with a valid prior computer auth.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 02:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552217#M508770</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-05T02:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552218#M508771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YEs&amp;nbsp; Hslai is right ,but in autorization rules you can make 1rule for machine&amp;nbsp; authorization and second rule user auth.&lt;/P&gt;&lt;P&gt;MAchine will match always first but the trick here is the user ,alway his rule must above the machine and include&lt;/P&gt;&lt;P&gt;was machine authenticated =true&lt;/P&gt;&lt;P&gt;And as you told it will match always 1 but it will match machine first at boot and secon when user log in .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 02:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552218#M508771</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-07-05T02:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552219#M508772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It turned out that the switch in question was running an unsupported version of iOS, 15.0(2) EX4.&lt;/P&gt;&lt;P&gt;So, I think it might be hitting the bug here, &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred" title="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo92394/?rfs=iqvred&lt;/A&gt;, although this version if iOS is not mentioned in the bug...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, I have requested to upgrade the version of iOS to supported version of, IOS 15.2(2) E6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post that we would run the tests again and capture the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 08:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552219#M508772</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-05T08:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Computer behind IP phone does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552220#M508773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot for the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am guessing the NAD is of 2960X and the CCO showing 15.0.2-EX4(ED) as a deferred release.&lt;/P&gt;&lt;P&gt;Yes, it's good to use one of the validated OS in Table 2 of &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/compatibility/b_ise_sdt_24.html#supportedciscoaccessswitches" style="margin: 0px 0px 0px 45px; font-family: CiscoSans, Arial, sans-serif; font-size: 14px; font-style: inherit; color: #007fc5; text-decoration: underline;"&gt;ISE 2.4 Supported Cisco Access Switches&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you encounter further issues, best to consult with the particular switch platform team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 15:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/computer-behind-ip-phone-does-not-work/m-p/3552220#M508773</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-05T15:52:26Z</dc:date>
    </item>
  </channel>
</rss>

