<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authentication session does not change on multi-auth port behind Polycom phones in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571720#M538436</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the followup on this, Utkarsh!&lt;/P&gt;&lt;P&gt;Glad to hear they do have the capability so it will work for you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jun 2016 15:06:07 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2016-06-30T15:06:07Z</dc:date>
    <item>
      <title>authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571716#M538432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the switch detect link status for endpoints when they are disconnected behind IP-Phones on a multi-auth port ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an issue where an endpoint is moved from one multi-auth port to another multi-auth port (both behind Polycom phones) but the authentication session still remains on the old port. The MAC-Address table however is updated. &lt;/P&gt;&lt;P&gt;Issue is faced on CAT 6K and CAT 4K switches only for Polycom phones. No issue is seen for Cisco IP Phones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After clearing authentication session on both the interfaces the authentication session is correctly applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a known issue on Polycomm Phones ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2016 13:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571716#M538432</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-06-29T13:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571717#M538433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Utkarsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch detects new endpoints on a switchport by MAC address. I suspect the polycom phones are not telling the switch about the disconnection when the endpoint moves.&amp;nbsp; This would explain why the session remains but the MAC address table is being updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2016 15:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571717#M538433</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2016-06-29T15:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571718#M538434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-63825"&gt;&lt;STRONG&gt;Cisco IP Phones&lt;/STRONG&gt;&lt;/A&gt; have a special feature called &lt;STRONG&gt;CDP 2nd Port Disconnect&lt;/STRONG&gt; which tells the switch when the endpoint behind it is Disconnected. Polycoms don't have this feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2016 04:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571718#M538434</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-30T04:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571719#M538435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thomas/Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response&lt;/P&gt;&lt;P&gt;On going through Polycom documentation it is mentioned that Polyom phones too send CDP packets&lt;/P&gt;&lt;P&gt;Polycom phones can also send proxy EAPoL on behalf of the machine.&lt;/P&gt;&lt;P&gt;However it seems both these are not enabled by default and we need to make changes to the XML configuration file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the link below &lt;/P&gt;&lt;P&gt;&lt;A href="http://plcmtechnet.com/documents/voice/unified-communications-software-ucs/5-0-1/administrator-guide/configuration-parameters#_-lt-dot1x-gt--lt-eapollogoff--gt-" title="http://plcmtechnet.com/documents/voice/unified-communications-software-ucs/5-0-1/administrator-guide/configuration-parameters#_-lt-dot1x-gt--lt-eapollogoff--gt-"&gt;Configuration Parameters | documents.polycom.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2016 06:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571719#M538435</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-06-30T06:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571720#M538436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the followup on this, Utkarsh!&lt;/P&gt;&lt;P&gt;Glad to hear they do have the capability so it will work for you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2016 15:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571720#M538436</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-30T15:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571721#M538437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another common option is to enable the inactivity timer on the port: &lt;A href="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html#wp386911" title="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html#wp386911"&gt;Wired 802.1X Deployment Guide - Cisco&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;That will remove authenticated MAC addresses that don't transmit any data over a certain period of minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally, you can allow MAC addresses to move between ports using this command: authentication mac-move permit. This command will remove a MAC address session if the same MAC address pops up on another port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2016 15:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571721#M538437</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2016-06-30T15:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571722#M538438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Viktor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to capture this &lt;SPAN data-dobid="hdw"&gt;behaviour for Cisco IP phone 9971 (running 1.9.4) but could not find any CDP disconnect packet. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN data-dobid="hdw"&gt;However I did find proxy EAPoL as below although with an frame check sequence incorrect error. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure this is the expected behaviour. I think the error is due to checksum offloading explained as &lt;A href="https://communities.vmware.com/thread/426699?start=0&amp;amp;tstart=0" title="https://communities.vmware.com/thread/426699?start=0&amp;amp;tstart=0"&gt;Ethernet Frame Check Sequence set to 0x00000000 | VMware Communities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN data-dobid="hdw"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN data-dobid="hdw"&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/97393_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2016 09:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571722#M538438</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-07-07T09:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571723#M538439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe these phones don't support CDP second port notification. This is what I see on my 9971. EAPOL Logoff would accomplish the same thing though.&lt;/P&gt;&lt;P&gt;Device ID: SEPD0C282D00906&lt;/P&gt;&lt;P&gt;Entry address(es): &lt;/P&gt;&lt;P&gt;&amp;nbsp; IP address: 10.118.97.3&lt;/P&gt;&lt;P&gt;Platform: Cisco IP Phone 9971,&amp;nbsp; Capabilities: Host Phone Two-port Mac Relay &lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet0,&amp;nbsp; Port ID (outgoing port): Port 1&lt;/P&gt;&lt;P&gt;Holdtime : 153 sec&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Second Port Status: Unknown&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version :&lt;/P&gt;&lt;P&gt;sip9971.9-4-2SR2-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;advertisement version: 2&lt;/P&gt;&lt;P&gt;Duplex: full&lt;/P&gt;&lt;P&gt;Power drawn: 12.804 Watts&lt;/P&gt;&lt;P&gt;Power request id: 1547, Power management id: 2&lt;/P&gt;&lt;P&gt;Power request levels are:12804 0 0 0 0 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jul 2016 00:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571723#M538439</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2016-07-09T00:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: authentication session does not change on multi-auth port behind Polycom phones</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571724#M538440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to get the Polycom Phone working with EAPoL proxy logoff.&lt;/P&gt;&lt;P&gt;Adding the line &lt;STRONG&gt;&lt;SPAN lang="EN-IN" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;lt;sec.dot1x.eapollogoff sec.dot1x.eapollogoff.enabled="1"&amp;gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN-IN" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;in the configuration file made it work.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2016 04:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-does-not-change-on-multi-auth-port-behind/m-p/3571724#M538440</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-07-12T04:05:08Z</dc:date>
    </item>
  </channel>
</rss>

