<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x multi domain authent issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963065#M5413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The jist of this is, with MDA configured, it will never allow access to anything, unless it sees a client on the wire. Whever you plug it in, it will try to authenticate the device with 802.1X. If 802.1X times out, then fallback options like MAB, the Guest-VLAN come into play.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you cut-n-paste your current port-config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Largely, you should be seeing the same thing with MDA that you'd see when you plug directly into the switch to begin with. Beware that 802.1X takes 90-sec to timeout by default. This could be the issue you're facing here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH a little in the meantime,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jun 2008 17:56:53 GMT</pubDate>
    <dc:creator>jafrazie</dc:creator>
    <dc:date>2008-06-16T17:56:53Z</dc:date>
    <item>
      <title>dot1x multi domain authent issue</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963062#M5410</link>
      <description>&lt;P&gt;hi , i'm installing ipphone on 3560 with 802.1x authentication and host mode multi-domain ,all works fine for ipphone but PC behind ipphone can't &lt;/P&gt;&lt;P&gt;receive an ip address via dhcp although dot1x guest vlan data is configured, is supplicant and 802.1x authentication mandatory on pc as on ipphone or can i have only authentication on ipphone and none on PC ? &lt;/P&gt;&lt;P&gt;is there some issue known for that situation ? &lt;/P&gt;&lt;P&gt;how long is a mac addres locked if dot1x authen failed ? is that timer configurable ? is the mac address locked for the port or for all switch port ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963062#M5410</guid>
      <dc:creator>a.diot</dc:creator>
      <dc:date>2020-02-21T18:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x multi domain authent issue</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963063#M5411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your PC 802.1X enabled? If so, is it enabled to send EAPOL-Start frames?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 00:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963063#M5411</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2008-06-16T00:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x multi domain authent issue</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963064#M5412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Jafrazie ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No , authent isn't enabled on windows PC and i noticed that behavor with XP and 2000 stations,&lt;/P&gt;&lt;P&gt;i have to unplug the ipphone in order to have the pc working , dhcp release or renew doesn't work (no network) then pc ip address is 169...&lt;/P&gt;&lt;P&gt;i will try to take some trace to confirm that the pc is not sending some eap frames &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 17:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963064#M5412</guid>
      <dc:creator>a.diot</dc:creator>
      <dc:date>2008-06-16T17:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x multi domain authent issue</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963065#M5413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The jist of this is, with MDA configured, it will never allow access to anything, unless it sees a client on the wire. Whever you plug it in, it will try to authenticate the device with 802.1X. If 802.1X times out, then fallback options like MAB, the Guest-VLAN come into play.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you cut-n-paste your current port-config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Largely, you should be seeing the same thing with MDA that you'd see when you plug directly into the switch to begin with. Beware that 802.1X takes 90-sec to timeout by default. This could be the issue you're facing here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH a little in the meantime,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 17:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-multi-domain-authent-issue/m-p/963065#M5413</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2008-06-16T17:56:53Z</dc:date>
    </item>
  </channel>
</rss>

