<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055641#M559271</link>
    <description>&lt;P&gt;The log shows IP phone MAC is rejected.&lt;/P&gt;&lt;P&gt;But in IP phone it can access voice VLAN , got the IP address and can call as normal&lt;/P&gt;</description>
    <pubDate>Tue, 31 Mar 2020 03:43:22 GMT</pubDate>
    <dc:creator>msompong1</dc:creator>
    <dc:date>2020-03-31T03:43:22Z</dc:date>
    <item>
      <title>Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4054912#M559252</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've tried to setup the ISE to authenticate the PC with (802.1x or MAB depend on the PC type)&lt;/P&gt;&lt;P&gt;The connection must have IP-phone direct connect to switch port and then connect to the PC.&lt;/P&gt;&lt;P&gt;Below is the port configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;BR /&gt;description Test 802.1x&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 104&lt;BR /&gt;shutdown&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout quiet-period 5&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;dot1x timeout supp-timeout 5&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my understanding, the IP-Phone will allow to access voice VLAN without authentication (with Voice domain) and PC will authenticate with 802.1x or MAB. After testing the IP-Phone tried to used the 802.1x&amp;nbsp; and MAB for authentication and has been failed like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh authentication sessions int f0/1&lt;BR /&gt;Interface: FastEthernet0/1&lt;BR /&gt;MAC Address: 0018.b97b.f84a&lt;BR /&gt;IP Address: Unknown&lt;BR /&gt;User-Name: UNRESPONSIVE&lt;BR /&gt;Status: Authz Failed&lt;BR /&gt;&lt;STRONG&gt;Domain: DATA&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt; Why not Voice Domain ?&lt;/STRONG&gt;&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Unsecure&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Idle timeout: N/A&lt;BR /&gt;Common Session ID: 0AC4488800000169B22D14D2&lt;BR /&gt;Acct Session ID: 0x000008C9&lt;BR /&gt;Handle: 0x41000169&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;Method State&lt;BR /&gt;dot1x Failed over&lt;BR /&gt;mab Failed over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I've checked the IP-Phone network , &lt;STRONG&gt;&lt;EM&gt;it have got the Voice VLAN&amp;nbsp; and it worked as normal !!!&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm not so sure what's wrong in configuration.&lt;/P&gt;&lt;P&gt;And from the switch log the IP-Phone continuous periodic authenticate to switch as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ar 30 09:07:07.902: RADIUS/ENCODE: Best Local IP-Address x.x.x.x for Radius-Server y.y.y.y&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS(0000027A): Send Access-Request to y.y.y.y:1645 id 1645/74, len 206&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: authenticator 78 43 F2 67 ED 04 19 CA - 94 4C DA C8 13 CA 7A E7&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: User-Name [1] 14 "0018b97bf84a"&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: User-Password [2] 18 *&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Service-Type [6] 6 Call Check [10]&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Framed-MTU [12] 6 1500&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Called-Station-Id [30] 19 "1C-1D-86-27-DC-81"&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Calling-Station-Id [31] 19 "00-18-B9-7B-F8-4A"&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Message-Authenticato[80] 18&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: 58 31 09 18 1F 75 5D 2A 4F 80 84 55 2D 87 57 37 [ X1u]*OU-W7]&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: EAP-Key-Name [102] 2 *&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Vendor, Cisco [26] 49&lt;BR /&gt;Mar 30 09:07:07.902: RADIUS: Cisco AVpair [1] 43 "audit-session-id=0AC4488800000169B22D14D2"&lt;BR /&gt;Mar 30 09:07:07.911: RADIUS: NAS-Port-Type [61] 6 Ethernet [15]&lt;BR /&gt;Mar 30 09:07:07.911: RADIUS: NAS-Port [5] 6 50001&lt;BR /&gt;Mar 30 09:07:07.911: RADIUS: NAS-Port-Id [87] 17 "FastEthernet0/1"&lt;BR /&gt;Mar 30 09:07:07.911: RADIUS: NAS-IP-Address [4] 6 x.x.x.x&lt;BR /&gt;Mar 30 09:07:07.911: RADIUS(0000027A): Started 5 sec timeout&lt;BR /&gt;Mar 30 09:07:07.969: RADIUS: Received from id 1645/74 y.y.y.y:1645, Access-Reject, len 38&lt;BR /&gt;Mar 30 09:07:07.969: RADIUS: authenticator DC E2 BC BF 41 0D 5F 95 - 9C 87 7D 91 BB 00 C2 99&lt;BR /&gt;Mar 30 09:07:07.969: RADIUS: Message-Authenticato[80] 18&lt;BR /&gt;Mar 30 09:07:07.969: RADIUS: E6 78 3D 8E D8 B4 CF 83 47 51 E7 BE B2 B8 B9 2D [ x=GQ-]&lt;BR /&gt;Mar 30 09:07:07.969: RADIUS(0000027A): Received from id 1645/74&lt;BR /&gt;Mar 30 09:07:07.969: %MAB-5-FAIL: Authentication failed for client (0018.b97b.f84a) on Interface Fa0/1 AuditSessionID 0AC4488800000&lt;BR /&gt;169B22D14D2&lt;BR /&gt;Mar 30 09:07:07.978: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'mab' for client (0018.b97b.f84a) on Interface Fa0&lt;BR /&gt;/1 AuditSessionID 0AC4488800000169B22D14D2&lt;BR /&gt;Mar 30 09:07:07.978: %AUTHMGR-7-FAILOVER: Failing over from 'mab' for client (0018.b97b.f84a) on Interface Fa0/1 AuditSessionID 0AC&lt;BR /&gt;4488800000169B22D14D2&lt;BR /&gt;Mar 30 09:07:07.978: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client (0018.b97b.f84a) on Interface Fa0/1&lt;BR /&gt;AuditSessionID 0AC4488800000169B22D14D2&lt;BR /&gt;Mar 30 09:07:07.978: %AUTHMGR-5-FAIL: Authorization failed for client (0018.b97b.f84a) on Interface Fa0/1 AuditSessionID 0AC4488800&lt;BR /&gt;000169B22D14D2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So my question is&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;what's wrong in configuration?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How can bypass the IP-Phone from authentication?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 09:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4054912#M559252</guid>
      <dc:creator>msompong1</dc:creator>
      <dc:date>2020-03-30T09:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4054927#M559253</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Once you enabled authentication on the port, you can't allow unauthenticated access, as you want, to basically just allow the IP Phone access to the network. Once authentication is enabled on the port, the "host-mode" defines how many devices you can get per port:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - single-host:1 device in voice domain &lt;STRONG&gt;OR&lt;/STRONG&gt;&amp;nbsp;1 device in data domain , both need to be authenticated (MAB, 802.1x)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - multi-domain: 1 device in the voice domain &amp;nbsp;&lt;STRONG&gt;AND&lt;/STRONG&gt;1 device in the data domain, both need to be authenticated (MAB, 8021.x)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- multi-auth: 1 device in the voice domain &amp;nbsp;&lt;STRONG&gt;AND&amp;nbsp;&lt;/STRONG&gt;multiple devices in the data domain, all need to be authenticated (MAB, 8021.x)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - multi-host:&amp;nbsp;1 device in the voice domain &lt;STRONG&gt;AND &lt;/STRONG&gt;multiple&amp;nbsp;device in the data domain, at least one device needs to be authenticated &amp;nbsp;(MAB, 8021x)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;The device in the voice VLAN, not only needs to be authenticated, but also needs to be authorised to use the voice VLAN. &lt;A title="Here's a good reference" href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;Here's a good reference&lt;/A&gt; to help you work it out for a wired deployment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 09:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4054927#M559253</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-30T09:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055595#M559268</link>
      <description>&lt;P&gt;I assume we are talking about an IP Phone doing MAB authentication.&lt;/P&gt;
&lt;P&gt;What does the ISE LiveLog details say about the authorization of the IP phone?&lt;/P&gt;
&lt;P&gt;What authorization rule was matched in your policy for the IP Phone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 00:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055595#M559268</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-03-31T00:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055641#M559271</link>
      <description>&lt;P&gt;The log shows IP phone MAC is rejected.&lt;/P&gt;&lt;P&gt;But in IP phone it can access voice VLAN , got the IP address and can call as normal&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 03:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055641#M559271</guid>
      <dc:creator>msompong1</dc:creator>
      <dc:date>2020-03-31T03:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055645#M559272</link>
      <description>&lt;P&gt;Thank you, Your reply is very clear for&amp;nbsp;&lt;SPAN&gt;authentication&amp;nbsp;mode.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 03:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055645#M559272</guid>
      <dc:creator>msompong1</dc:creator>
      <dc:date>2020-03-31T03:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055686#M559275</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; What you're seeing is due to the configured "authentication open" on the port, which means you've deployed what is called ISE in Monitor Mode. All MAC addresses on the port will try to be authenticated via MAB/802.1x against ISE, but there is no enforcement (the end result success or fail is not relevant), and each MAC address is actually given full access to the network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; The moment you remove "authentication open", each MAC address will have to be authenticated/authorized in order to get network access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 06:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4055686#M559275</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-31T06:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Voice VLAN with 802.1x and MAB PC Authentication on ISE.</title>
      <link>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4700399#M577663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Cristian Matei,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I met the same issue that the endpoint can't get the valid IP of voice vlan. I set the configuraiton "authentication host-mode multi-auth" on the switch port. Do you have any idea for this issue ?&lt;/P&gt;&lt;P&gt;Switch#show access-session mac 6416.7fb8.8cf9 details&lt;BR /&gt;Interface: GigabitEthernet3/0/16&lt;BR /&gt;IIF-ID: 0x1309BD79&lt;BR /&gt;MAC Address: 6416.7fb8.8cf9&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: 64-16-7F-B8-8C-F9&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Acct update timeout: 900s (local), Remaining: 849s&lt;BR /&gt;Common Session ID: 04A8AC0A00008B76BCB3A942&lt;BR /&gt;Acct Session ID: 0x0000009f&lt;BR /&gt;Handle: 0x360000bd&lt;BR /&gt;Current Policy: POLICY_Gi3/0/16&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 12:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/voice-vlan-with-802-1x-and-mab-pc-authentication-on-ise/m-p/4700399#M577663</guid>
      <dc:creator>tonyang</dc:creator>
      <dc:date>2022-10-09T12:37:24Z</dc:date>
    </item>
  </channel>
</rss>

