<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ghost authentication session with 802.1X in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299305#M565798</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1168717"&gt;@AdrianDessaigne2301&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;it's not recommended to use &lt;EM&gt;port-security&lt;/EM&gt; and &lt;EM&gt;dot1x&lt;/EM&gt; in the same configuration. Could you please remove the &lt;EM&gt;port-security commands&lt;/EM&gt;&amp;nbsp;and try again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Mon, 01 Mar 2021 11:47:57 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-03-01T11:47:57Z</dc:date>
    <item>
      <title>Ghost authentication session with 802.1X</title>
      <link>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299299#M565797</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;&lt;P&gt;I have a weird behavior trying to use 802.1X with my Alcatel Phone and my PC.&lt;/P&gt;&lt;P&gt;My computer is connected behind the phone (Alcatel 8058s), and the phone is connected to the switch port. When I disconnect the PC, I still see it in the list of authentication sessions :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SWITCH#show authentication session&lt;/P&gt;&lt;P&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;Gi1/0/13 040e.3cc0.db1d 802.1X DATA Auth 0A0363F900000024004F707D&amp;nbsp; &amp;lt;-----&lt;BR /&gt;Gi1/0/13 487a.5514.b085 mab VOICE Auth 0A0363F900000025005006EC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tough changing the value of "authentication timer reauthenticate" could fix the issue, but even when disconnected, the PC still get reauthenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the version of my switch :&amp;nbsp;&lt;STRONG&gt;WS-C2960X-24TS-L 15.2(4)E8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the configuration of the port :&lt;/P&gt;&lt;P&gt;switchport access vlan X&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan Y&lt;BR /&gt;switchport port-security maximum 2&lt;BR /&gt;switchport port-security violation restrict&lt;BR /&gt;switchport port-security aging time 2&lt;BR /&gt;switchport port-security aging type inactivity&lt;BR /&gt;switchport port-security&lt;BR /&gt;priority-queue out&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 14400&lt;BR /&gt;authentication timer restart 10&lt;BR /&gt;authentication timer unauthorized 300&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;no snmp trap link-status&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;macro description cisco-desktop&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout quiet-period 50&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;dot1x timeout supp-timeout 25&lt;BR /&gt;dot1x max-req 3&lt;BR /&gt;dot1x max-reauth-req 5&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answers and help !&lt;/P&gt;&lt;P&gt;Adrian.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 11:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299299#M565797</guid>
      <dc:creator>AdrianDessaigne2301</dc:creator>
      <dc:date>2021-03-01T11:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ghost authentication session with 802.1X</title>
      <link>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299305#M565798</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1168717"&gt;@AdrianDessaigne2301&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;it's not recommended to use &lt;EM&gt;port-security&lt;/EM&gt; and &lt;EM&gt;dot1x&lt;/EM&gt; in the same configuration. Could you please remove the &lt;EM&gt;port-security commands&lt;/EM&gt;&amp;nbsp;and try again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 11:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299305#M565798</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-01T11:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ghost authentication session with 802.1X</title>
      <link>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299320#M565802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your answers. Unfortunatly, after removing all port-security configuration from the port, the issues is still there. (PC still showing in auth session list after disconnecting it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the new config of the port :&lt;/P&gt;&lt;P&gt;switchport access vlan X&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan Y&lt;BR /&gt;priority-queue out&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 60&lt;BR /&gt;authentication timer restart 10&lt;BR /&gt;authentication timer unauthorized 300&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;no snmp trap link-status&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;macro description cisco-desktop&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout quiet-period 50&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;dot1x timeout supp-timeout 25&lt;BR /&gt;dot1x max-req 3&lt;BR /&gt;dot1x max-reauth-req 5&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only fix I could find is to reset the port or the authentication sessions, but I don't want to leave that manual (+ we do have a lot's of switches).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 12:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4299320#M565802</guid>
      <dc:creator>AdrianDessaigne2301</dc:creator>
      <dc:date>2021-03-01T12:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Ghost authentication session with 802.1X</title>
      <link>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4306948#M566124</link>
      <description>&lt;P&gt;The phone needs to support either proxy EAPOL-Logoff or CDP 2nd Port Disconnect. Either of these features will tell the switch when the endpoint behind it disconnects so it knows to drop them.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/t5/security-documents/phone-amp-collaboration-authentication-capabilities/ta-p/3622266" target="_self"&gt;Phone &amp;amp; Collaboration Authentication Capabilities&lt;/A&gt;&lt;/STRONG&gt; lists the options for some phones but not Alcatel so you'll need to research it for yourself.&lt;/P&gt;
&lt;P&gt;Please add what you find in this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ghost-authentication-session-with-802-1x/m-p/4306948#M566124</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-03-10T07:28:23Z</dc:date>
    </item>
  </channel>
</rss>

