<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300448#M565844</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having some issues at our office When users move from one port of the switch to a port of another switch, their MAC address stays on the previous port as STATIC, creating connectivity problems when the new connection is below the previous switch.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Diagrama MAC STATIC PROBLEM.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/105469i724176CE2965A008/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Diagrama MAC STATIC PROBLEM.jpg" alt="Diagrama MAC STATIC PROBLEM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The switch learns the MAC address as static because we use authentication on the switch ports with Cisco ISE 2.7. As computers are connected through an IP phone when they move, the port does not turn off and the MAC address remains stuck in the previous port.&lt;/P&gt;&lt;P&gt;Do you guys have any idea how this problem can be solved?&lt;/P&gt;&lt;P&gt;Meanwhile we are using Radius idle timeout of 5 seconds in the authorization profile in ISE. In this way, after 5 seconds after the computer was disconnected, the session ends and the switch clears the MAC, but sometimes this configuration brings me problems of instability in the connectivity of the users and that is why I need to know if there is any other solution .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below I share the configuration that we use in the switches ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Mar 2021 03:49:35 GMT</pubDate>
    <dc:creator>MambaRod16</dc:creator>
    <dc:date>2021-03-03T03:49:35Z</dc:date>
    <item>
      <title>Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300448#M565844</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having some issues at our office When users move from one port of the switch to a port of another switch, their MAC address stays on the previous port as STATIC, creating connectivity problems when the new connection is below the previous switch.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Diagrama MAC STATIC PROBLEM.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/105469i724176CE2965A008/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Diagrama MAC STATIC PROBLEM.jpg" alt="Diagrama MAC STATIC PROBLEM.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The switch learns the MAC address as static because we use authentication on the switch ports with Cisco ISE 2.7. As computers are connected through an IP phone when they move, the port does not turn off and the MAC address remains stuck in the previous port.&lt;/P&gt;&lt;P&gt;Do you guys have any idea how this problem can be solved?&lt;/P&gt;&lt;P&gt;Meanwhile we are using Radius idle timeout of 5 seconds in the authorization profile in ISE. In this way, after 5 seconds after the computer was disconnected, the session ends and the switch clears the MAC, but sometimes this configuration brings me problems of instability in the connectivity of the users and that is why I need to know if there is any other solution .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below I share the configuration that we use in the switches ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 03:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300448#M565844</guid>
      <dc:creator>MambaRod16</dc:creator>
      <dc:date>2021-03-03T03:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300461#M565845</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What IP phone devices are you using?&lt;BR /&gt;You need to make sure the logoff message is sent out to the radius when a pc disconnects from the IP phone.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 04:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300461#M565845</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2021-03-03T04:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300694#M565849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/498034"&gt;@MambaRod16&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;beyond &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321306"&gt;@Francesco Molino&lt;/a&gt;&amp;nbsp;said, try the following command:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;authentication control-direction in&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 13:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4300694#M565849</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-03T13:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4301620#M565886</link>
      <description>&lt;P&gt;Our IP Phones are AVAYA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I achieve that&amp;nbsp;&lt;SPAN&gt;the logoff message is sent out to the radius when a pc disconnects from the IP phone?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 17:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4301620#M565886</guid>
      <dc:creator>MambaRod16</dc:creator>
      <dc:date>2021-03-04T17:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302626#M565924</link>
      <description>&lt;P&gt;Do you have device Tracking enabled?&lt;/P&gt;
&lt;P&gt;eg some sample commands below. You apply the policy to the interfaces&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;authentication mac-move permit
!
device-tracking policy IPDT_POLICY
 no protocol udp
 tracking enable&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 21:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302626#M565924</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-03-06T21:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302929#M565931</link>
      <description>&lt;P&gt;Hi Arne,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please tell me how I can use IP Device Tracking to solve this problem?&lt;/P&gt;&lt;P&gt;Below the configuration I'm using on the switches, please tell me if something is missing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;GLOBALLY&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authentication mac-move permit&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server radius dot1x_auth&lt;BR /&gt;server name EXAMPLE-ISE-1&lt;BR /&gt;server name EXAMPLE-ISE-2&lt;BR /&gt;aaa authentication dot1x default group dot1x_auth&lt;BR /&gt;aaa authorization network default group dot1x_auth&lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting dot1x default start-stop group dot1x_auth&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 192.168.4.58 server-key ExampleKey&lt;BR /&gt;client 192.168.4.59 server-key ExampleKey&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol&lt;/P&gt;&lt;P&gt;ip access-list extended ACL_Redirect&lt;BR /&gt;deny udp any eq bootpc any eq bootps&lt;BR /&gt;deny udp any any eq domain&lt;BR /&gt;deny ip any host 192.168.4.58&lt;BR /&gt;deny ip any host 192.168.4.59&lt;BR /&gt;permit tcp any any eq www&lt;BR /&gt;permit tcp any any eq 443&lt;BR /&gt;permit ip any any&lt;BR /&gt;deny ip any any&lt;BR /&gt;&lt;BR /&gt;ip device tracking probe delay 10&lt;BR /&gt;ip device tracking&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf upper-case&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;radius-server dead-criteria tries 2&lt;BR /&gt;radius-server key ExampleKey&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius server EXAMPLE-ISE-1&lt;BR /&gt;address ipv4 192.168.4.58 auth-port 1812 acct-port 1813&lt;BR /&gt;key ExampleKey&lt;BR /&gt;radius server EXAMPLE-ISE-2&lt;BR /&gt;address ipv4 192.168.4.59 auth-port 1812 acct-port 1813&lt;BR /&gt;key ExampleKey&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ON THE INTERFACE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;switchport access vlan 60&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 70&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 04:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302929#M565931</guid>
      <dc:creator>MambaRod16</dc:creator>
      <dc:date>2021-03-08T04:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302933#M565932</link>
      <description>&lt;P&gt;Do you have device tracking assigned on the interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is the global device-tracking definition (courtesy of DNAC &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; and how you would apply it to an interface:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;device-tracking policy IPDT_MAX_10
 limit address-count 10
 no protocol udp
 tracking enable


interface gig x/x/x
  device-tracking attach-policy IPDT_MAX_10&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 05:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4302933#M565932</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-03-08T05:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity problem using 802.1X Authentication when moving between switch ports - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4306931#M566115</link>
      <description>&lt;P&gt;You want your phones to have the CDP 2nd Port disconnect option enabled. They will tell the switch when to release the MAC from the data VLAN when you use this. See &lt;A href="https://community.cisco.com/t5/security-documents/phone-amp-collaboration-authentication-capabilities/ta-p/3622266" target="_self"&gt;Phone &amp;amp; Collaboration Authentication Capabilities&lt;/A&gt; for more details with different phone vendors.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 02:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/connectivity-problem-using-802-1x-authentication-when-moving/m-p/4306931#M566115</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-14T02:43:02Z</dc:date>
    </item>
  </channel>
</rss>

