<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PC authentication with dot1x and IP Phone with MAB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318822#M566606</link>
    <description>&lt;P&gt;Hi BB, I will coordinate the tests and comment on the results.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Apr 2021 18:01:23 GMT</pubDate>
    <dc:creator>promero</dc:creator>
    <dc:date>2021-04-05T18:01:23Z</dc:date>
    <item>
      <title>PC authentication with dot1x and IP Phone with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318782#M566599</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;I have a problem, I want to connect a PC and a Polycom phone but the PC does not authenticate to ISE.&lt;/P&gt;&lt;P&gt;By having the PC connected to the phone, the ISE recognizes it by MAB and it should be by DOT1X.&lt;/P&gt;&lt;P&gt;When doing tests, I connect the PC directly to the network point (without a telephone) and it authenticates correctly the same happens with the telephone alone.&lt;/P&gt;&lt;P&gt;What could be the problem? The phone is Polycom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- ISE 2.7&lt;/P&gt;&lt;P&gt;- Patch 2&lt;/P&gt;&lt;P&gt;- SW&amp;nbsp;WS-C3650-48PS&lt;/P&gt;&lt;P&gt;- SW IOS Version&amp;nbsp;16.3.6&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SW:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current configuration : 546 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/5&lt;BR /&gt;description ###PC + IP PHONE###&lt;BR /&gt;switchport access vlan 60&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 777&lt;BR /&gt;duplex full&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 16:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318782#M566599</guid>
      <dc:creator>promero</dc:creator>
      <dc:date>2021-04-05T16:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: PC authentication with dot1x and IP Phone with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318791#M566602</link>
      <description>&lt;P&gt;try below order :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;authentication order&amp;nbsp;&lt;STRONG&gt;mab&amp;nbsp;dot1x&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication priority dot1x mab&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;still not working, look at the Live Event Logs in ISE will give you full information on why this was failed?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 17:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318791#M566602</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-05T17:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: PC authentication with dot1x and IP Phone with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318822#M566606</link>
      <description>&lt;P&gt;Hi BB, I will coordinate the tests and comment on the results.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 18:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318822#M566606</guid>
      <dc:creator>promero</dc:creator>
      <dc:date>2021-04-05T18:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: PC authentication with dot1x and IP Phone with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318968#M566615</link>
      <description>&lt;P&gt;Be aware that, if you use the FlexAuth configuration of 'order mab dot1x' and 'priority dot1x mab' you will need to ensure your AuthZ Profile for the PC includes the 'termination-action-modifier=1' av-pair as described in the &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/FlexAuthNote/flexauth-note.html" target="_blank" rel="noopener"&gt;TrustSec 1.99 Deployment Note: FlexAuth Order, Priority, and Failed Authentication&lt;/A&gt; document.&lt;/P&gt;
&lt;P&gt;If the PC is working correctly when directly connected to the switchport, it sounds like the phone is not passing the EAPOL message through to the PC. You would have to do a packet capture on the switchport and the PC to confirm what's happening with EAPOL.&lt;/P&gt;
&lt;P&gt;The Avaya phones should support an EAP pass-through function, but there may need to be configuration or a minimum firmware version required to enable this. You might need to engage the Avaya support team to help investigate further.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 23:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4318968#M566615</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-04-05T23:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: PC authentication with dot1x and IP Phone with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4319538#M566628</link>
      <description>&lt;P&gt;Greg,&lt;/P&gt;&lt;P&gt;Thank you for your comment, I will run the tests and report the results.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 20:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-authentication-with-dot1x-and-ip-phone-with-mab/m-p/4319538#M566628</guid>
      <dc:creator>promero</dc:creator>
      <dc:date>2021-04-06T20:18:05Z</dc:date>
    </item>
  </channel>
</rss>

