<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting IP address - MAB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4440061#M568743</link>
    <description>&lt;P&gt;Hi Mate&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;All other connected endpoints connected to this switch is getting IP address and I'm able to see the relevant MAC address binding for device tracking. Yeah, we do use DHCP for the IP address connectivity and this is the only interface that seems to have problem with.&lt;/P&gt;&lt;P&gt;DHCP Snooping and ARP inspection has been configured for this VLAN and allowed on the Trunk links.&lt;/P&gt;&lt;P&gt;This is a MAB connection and we're pushing Dynamic VLAN in addition to dACL but for some reason, switch isn't able to enforce the dACL (VLAN is enforced).&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2021 05:56:39 GMT</pubDate>
    <dc:creator>Srinivasan Nagarajan</dc:creator>
    <dc:date>2021-07-28T05:56:39Z</dc:date>
    <item>
      <title>Not getting IP address - MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4438945#M568707</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We're using MAB authentication where one of the device is not getting the IP address. I see, the dACL is being pushed from the ISE but doesn't seems to be enforced on the switch port. Switch (2960) version is 15.2 and device tracking is enabled.&lt;/P&gt;&lt;P&gt;When I enter the below command, I don't see any IP Address/MAC address for that switch port. Any idea, what to check further? Thanks in advance&lt;/P&gt;&lt;P&gt;Switch #show ip device tracking interface GigabitEthernet1/0/5&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet1/0/5 is: STAND ALONE&lt;BR /&gt;IP Device Tracking = Enabled&lt;BR /&gt;IP Device Tracking Probe Count = 3&lt;BR /&gt;IP Device Tracking Probe Interval = 30&lt;BR /&gt;IPv6 Device Tracking Client Registered Handle: 171&lt;BR /&gt;IP Device Tracking Enabled Features:&lt;BR /&gt;HOST_TRACK_CLIENT_SM&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 14:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4438945#M568707</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-07-26T14:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting IP address - MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4439151#M568719</link>
      <description>&lt;P&gt;More detailed information is needed to provide useful assistance.&lt;/P&gt;
&lt;P&gt;Is the switch capturing the IP address bindings for other connected endpoints and this is the only one that is not working? Is the endpoint using DHCP or static IP addressing? Do you have other endpoints using the same IP addressing method that are working? Is the endpoint getting an IP address from the DHCP server but the switch is not capturing it?&lt;/P&gt;
&lt;P&gt;See this technote for an overview of how IPDT works for the 15.x code.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html" target="_blank" rel="noopener"&gt;IP Device Tracking (IPDT) Overview&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the endpoint uses DHCP, you might verify that DHCP Snooping is configured globally, on the VLAN, and trust is enabled on your uplink.&lt;/P&gt;
&lt;P&gt;If the endpoint is using static IP, you might need to mirror the port to see if an ARP probe is being sent by the switch and the endpoint is responding.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 23:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4439151#M568719</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-07-26T23:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting IP address - MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4440061#M568743</link>
      <description>&lt;P&gt;Hi Mate&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;All other connected endpoints connected to this switch is getting IP address and I'm able to see the relevant MAC address binding for device tracking. Yeah, we do use DHCP for the IP address connectivity and this is the only interface that seems to have problem with.&lt;/P&gt;&lt;P&gt;DHCP Snooping and ARP inspection has been configured for this VLAN and allowed on the Trunk links.&lt;/P&gt;&lt;P&gt;This is a MAB connection and we're pushing Dynamic VLAN in addition to dACL but for some reason, switch isn't able to enforce the dACL (VLAN is enforced).&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 05:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/not-getting-ip-address-mab/m-p/4440061#M568743</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-07-28T05:56:39Z</dc:date>
    </item>
  </channel>
</rss>

