<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X trying to authenticate phone, not client in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4477279#M570036</link>
    <description>&lt;P&gt;I would suggest reviewing your design and configuration against the &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html" target="_blank" rel="noopener"&gt;IP Telephony for 802.1X Design Guide&lt;/A&gt;. This is an old document, but nothing much has changed around how the phones and PC get authenticated separately and the important mechanisms to understand and configure. These concepts would apply when using any RADIUS server.&lt;/P&gt;
&lt;P&gt;Some key points based on what has been discussed in this thread:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you're using MDA, you need to ensure that the phone is being authorised correctly using the 'device-traffic-class=voice' VSA. If you're not using ISE (with Profiling), you would likely have to apply this result by matching on some sort of static MAC address table with all of your phones in it. If you are not sending this VSA, the phones would be put into the DATA domain and the port would go into err-disable as MDA does not allow more than one session in the DATA domain.&lt;/LI&gt;
&lt;LI&gt;If the phone is authenticated via MAB but periodically tries to authenticate via dot1x, there are a few possible reasons.
&lt;UL&gt;
&lt;LI&gt;The phone itself is configured for 802.1x. If this is the case, it will periodically retry via 802.1x so this setting should be disabled on the phone.&lt;/LI&gt;
&lt;LI&gt;The FlexAuth configuration on the switchport is causing it to try dot1x after a periodic reauth.&lt;/LI&gt;
&lt;LI&gt;A disconnect/reconnect or session timeout it happening, forcing the switchport to restart the auth process. Since 'priority dot1x mab' will assume 'order dot1x mab', the session has to wait for dot1x to timeout first before trying MAB.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For the latter two possibilities, see &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/FlexAuthNote/flexauth-note.html" target="_blank" rel="noopener"&gt;TrustSec 1.99 Deployment Note: FlexAuth Order, Priority, and Failed Authentication&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 22:56:52 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-09-29T22:56:52Z</dc:date>
    <item>
      <title>802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475209#M569968</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing some problems when implementing 802.1X in my environment (Catalyst 2960x).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;802.1X is working fine so far and the config should be right. But sometimes, the switch is trying to authenticate the Cisco Phone and not the windows client. I then get the following message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sep 28 08:32:13.775 MESZ: %DOT1X-5-FAIL: Authentication failed for client (xxxx.xxxx.xxxx) on Interface Gi1/0/16 AuditSessionID XYZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the xxxx.xxxx.xxxx mac-adress is the mac of the phone ... this causes the client to get unauthenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What causes the switch to authenticate the phone and not the client?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port Config:&lt;/P&gt;&lt;P&gt;switchport access vlan 11&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 152&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;storm-control broadcast level pps 100&lt;BR /&gt;storm-control multicast level bps 500k&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AAA-Konfig:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login CON local-case&lt;BR /&gt;aaa authentication login VTY group radius local&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization exec VTY group radius if-authenticated&lt;BR /&gt;aaa authorization exec CON local&lt;BR /&gt;aaa authorization commands 15 VTY if-authenticated&lt;BR /&gt;aaa authorization commands 15 CON local&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 07:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475209#M569968</guid>
      <dc:creator>MH311x</dc:creator>
      <dc:date>2021-09-28T07:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475308#M569970</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1188358"&gt;@MH311x&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that the full interface configuration? Potentially the host mode could be single-host mode (it's not defined and I don't know what the default is on your switch model/version), so only the phone would authenticate, not the PC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try configuring multi-domain "&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;authentication host-mode multi-domain&lt;/SPAN&gt;" under the interface, this will authenticate one device in the voice domain and one device in the data domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are obviously also failing to authenticate the phone, so check the ISE logs to determine why that is failing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to the ISE Wired Guide for more information.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 08:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475308#M569970</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-09-28T08:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475390#M569978</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this is the full interface configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the first step we just want to authenticate the PC and not the phones ... so the phones should not take part in the authentication process. We have a RADIUS-server (no ISE) running which is authenticating the clients ... in 95% this works well. But sometimes the authentication is initalized by the phones mac adress. Is there a way to "ignore" the phone in the authentication process?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the single-host mode would be right, but the "single host" should then be the PC and not the phone. Is there a way to force this?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 09:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475390#M569978</guid>
      <dc:creator>MH311x</dc:creator>
      <dc:date>2021-09-28T09:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475402#M569979</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1188358"&gt;@MH311x&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No unfortunately that's not possible, according to this post, there used to be a feature to bypass phone authentication, but this was depreciated years ago.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/802-1x-single-host-mode/td-p/2734265" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/802-1x-single-host-mode/td-p/2734265&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to use multi-domain and authenticate both the PC and Phone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 10:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475402#M569979</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-09-28T10:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475445#M569981</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay, thanks for the information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since we have no ISE, is there a way to configure the host mode to multi-domain but authenticating the phone via MAB and the PC via EAP/802.1X?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 11:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475445#M569981</guid>
      <dc:creator>MH311x</dc:creator>
      <dc:date>2021-09-28T11:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475452#M569983</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1188358"&gt;@MH311x&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If using MAB the endpoint will send it's MAC address as the username and password, so whatever RADIUS server/backend authentication identity store you are using will need a username/password defined for each phone.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 11:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475452#M569983</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-09-28T11:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475454#M569984</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, thats no problem. The mac adresses of the phones are all stored in our NAC (which is also the radius-server), so this should be fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am just wondering about the port configuration to achieve this, because I have to use two different authentication types on one port.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 11:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475454#M569984</guid>
      <dc:creator>MH311x</dc:creator>
      <dc:date>2021-09-28T11:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475461#M569985</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1188358"&gt;@MH311x&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You configure "&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;authentication host-mode multi-domain&lt;/SPAN&gt;" under the interface.&lt;/P&gt;
&lt;PRE&gt;interface gigabitethernet 1/0/1&lt;BR /&gt; a&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;uthentication host-mode multi-domain&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Sep 2021 11:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4475461#M569985</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-09-28T11:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4476701#M570014</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That doesn't solve the problem, because I want to authenticate the phone via MAB and the PC via 802.1X.&lt;/P&gt;&lt;P&gt;When configuing authentication host-mode multi-domain, the phone is also authenticated via 802.1X.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to configure the following now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;BR /&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;BR /&gt;dot1x max-reauth-req 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;... but the phone does no fallback to MAB (or the port get in err-disabled state before it would fallback to mab).&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 10:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4476701#M570014</guid>
      <dc:creator>MH311x</dc:creator>
      <dc:date>2021-09-29T10:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4476759#M570015</link>
      <description>&lt;P&gt;you also need to configure&lt;/P&gt;&lt;PRE&gt;authentication order dot1x mab&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 11:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4476759#M570015</guid>
      <dc:creator>martin.fischer</dc:creator>
      <dc:date>2021-09-29T11:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4477279#M570036</link>
      <description>&lt;P&gt;I would suggest reviewing your design and configuration against the &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html" target="_blank" rel="noopener"&gt;IP Telephony for 802.1X Design Guide&lt;/A&gt;. This is an old document, but nothing much has changed around how the phones and PC get authenticated separately and the important mechanisms to understand and configure. These concepts would apply when using any RADIUS server.&lt;/P&gt;
&lt;P&gt;Some key points based on what has been discussed in this thread:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If you're using MDA, you need to ensure that the phone is being authorised correctly using the 'device-traffic-class=voice' VSA. If you're not using ISE (with Profiling), you would likely have to apply this result by matching on some sort of static MAC address table with all of your phones in it. If you are not sending this VSA, the phones would be put into the DATA domain and the port would go into err-disable as MDA does not allow more than one session in the DATA domain.&lt;/LI&gt;
&lt;LI&gt;If the phone is authenticated via MAB but periodically tries to authenticate via dot1x, there are a few possible reasons.
&lt;UL&gt;
&lt;LI&gt;The phone itself is configured for 802.1x. If this is the case, it will periodically retry via 802.1x so this setting should be disabled on the phone.&lt;/LI&gt;
&lt;LI&gt;The FlexAuth configuration on the switchport is causing it to try dot1x after a periodic reauth.&lt;/LI&gt;
&lt;LI&gt;A disconnect/reconnect or session timeout it happening, forcing the switchport to restart the auth process. Since 'priority dot1x mab' will assume 'order dot1x mab', the session has to wait for dot1x to timeout first before trying MAB.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For the latter two possibilities, see &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/FlexAuthNote/flexauth-note.html" target="_blank" rel="noopener"&gt;TrustSec 1.99 Deployment Note: FlexAuth Order, Priority, and Failed Authentication&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 22:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4477279#M570036</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-09-29T22:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X trying to authenticate phone, not client</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4477799#M570067</link>
      <description>&lt;P&gt;You should also add the line "mab" to the port config.&lt;BR /&gt;When using mab, the switch captures it and sends it to the radius server, the device isn't aware of any auth taking place.&lt;/P&gt;
&lt;P&gt;Configure auth host-mode multi-domain also.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-trying-to-authenticate-phone-not-client/m-p/4477799#M570067</guid>
      <dc:creator>ComputerRick</dc:creator>
      <dc:date>2021-09-30T15:31:56Z</dc:date>
    </item>
  </channel>
</rss>

