<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with 802.1x on C2960S-48TS-L in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4488810#M570512</link>
    <description>&lt;P&gt;The first thing you should try is removing the 'switchport port-security' configuration from the switchport. It is not compatible with the mab/dot1x NAC features running on the same switchport and can cause race conditions and unpredictable behaviour.&lt;/P&gt;
&lt;P&gt;The same is true of any Catalyst switch model.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 21:29:04 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-10-19T21:29:04Z</dc:date>
    <item>
      <title>Problem with 802.1x on C2960S-48TS-L</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4488463#M570499</link>
      <description>&lt;P&gt;Sometimes after rebooting device connected to 801.x port this device successfully perfoming 802.1x authentication&lt;/P&gt;&lt;PRE&gt;Oct 19 13:29:27.869 MSK: %LINK-3-UPDOWN: Interface GigabitEthernet3/0/23, changed state to down
Oct 19 13:29:28.980 MSK: %AUTHMGR-5-START: Starting 'dot1x' for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023C057D460F9
Oct 19 13:29:30.831 MSK: %LINK-3-UPDOWN: Interface GigabitEthernet3/0/23, changed state to up
Oct 19 13:29:30.836 MSK: %DOT1X-5-SUCCESS: Authentication successful for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023C057D460F9
Oct 19 13:29:30.889 MSK: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023C057D460F9
Oct 19 13:29:31.832 MSK: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet3/0/23, changed state to up&lt;/PRE&gt;&lt;PRE&gt;Gi3/0/23     1060.4b76.0515 dot1x   DATA    Auth      00000000000023C057D460F9&lt;/PRE&gt;&lt;P&gt;But port blocking any traffic to/from this device.&lt;/P&gt;&lt;P&gt;After wait a few minutes - starting new "Auth" session and this port is working normally&lt;/P&gt;&lt;PRE&gt;Oct 19 13:36:32.462 MSK: %AUTHMGR-5-START: Starting 'dot1x' for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023CB57DAD729
Oct 19 13:36:32.656 MSK: %DOT1X-5-SUCCESS: Authentication successful for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023CB57DAD729
Oct 19 13:36:33.270 MSK: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (1060.4b76.0515) on Interface Gi3/0/23 AuditSessionID 00000000000023CB57DAD729&lt;/PRE&gt;&lt;P&gt;If i shudown/no shutdown or reconnect ethernet wire - starting a new "Auth" sesssion and port working fine.&lt;/P&gt;&lt;P&gt;Port configuration:&lt;/P&gt;&lt;PRE&gt;interface GigabitEthernet3/0/23
 description ### Universal WorkPort ###
 switchport access vlan 42
 switchport mode access
 switchport nonegotiate
 switchport voice vlan 400
 switchport port-security maximum 3
 switchport port-security violation  restrict
 switchport port-security aging time 2
 switchport port-security aging type inactivity
 switchport port-security
 ip arp inspection limit rate 50
 authentication event fail action authorize vlan 997
 authentication event no-response action authorize vlan 997
 authentication host-mode multi-auth
 authentication port-control auto
 authentication periodic
 authentication timer inactivity 15
 mab
 mls qos trust device cisco-phone
 dot1x pae authenticator
 storm-control broadcast level 1.50
 storm-control action shutdown
 no vtp
 spanning-tree portfast
 spanning-tree bpduguard enable
 ip dhcp snooping limit rate 100&lt;/PRE&gt;&lt;PRE&gt;Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 15.2(2)E9, RELEASE SOFTWARE (fc4)&lt;/PRE&gt;&lt;P&gt;On another switch models this configuration working without problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4488463#M570499</guid>
      <dc:creator>zuev_oleg</dc:creator>
      <dc:date>2021-10-19T13:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with 802.1x on C2960S-48TS-L</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4488810#M570512</link>
      <description>&lt;P&gt;The first thing you should try is removing the 'switchport port-security' configuration from the switchport. It is not compatible with the mab/dot1x NAC features running on the same switchport and can cause race conditions and unpredictable behaviour.&lt;/P&gt;
&lt;P&gt;The same is true of any Catalyst switch model.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 21:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4488810#M570512</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-10-19T21:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with 802.1x on C2960S-48TS-L</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4489103#M570524</link>
      <description>&lt;P&gt;Removing 'switchport port-security' configuration not helped.&lt;/P&gt;&lt;P&gt;PS. If remove port-security configuration - how to defend from 'mac flooding' type attack?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 10:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-802-1x-on-c2960s-48ts-l/m-p/4489103#M570524</guid>
      <dc:creator>zuev_oleg</dc:creator>
      <dc:date>2021-10-20T10:53:51Z</dc:date>
    </item>
  </channel>
</rss>

