<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x is not detecting STP loop in switch C3850-48P in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4584634#M573837</link>
    <description>&lt;P&gt;"In the default state, when you connect a supplicant switch to an authenticator switch that has BPDU guard enabled, the authenticator port could be error-disabled if it receives a Spanning Tree Protocol (STP) bridge protocol data unit (BPDU) packets before the supplicant switch has authenticated. Beginning with Cisco IOS Release 15.0(1)SE, you can control traffic exiting the supplicant port during the authentication period. Entering the &lt;STRONG&gt;dot1x supplicant controlled transient&lt;/STRONG&gt; global configuration command temporarily blocks the supplicant port during authentication to ensure that the authenticator port does not shut down before authentication completes. If authentication fails, the supplicant port opens. Entering the &lt;STRONG&gt;no do&lt;/STRONG&gt; &lt;STRONG&gt;t1x supplicant controlled transient&lt;/STRONG&gt; global configuration command opens the supplicant port during the authentication period. This is the default behavior.&lt;/P&gt;&lt;P class=""&gt;We strongly recommend using the &lt;STRONG&gt;dot1x supplicant controlled transient &lt;/STRONG&gt;command on a supplicant switch when &lt;STRONG&gt;BPDU guard&lt;/STRONG&gt; is enabled on the authenticator switch port with the &lt;STRONG&gt;spanning-tree bpduguard enable&lt;/STRONG&gt; interface onfiguration command."&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;From Cisco Doc.&lt;BR /&gt;So I think this command is disable and this make traffic pass include BPDU.&lt;/P&gt;</description>
    <pubDate>Sun, 03 Apr 2022 22:05:18 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-04-03T22:05:18Z</dc:date>
    <item>
      <title>Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4583681#M573791</link>
      <description>&lt;P&gt;I have a client who has mistakenly created loop on cisco switch&amp;nbsp;C3850-48P by connecting another cable to the switch from cisco IP phone&amp;nbsp;7811 model. This should ideally be detected by switch and the ports should be blocked since there are BPDU guard configured globally and on interface too. The interfaces are NAC enabled and only dot1x is configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But with mab enabled on the ports, the loop is being detected and port is being sent to err-disabled state. But with only dot1x enabled it is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. will the stp loop detection only work with mab enabled on the switch? with only dot1x it will not work? is this normal behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface config :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/9 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; on this port the IP phone is already connected and authenticated with dot1x&lt;BR /&gt;description PR11-N-10&lt;BR /&gt;switchport access vlan 140&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 232&lt;BR /&gt;logging event status&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout server-timeout 5&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;dot1x max-reauth-req 1&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input TrustDSCP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/29&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; on this port the other cable with connected and creating a loop&lt;BR /&gt;description PR11-N-32&lt;BR /&gt;switchport access vlan 140&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 232&lt;BR /&gt;logging event status&lt;BR /&gt;shutdown &amp;gt;&amp;gt;&amp;gt;&amp;gt; the port is now shut due to the loop situation, once it is opened it created loop and not going to blocked state&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout server-timeout 5&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;dot1x max-reauth-req 1&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input TrustDSCP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is with mab enabled :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mar 25 13:13:52: %SPANTREE-6-PORT_STATE: Port Gi1/0/29 instance 140 moving from disabled to blocking&lt;BR /&gt;Mar 25 13:13:52: %SPANTREE-6-PORT_STATE: Port Gi1/0/29 instance 140 moving from blocking to forwarding&lt;BR /&gt;Mar 25 13:13:52: %SPANTREE-6-PORT_STATE: Port Gi1/0/29 instance 232 moving from disabled to blocking&lt;BR /&gt;Mar 25 13:13:52: %SPANTREE-6-PORT_STATE: Port Gi1/0/29 instance 232 moving from blocking to forwarding&lt;BR /&gt;Mar 25 13:13:52: %SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port Gi1/0/9 with BPDU Guard enabled. Disabling port.&lt;BR /&gt;Mar 25 13:13:52: %PM-4-ERR_DISABLE: bpduguard error detected on Gi1/0/9, putting Gi1/0/9 in err-disable state&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is without mab :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TEPPINETS003-ACC-PR1(config)#int gi 1/0/29&lt;BR /&gt;TEPPINETS003-ACC-PR1(config-if)#no shu&lt;BR /&gt;TEPPINETS003-ACC-PR1(config-if)#no shutdown&lt;BR /&gt;TEPPINETS003-ACC-PR1(config-if)#&lt;BR /&gt;Mar 25 13:09:49: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/29, changed state to up &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; port 29 comes up&lt;BR /&gt;Mar 25 13:09:49: %SPANTREE-6-PORT_STATE: Port Gi1/0/9 instance 232 moving from forwarding to disabled &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; vlan 232 instance of port 9 goes down&lt;BR /&gt;Mar 25 13:09:50: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/29, changed state to up&lt;BR /&gt;Mar 25 13:09:50: %SW_MATM-4-MACFLAP_NOTIF: Host 5897.1e28.0f93 in vlan 232 is flapping between port Gi1/0/29 and port Po1 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; MAC flap, indication of layer 2 loop&lt;BR /&gt;Mar 25 13:09:55: %SW_MATM-4-MACFLAP_NOTIF: Host 1ce6.c799.7ca6 in vlan 232 is flapping between port Gi1/0/29 and port Po1&lt;BR /&gt;Mar 25 13:10:03: %SPANTREE-6-PORT_STATE: Port Gi1/0/9 instance 232 moving from disabled to blocking &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; vlan 232 instance of port 9 changing to blocking&lt;BR /&gt;Mar 25 13:10:03: %SPANTREE-6-PORT_STATE: Port Gi1/0/9 instance 232 moving from blocking to forwarding &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; vlan 232 instance of port 9 changing to forwarding&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to clear this situation.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sanjoy&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 08:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4583681#M573791</guid>
      <dc:creator>Sanjoy4231</dc:creator>
      <dc:date>2022-04-01T08:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4584631#M573836</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1308157"&gt;@Sanjoy4231&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would have expected the BPDU to be independent of whether or not MAB is enabled. A BPDU should not be sent to a RADIUS server as a form of MAB ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this on IOS 15.2 in my lab.&lt;/P&gt;
&lt;PRE&gt;Apr  3 12:43:02.453: dot1x-ev:[Gi1/2] Interface state changed to UP
Apr  3 12:43:02.459: dot1x-ev:DOT1X Supplicant not enabled on GigabitEthernet1/2
Apr  3 12:43:03.201: %SYS-5-CONFIG_I: Configured from console by console
Apr  3 12:43:03.457: &lt;FONT color="#FF0000"&gt;%SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port Gi1/2 with BPDU Guard enabled. Disabling port.&lt;/FONT&gt;
Apr  3 12:43:03.458: %PM-4-ERR_DISABLE: bpduguard error detected on Gi1/2, putting Gi1/2 in err-disable state
Apr  3 12:43:03.462: dot1x-ev:[Gi1/2] Interface state changed to DOWN
Apr  3 12:43:03.463: dot1x-ev:[Gi1/2] No DOT1X subblock found for port down
Apr  3 12:43:04.269: %LINK-3-UPDOWN: Interface GigabitEthernet1/2, changed state to down
CORE#
CORE#
CORE#show derived-config int gi 1/2
Building configuration...

Derived configuration : 287 bytes
!
interface GigabitEthernet1/2
 switchport access vlan 10
 switchport mode access
 negotiation auto
 access-session port-control auto
 dot1x pae authenticator
 spanning-tree portfast edge
 spanning-tree bpduguard enable
 service-policy type control subscriber AI_DOT1X_MAB_POLICIES
end&lt;/PRE&gt;
&lt;P&gt;Same behaviour observed when 'mab' is added back to the config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's an interesting question though, because I expected spanning tree protection to be done independently of processing packets for MAB/EAPOL on the port. When 'mab' is configured on the port, do you see any events in the ISE Live Logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 21:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4584631#M573836</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-04-03T21:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4584634#M573837</link>
      <description>&lt;P&gt;"In the default state, when you connect a supplicant switch to an authenticator switch that has BPDU guard enabled, the authenticator port could be error-disabled if it receives a Spanning Tree Protocol (STP) bridge protocol data unit (BPDU) packets before the supplicant switch has authenticated. Beginning with Cisco IOS Release 15.0(1)SE, you can control traffic exiting the supplicant port during the authentication period. Entering the &lt;STRONG&gt;dot1x supplicant controlled transient&lt;/STRONG&gt; global configuration command temporarily blocks the supplicant port during authentication to ensure that the authenticator port does not shut down before authentication completes. If authentication fails, the supplicant port opens. Entering the &lt;STRONG&gt;no do&lt;/STRONG&gt; &lt;STRONG&gt;t1x supplicant controlled transient&lt;/STRONG&gt; global configuration command opens the supplicant port during the authentication period. This is the default behavior.&lt;/P&gt;&lt;P class=""&gt;We strongly recommend using the &lt;STRONG&gt;dot1x supplicant controlled transient &lt;/STRONG&gt;command on a supplicant switch when &lt;STRONG&gt;BPDU guard&lt;/STRONG&gt; is enabled on the authenticator switch port with the &lt;STRONG&gt;spanning-tree bpduguard enable&lt;/STRONG&gt; interface onfiguration command."&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;From Cisco Doc.&lt;BR /&gt;So I think this command is disable and this make traffic pass include BPDU.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 22:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4584634#M573837</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-03T22:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585329#M573870</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;Thanks for the input. I will try this command and will let you know if this fixes the issue. Although here the client is using a CISCO IP phone as the supplicant. Could the BPDU be received from a CISCO IP phone as this is what's happening here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My issue here is, the STP is not running with only dot1x configured. But with MAB, it is participating fine and upon detecting loop it is also blocking the port. Client wants the same with only dot1x configured the authenticator port.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585329#M573870</guid>
      <dc:creator>Sanjoy4231</dc:creator>
      <dc:date>2022-04-04T14:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585340#M573871</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;Hello Arne, Thanks for your response. I did not check the live logs in ISE and not sure whether the customer is using ISE or not. Will check and update the post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with only dot1x configured, i am not seeing any BPDU produced by the supplicant(CISCO IP phone in this case) which is why the port is not being blocked. Not sure what can be done here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer is using a very old IOS version. Could this be a bug which could possibly be fixed if i upgrade the IOS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 15:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585340#M573871</guid>
      <dc:creator>Sanjoy4231</dc:creator>
      <dc:date>2022-04-04T15:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x is not detecting STP loop in switch C3850-48P</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585395#M573874</link>
      <description>&lt;P&gt;You miss config connect two IP phone to two SW port.&amp;nbsp;&lt;BR /&gt;G0/29-IP phone&amp;nbsp;&lt;BR /&gt;G0/9-ether-port of IP Phone&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, the LOOP how it happened,&amp;nbsp;&lt;BR /&gt;G0/29-IP Phone will be forward STP since the IP Phone not send any BPDU&amp;nbsp;&lt;BR /&gt;G0/9-ether-port return connect to SW so how loop,&amp;nbsp;&lt;BR /&gt;SW send BPDU "even with BPDU guard the SW still send BPDU" the IP phone by default re-forward it back to SW "IP phone assume that PC connect to ether-port"&lt;BR /&gt;SW detect BPDU in BPDU guard and block the port.&lt;BR /&gt;&lt;BR /&gt;keep notice:- G0/9 is block because BPDU not G0/29 which is source of issue.&lt;BR /&gt;&lt;BR /&gt;so here IP phone is bypass BPDU from one SW port to other SW port.&lt;BR /&gt;&lt;BR /&gt;BPDU guard work in data plane and detect BPDU before block port.&lt;BR /&gt;&lt;BR /&gt;802.1x vs mab&amp;nbsp;&lt;BR /&gt;SW with 802.1x only allow EAP to pass through the auth process and after auths/authz it allow all traffic to pass&lt;BR /&gt;&lt;BR /&gt;mab allow any frame from client to learn mac address and this include BPDU&amp;nbsp;&lt;BR /&gt;I think this is why mab make port detect loop.&lt;BR /&gt;&lt;BR /&gt;BUT if 802.1x allow any traffic after auths/authz why the port not block and looping and mac flapping&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;you config multi-auth the voice is success auth/authz&lt;BR /&gt;BUT&lt;BR /&gt;data which is VLAN 140 is never success and all traffic deny except the EAP&lt;BR /&gt;&lt;BR /&gt;Hope this help you to decided best solution here.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 15:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-is-not-detecting-stp-loop-in-switch-c3850-48p/m-p/4585395#M573874</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-04T15:57:49Z</dc:date>
    </item>
  </channel>
</rss>

