<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Double dynamic vlan assignement on interface ISE MAB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4811717#M581055</link>
    <description>&lt;P&gt;Here is the switchport configuration :&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;ip flow monitor dnacmonitor input&lt;BR /&gt;ip flow monitor dnacmonitor output&lt;BR /&gt;load-interval 30&lt;BR /&gt;access-session inherit disable interface-template-sticky&lt;BR /&gt;access-session inherit disable autoconf&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;no macro auto processing&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout supp-timeout 7&lt;BR /&gt;dot1x max-req 3&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 2046&lt;BR /&gt;mab&lt;BR /&gt;access-session closed&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;service-policy type control subscriber PMAP_DefaultWiredDot1xClosedAuth_1X_MAB&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input DNA-MARKING_IN&lt;BR /&gt;service-policy output DNA-dscp#APIC_QOS_Q_OUT&lt;BR /&gt;ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt;The dynamic vlan is the 1022 (voice vlan) with a DHCP server pool.&lt;/P&gt;&lt;P&gt;the 2046 vlan is a voice vlan included in the cisco Closed wired authentication template on the port with no IP pool.&lt;/P&gt;&lt;P&gt;As my understanding, the Phone is not able to have an IP from the voice vlan IP pool, so it is put in the vlan 1 (default) and the voice vlan, but as there is no pool associated it does not get any IP. When I add a data vlan on the switchport with a dhcp IP pool, the Phone gets an IP address on this vlan and is working.&lt;/P&gt;&lt;P&gt;Here is the mac table for the phone port :&lt;/P&gt;&lt;P&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/P&gt;&lt;P&gt;Vlan&amp;nbsp; &amp;nbsp; &amp;nbsp;Mac Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp; &amp;nbsp; &amp;nbsp; -----------&amp;nbsp; &amp;nbsp; &amp;nbsp; --------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-----&lt;BR /&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0004.f271.7a12&amp;nbsp; &amp;nbsp; &amp;nbsp; STATIC&amp;nbsp; &amp;nbsp; Gi1/0/14&lt;BR /&gt;1022&amp;nbsp; &amp;nbsp; 0004.f271.7a12&amp;nbsp; &amp;nbsp; STATIC&amp;nbsp; &amp;nbsp; Gi1/0/14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 08:57:35 GMT</pubDate>
    <dc:creator>Louey</dc:creator>
    <dc:date>2023-04-11T08:57:35Z</dc:date>
    <item>
      <title>Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808527#M580953</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We are implementing mab for our IP-Phones.&lt;/P&gt;&lt;P&gt;I made an authorization policy to assign a dynamic vlan to them once authenticated. The authencation passed and authorization policy matched but in addition to the dynamic vlan, they are getting the default vlan 1 also as shown below :&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt;---- ----------- -------- -----&lt;BR /&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp;70ca.9b9f.2a42&amp;nbsp; STATIC&amp;nbsp; Gi1/0/33&lt;BR /&gt;1022&amp;nbsp; &amp;nbsp; 70ca.9b9f.2a42&amp;nbsp; STATIC&amp;nbsp; Gi1/0/33&lt;/P&gt;&lt;P&gt;This make the phones not getting an IP in the designed vlan and not getting reachable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any helps for that please ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 09:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808527#M580953</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-04-05T09:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808699#M580954</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check ISE &lt;STRONG&gt;(live&lt;/STRONG&gt;) logs for the particular authentication(s) and observe if the policy works as intended or not &lt;EM&gt;(to start with)&lt;/EM&gt; ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 10:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808699#M580954</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-05T10:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808732#M580955</link>
      <description>&lt;P&gt;It is matching the right authentication policy and authentication is passed. Even the authZ policy is okay it is just that the phone is not getting an ip address on the configured dynamic voice vlan. the dynamic vlan is 1022 (which is a voice vlan) and I checked also "voice domain permission" on hte AuthZ policy.&lt;/P&gt;&lt;P&gt;The phone is not reachable as getting the wrong IP or no IP at all, and two vlans appear on the switchport.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 11:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808732#M580955</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-04-05T11:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808743#M580956</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check interface configuration according to :&amp;nbsp;&lt;A href="https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_aaa/configuration/15-2mt/sec-config-mab.html" target="_blank"&gt;https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_aaa/configuration/15-2mt/sec-config-mab.html&lt;/A&gt;&amp;nbsp; (and or review the examples)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 11:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4808743#M580956</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-05T11:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4810617#M581025</link>
      <description>&lt;P&gt;You have not shared any switch configurations so it is impossible to know what you may or may not be doing wrong with your VLAN or more likely your 802.1X/MAB switchport authentications.&amp;nbsp; We have best practice configurations documented in the &lt;LI-MESSAGE title="ISE Secure Wired Access Prescriptive Deployment Guide" uid="3641515" url="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/m-p/3641515#U3641515" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt; including details for the phones.&lt;/P&gt;
&lt;P&gt;Please see &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt; to provide enough details to help us help you with troubleshooting.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2023 22:14:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4810617#M581025</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-04-08T22:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4811717#M581055</link>
      <description>&lt;P&gt;Here is the switchport configuration :&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;ip flow monitor dnacmonitor input&lt;BR /&gt;ip flow monitor dnacmonitor output&lt;BR /&gt;load-interval 30&lt;BR /&gt;access-session inherit disable interface-template-sticky&lt;BR /&gt;access-session inherit disable autoconf&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;no macro auto processing&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout supp-timeout 7&lt;BR /&gt;dot1x max-req 3&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 2046&lt;BR /&gt;mab&lt;BR /&gt;access-session closed&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;service-policy type control subscriber PMAP_DefaultWiredDot1xClosedAuth_1X_MAB&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input DNA-MARKING_IN&lt;BR /&gt;service-policy output DNA-dscp#APIC_QOS_Q_OUT&lt;BR /&gt;ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt;The dynamic vlan is the 1022 (voice vlan) with a DHCP server pool.&lt;/P&gt;&lt;P&gt;the 2046 vlan is a voice vlan included in the cisco Closed wired authentication template on the port with no IP pool.&lt;/P&gt;&lt;P&gt;As my understanding, the Phone is not able to have an IP from the voice vlan IP pool, so it is put in the vlan 1 (default) and the voice vlan, but as there is no pool associated it does not get any IP. When I add a data vlan on the switchport with a dhcp IP pool, the Phone gets an IP address on this vlan and is working.&lt;/P&gt;&lt;P&gt;Here is the mac table for the phone port :&lt;/P&gt;&lt;P&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;/P&gt;&lt;P&gt;Vlan&amp;nbsp; &amp;nbsp; &amp;nbsp;Mac Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp; &amp;nbsp; &amp;nbsp; -----------&amp;nbsp; &amp;nbsp; &amp;nbsp; --------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-----&lt;BR /&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0004.f271.7a12&amp;nbsp; &amp;nbsp; &amp;nbsp; STATIC&amp;nbsp; &amp;nbsp; Gi1/0/14&lt;BR /&gt;1022&amp;nbsp; &amp;nbsp; 0004.f271.7a12&amp;nbsp; &amp;nbsp; STATIC&amp;nbsp; &amp;nbsp; Gi1/0/14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 08:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4811717#M581055</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-04-11T08:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4812076#M581086</link>
      <description>&lt;P&gt;Can you try "access-session host-mode multi-auth" because a voice device first gets learnt in data VLAN and then moves to voice VLAN so to allow both voice and data VLAN use host-mode multi-auth.&lt;/P&gt;
&lt;P&gt;Reference : &lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-mt/sec-user-8021x-15-mt-book/sec-ieee-802x-multi-auth.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/15-mt/sec-user-8021x-15-mt-book/sec-ieee-802x-multi-auth.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 17:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4812076#M581086</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-11T17:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Double dynamic vlan assignement on interface ISE MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4813826#M581134</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I belive you have a 'standard' IP Phone. This means you need a voice VLAN on switch port + your phone sends its own traffic tagged. &lt;BR /&gt;When you authenticate your phone, ISE has to return voice VLAN permissions (voice vlan in the authorization profile) so that your phone can belong to the voice domain. If this does not happen, you phone will not work.&lt;/P&gt;
&lt;P&gt;You cannot combine dynamic vlan assignment with voice vlan permissions. What I'm trying to tell you is that even though you're pushing VLAN 1022 to your switch, that VLAN is a data VLAN from your switch's perspective, not a voice VLAN and the tagged traffic your phone is sending to the switch is dropped.&lt;/P&gt;
&lt;P&gt;Please check this similar post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/dynamic-voice-vlan-assignment-when-different-phone-systems-are/td-p/4812111" target="_blank"&gt;Dynamic voice VLAN assignment when different phone systems are in play - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Like&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532" target="_self"&gt;Arne Bier&lt;/A&gt; mentioned,&amp;nbsp; you can combine voice domain permissions with an interface templace.&lt;/P&gt;
&lt;P&gt;As an alternative you can use a macro locally defined on the switch and refer to that in your authorization profile.&lt;/P&gt;
&lt;P&gt;In the end, you get the same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 15:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/double-dynamic-vlan-assignement-on-interface-ise-mab/m-p/4813826#M581134</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2023-04-13T15:00:41Z</dc:date>
    </item>
  </channel>
</rss>

