<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access-session host-mode multi-domain enforcement issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5032017#M587874</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Wanted to see if anyone has observed this design issue I have been noticing.&amp;nbsp; (Across multiple code trains).&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Most of my testing at this point has been done on 9200 Compact,&amp;nbsp; but issues seems to be persistent on different hardware.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Goal:&amp;nbsp; Restrict port to One Workstation, One Phone, using host-mode multi-domain.&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;Important to note the Interface is operating in open mode from an ISE authentication perspective&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue: Enforcement behavior differences between "restrict" and "protect"&lt;/STRONG&gt;&lt;BR /&gt;Restrict mode does not seem to properly enforce the expected behavior with&amp;nbsp;Access-session host-mode multi-domain&lt;/P&gt;
&lt;P&gt;1) Protect works as expected, and is properly enforcing the port to&amp;nbsp;One Workstation, One Phone&lt;BR /&gt;protect - silently drop violating packets&lt;BR /&gt;2) Restrict mode seems to be operating in a very buggy pattern, and not enforcing (sort of)&lt;BR /&gt;restrict - drop violating packets and generate a syslog&lt;/P&gt;
&lt;P&gt;To my understanding, both options should do enforcement, restrict mode also providing syslogging on the failure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Details on findings:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;On the surface, both modes seem to be doing the same thing.&amp;nbsp; Here are the similarities (what's working)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1) Both modes restrict allowed authentications to 2 devices.&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;show access-session interface gigabitEthernet 1/0/8&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Security violation caused by &lt;STRONG&gt;1111.2222.3333&lt;/STRONG&gt;: Violation action is &lt;/EM&gt;(restrict or protect)&lt;BR /&gt;&lt;EM&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; Domain&amp;nbsp; Status Fg&amp;nbsp; Session ID&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1111.1111.1111&amp;nbsp;dot1x&amp;nbsp;&amp;nbsp; VOICE&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XXXXXXXXX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Gi1/0/8&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222.2222.2222 mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DATA&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XXXXXXXXX&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;2) Both modes limit the mac address table to 2 devices&lt;BR /&gt;&lt;EM&gt;show mac address-table | include 1/0/8&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10&amp;nbsp;&amp;nbsp; 1111.1111.1111&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/8 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2222.2222.2222&amp;nbsp; &amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/8&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here is what's not working / buggy? (Restrict mode only)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1) Device-Tracking Database is learning about additional devices&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;show device-tracking database | inc 1/0/8&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;ARP 10.10.13.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222.2222.2222 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0005&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp; &amp;nbsp;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DH4 10.10.10.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1111.1111.1111&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0024&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;DH4 10.10.13.2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;1111.2222.3333 &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0024&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;Now this is where things get weird&lt;BR /&gt;- Running restrict mode, only 2 devices are authenticated&lt;BR /&gt;- Only 2 MACs are learned in the MAC address table (matching the authenticated devices&lt;BR /&gt;- &lt;STRONG&gt;All 3 devices are still pingable / reachable&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;What this looks like to me, is while restrict mode is preventing additional devices from showing up in the MAC address table, it is NOT actually dropping traffic as described.&amp;nbsp; Protect mode does not have the same issue.&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;Any thoughts on this fun one? !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 21:09:11 GMT</pubDate>
    <dc:creator>Kevin Marcan</dc:creator>
    <dc:date>2024-03-01T21:09:11Z</dc:date>
    <item>
      <title>Access-session host-mode multi-domain enforcement issues</title>
      <link>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5032017#M587874</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Wanted to see if anyone has observed this design issue I have been noticing.&amp;nbsp; (Across multiple code trains).&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Most of my testing at this point has been done on 9200 Compact,&amp;nbsp; but issues seems to be persistent on different hardware.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Goal:&amp;nbsp; Restrict port to One Workstation, One Phone, using host-mode multi-domain.&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;Important to note the Interface is operating in open mode from an ISE authentication perspective&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue: Enforcement behavior differences between "restrict" and "protect"&lt;/STRONG&gt;&lt;BR /&gt;Restrict mode does not seem to properly enforce the expected behavior with&amp;nbsp;Access-session host-mode multi-domain&lt;/P&gt;
&lt;P&gt;1) Protect works as expected, and is properly enforcing the port to&amp;nbsp;One Workstation, One Phone&lt;BR /&gt;protect - silently drop violating packets&lt;BR /&gt;2) Restrict mode seems to be operating in a very buggy pattern, and not enforcing (sort of)&lt;BR /&gt;restrict - drop violating packets and generate a syslog&lt;/P&gt;
&lt;P&gt;To my understanding, both options should do enforcement, restrict mode also providing syslogging on the failure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Details on findings:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;On the surface, both modes seem to be doing the same thing.&amp;nbsp; Here are the similarities (what's working)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1) Both modes restrict allowed authentications to 2 devices.&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;show access-session interface gigabitEthernet 1/0/8&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Security violation caused by &lt;STRONG&gt;1111.2222.3333&lt;/STRONG&gt;: Violation action is &lt;/EM&gt;(restrict or protect)&lt;BR /&gt;&lt;EM&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; Domain&amp;nbsp; Status Fg&amp;nbsp; Session ID&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1111.1111.1111&amp;nbsp;dot1x&amp;nbsp;&amp;nbsp; VOICE&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XXXXXXXXX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Gi1/0/8&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222.2222.2222 mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DATA&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XXXXXXXXX&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;2) Both modes limit the mac address table to 2 devices&lt;BR /&gt;&lt;EM&gt;show mac address-table | include 1/0/8&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10&amp;nbsp;&amp;nbsp; 1111.1111.1111&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/8 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;13&amp;nbsp;&amp;nbsp;&amp;nbsp; 2222.2222.2222&amp;nbsp; &amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/8&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here is what's not working / buggy? (Restrict mode only)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1) Device-Tracking Database is learning about additional devices&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;show device-tracking database | inc 1/0/8&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&lt;EM&gt;ARP 10.10.13.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2222.2222.2222 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0005&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp; &amp;nbsp;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DH4 10.10.10.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1111.1111.1111&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0024&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;DH4 10.10.13.2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;1111.2222.3333 &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gi1/0/8&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0024&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REACHABLE&amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;Now this is where things get weird&lt;BR /&gt;- Running restrict mode, only 2 devices are authenticated&lt;BR /&gt;- Only 2 MACs are learned in the MAC address table (matching the authenticated devices&lt;BR /&gt;- &lt;STRONG&gt;All 3 devices are still pingable / reachable&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;What this looks like to me, is while restrict mode is preventing additional devices from showing up in the MAC address table, it is NOT actually dropping traffic as described.&amp;nbsp; Protect mode does not have the same issue.&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="xxmsonormal"&gt;Any thoughts on this fun one? !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 21:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5032017#M587874</guid>
      <dc:creator>Kevin Marcan</dc:creator>
      <dc:date>2024-03-01T21:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access-session host-mode multi-domain enforcement issues</title>
      <link>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5032058#M587875</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292087"&gt;@Kevin Marcan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yeah &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 22:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5032058#M587875</guid>
      <dc:creator>Ruben Cocheno</dc:creator>
      <dc:date>2024-03-01T22:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Access-session host-mode multi-domain enforcement issues</title>
      <link>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5033196#M587890</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292087"&gt;@Kevin Marcan&lt;/a&gt;&amp;nbsp;- that's interesting - I have not noticed this myself because I tend to shy away from multi-domain (mostly due to misbehaving desktop phones (avaya) that can have buggy FW from time to time - they don't land in the VOICE domain ... and then err-disable the port when PC and phone exceed the allowed MAC in DATA domain). This is in Low-Impact Mode BTW.&lt;/P&gt;
&lt;P&gt;You mentioned open mode. Isn't it expected that there is no enforcement in open mode? I hadn't thought about what that means in terms of this MAC address limit though. I could be wrong.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it worth sharing your "show derived-interface XXX" so we can see what is configured ?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2024 20:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5033196#M587890</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-03-03T20:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access-session host-mode multi-domain enforcement issues</title>
      <link>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5033313#M587897</link>
      <description>&lt;P&gt;Pretty standard config.&amp;nbsp; &amp;nbsp;Some background is I am essentially looking to replicate what has been previously in place with port-security.&amp;nbsp;&lt;BR /&gt;- Enforce a maximum mac address limit (Port Security)&lt;BR /&gt;- Open mode from a ISE Auth perspective.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Closed mode does technically make restrict work, but at this stage I am hoping to avoid closed mode.&lt;BR /&gt;What I do find interesting is the behavior difference between restrict and protect,&amp;nbsp; that is the part I am really getting hung up on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;interface GigabitEthernet1/0/8&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;description WiredISE Normal Port&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport access vlan 13&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport voice vlan 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication periodic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer reauthenticate server&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;access-session host-mode multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;access-session port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;service-policy type control subscriber DOT1X-MAB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ip dhcp snooping limit rate 100&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 05:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-session-host-mode-multi-domain-enforcement-issues/m-p/5033313#M587897</guid>
      <dc:creator>Kevin Marcan</dc:creator>
      <dc:date>2024-03-04T05:42:55Z</dc:date>
    </item>
  </channel>
</rss>

