<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mitel - DHCP Discovery in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076986#M588971</link>
    <description>&lt;P&gt;&lt;SPAN&gt;authentication event fail action next-method &amp;lt;- only remove this and keep your port config as it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 09:15:39 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-04-24T09:15:39Z</dc:date>
    <item>
      <title>Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076112#M588925</link>
      <description>&lt;P&gt;Hi, I have a Mitel 5312 phone plugged into a switchport configured for ISE but when it boots up it gets stuck on DHCP Discovery. If I put the port to authentication open then it goes through and boots up as normal.&lt;/P&gt;&lt;P&gt;The logs all look ok but I can't see why it's not getting an ip address.&lt;/P&gt;&lt;P&gt;This is for MAB.&lt;/P&gt;&lt;P&gt;Any ideas? thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076112#M588925</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T11:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076125#M588926</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286969"&gt;@alliasneo1&lt;/a&gt; when the switch is in closed mode, is the phone actually successfully authenticated and authorised in ISE? &lt;/P&gt;
&lt;P&gt;Are you pushing down the voice domain permission as well? &lt;A href="https://www.ciscopress.com/articles/article.asp?p=2091952&amp;amp;seqNum=4" target="_blank"&gt;https://www.ciscopress.com/articles/article.asp?p=2091952&amp;amp;seqNum=4&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076125#M588926</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-23T11:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076134#M588927</link>
      <description>&lt;P&gt;you need to use low-impact mode&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 11:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076134#M588927</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-23T11:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076179#M588929</link>
      <description>&lt;P&gt;I ran into similar issues a few times with my customers and the issue was caused by the delay between switching from dot1x to MAB. The fix in my cases was to flip the order by making MAB first and then dot1x leaving the priority to be dot1x first and then MAB. Not sure if this is the case in your scenario.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076179#M588929</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T12:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076186#M588930</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your response, I tried reversing the order but keeping the priority the same but this didn't work.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076186#M588930</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T12:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076189#M588931</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Low impact mode would completly change the port config though wouldn't it?&lt;/P&gt;&lt;P&gt;At the moment I have this as the config:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/23&lt;BR /&gt;description 'PHONE'&lt;BR /&gt;switchport access vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 65535&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as I understand Low impact mode it would change it to be more like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;interface gx/x/x&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication host-mode multi-auth&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication open&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication port-control auto&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mab&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dot1x ape authenticator&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip access-group default-ACL in&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;exit&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip access-list extended default-ACL&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;permit udp any any log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;deny ip any any log&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076189#M588931</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T12:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076197#M588932</link>
      <description>&lt;P&gt;You're welcome. I would suggest you try to remove dot1x from a switch port config leaving only MAB and test, if that works, then the issue would most likely be the timer of falling back from dot1x to MAB. In that case you can try to reduce the timers gradually until you find the right value that allows the phone to get their IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076197#M588932</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T12:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076213#M588933</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes the phone has succesfully authenticated and it is authorised.&lt;/P&gt;&lt;P&gt;The switch is currently in closed mode, this is the port config:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/23&lt;BR /&gt;description 'PHONE'&lt;BR /&gt;switchport access vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 65535&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076213#M588933</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T12:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076242#M588934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if I've done this correctly but I stripped back the config to this:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/23&lt;BR /&gt;description 'PHONE'&lt;BR /&gt;switchport access vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan &lt;STRONG&gt;xx&lt;/STRONG&gt;&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;But it still fails. As soon as I add authentication open to this, it works.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076242#M588934</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T13:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076246#M588935</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286969"&gt;@alliasneo1&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;What about the voice-domain permission pushed down to the NAD?&lt;/P&gt;
&lt;P&gt;Your dot1x tx-period is not excessively long, so I would not expect the endpoint to time out waiting for a DHCP request. I've a customer with also with mitel phones and tx-period of 10 seconds, they work fine.&lt;/P&gt;
&lt;P&gt;FYI the recommended dot1x timer values are:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config-if)#dot1x timeout tx-period 7
c9300-Sw(config-if)#dot1x max-reauth-req 3&lt;/PRE&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Enable RADIUS/AAA debugs, test and provide the output for review.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076246#M588935</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-23T13:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076257#M588936</link>
      <description>&lt;P&gt;When you say, &lt;EM&gt;What about the voice-domain permission pushed down to the NAD?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I have the 'Authorisation Profile' with 'Voice Domain Permission' ticked under common tasks. - Is that all I need?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076257#M588936</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T13:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076266#M588938</link>
      <description>&lt;P&gt;Yeah you got it right. Could you please share the output of the command "show authentication sessions interface &amp;lt; &lt;EM&gt;the interface where a phone is connected&lt;/EM&gt; &amp;gt; details" for review? the command should be issued while the port is configured in closed mode please.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076266#M588938</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T13:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076267#M588939</link>
      <description>&lt;P&gt;I just pasted the config back onto the port and removed authentication open and the phone is working now. I can see the ip address in ISE. How strange.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076267#M588939</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T13:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076271#M588940</link>
      <description>&lt;P&gt;It appears to be working now. I put the port config back on and removed authentiation open. rebooted the phone and now it's booted up correctly and I can see the ip address in ISE.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076271#M588940</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-23T13:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076305#M588942</link>
      <description>&lt;P&gt;Glad it worked. If you see some inconsistent behaviour, probably worth checking with the vendor if there is any known issues with the firmware release they are running and maybe there is an updated firmware version.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076305#M588942</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T14:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076311#M588944</link>
      <description>&lt;P&gt;Yes, but if you move the 802.1x and it work then there is issue in order, let me check it&amp;nbsp;&lt;BR /&gt;update you tonight&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076311#M588944</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-23T14:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mitel - DHCP Discovery</title>
      <link>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076986#M588971</link>
      <description>&lt;P&gt;&lt;SPAN&gt;authentication event fail action next-method &amp;lt;- only remove this and keep your port config as it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 09:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mitel-dhcp-discovery/m-p/5076986#M588971</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-24T09:15:39Z</dc:date>
    </item>
  </channel>
</rss>

