<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange MAC adresses from sharp printers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/5219927#M592991</link>
    <description>&lt;P&gt;I get your point about simultaneous MAB/802.1X - it's not pretty in ISE, but it can get you out of a messy situation.&lt;/P&gt;
&lt;P&gt;It's a pity that the switch is so old -&amp;nbsp; I don't suppose it support on-switch packet capture? I'd still want to know what those packets are that are using that strange MAC address.&amp;nbsp; Out of interest, do you have these printers attached to other switch models, and if so, is the behaviour the same?&lt;/P&gt;</description>
    <pubDate>Mon, 04 Nov 2024 19:39:28 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-11-04T19:39:28Z</dc:date>
    <item>
      <title>Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603168#M574450</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this is the right place to post, but anyways.&lt;/P&gt;&lt;P&gt;We have a fair amount of sharp printerson our network. All are connected to the network on ISE IBNS 2.0 and simultaneous dot1x+MAB is enabled on all ports, and the printers are authenticating with MAB just fine.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On all the Switches with Sharp printers i do however see a lot of "Authentication failed" messages in the log.&lt;/P&gt;&lt;P&gt;All coming from this strange mac beginning with 20:00:ff:11&lt;/P&gt;&lt;P&gt;When i do a "sh mac add" or "sh access-session" only the real mac of the printer is shown on the connected interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The macs do however appear in ISE as failed endpoints. As a workaround to not have ISE filled up i have a purge rule that deletes the macs every night.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My initial thought is that the Sharp printers have som network protocol running that generate random macs, but I cant seem to find anything on the printer.&lt;/P&gt;&lt;P&gt;They are all the same model MX-5140N&lt;/P&gt;&lt;P&gt;The switches are all 2960X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if anyone has seen something similar to this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Janne&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 07:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603168#M574450</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2022-05-02T07:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603347#M574455</link>
      <description>&lt;P&gt;Could be, do they run a tablet/android based GUI system?&amp;nbsp; I've also seen some switch bugs cause strangeness like this; SVI MAC addresses showing up on access ports for example.&amp;nbsp; What is your switch code?&amp;nbsp; Also, technically simultaneous auth isn't supported by ISE.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 16:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603347#M574455</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-02T16:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603458#M574468</link>
      <description>&lt;P&gt;That MAC address OUI prefix&lt;A href="https://community.cisco.com/t5/security-documents/random-mac-address-how-to-deal-with-it-using-ise/ta-p/4049321" target="_self"&gt; doesn't conform to a randomised (locally administered) address.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Have you tried running a tcpdump on ISE to try capture a RADIUS request from such an event?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why are you using simultaneous MAB/802.1X - it's kind of ugly because you will always have 50% failures in ISE. In some cases where you have uncooperative endpoints you may need this - but for the most part you could try to do MAB first, then 802.1X (for most fussy non 802.1X devices to play ball).&lt;/P&gt;
&lt;P&gt;Lastly - why do you see so many MAB events? You could try to not set a session timeout for those printers - then they would not auth again - rather rely on RADIUS accounting (interim 2880 minutes) to keep the session alive.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 20:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603458#M574468</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-05-02T20:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603708#M574484</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp; I'm not sure what kind of OS the GUI is running on, but the printers do have a touch screen integrated.&lt;/P&gt;&lt;P&gt;What do you mean with switch code, but the portconfig is attatched.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp; I have not tried running a tcp dump yet, will do that as soon as I got the spare time.&lt;/P&gt;&lt;P&gt;The reason for simultaneous MAB/802.1X is because we encounter problems with legacy devices and other MAB only devices where they dont recieve an IP because the 802.1X takes too long to time-out and by the time MAB is tried the device already got an apipa and wont try again.&lt;BR /&gt;We tried playing with the timers of dot1x but it was very unstable and generated a lot of unnecessary work for us with getting the user to restart endpoints ect.&lt;/P&gt;&lt;P&gt;Also we want a config that fits all to make deployment ect more streamline.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm not sure why i see that many events. The thing is, that the actual mac address of the printer only requests once, and is accepted.&lt;BR /&gt;but the 20:00:ff:11 macs continue only to get rejected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 11:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603708#M574484</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2022-05-03T11:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603820#M574499</link>
      <description>&lt;P&gt;Software version on the 2960X&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 14:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4603820#M574499</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-03T14:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4605576#M574606</link>
      <description>&lt;P&gt;we are running 15.2(2)E9 on our 2960X&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 07:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/4605576#M574606</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2022-05-06T07:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/5219839#M592990</link>
      <description>&lt;P&gt;I have this same issue where MAC's on trunk ports will suddenly appear on the port that the HPE printer is connected to, and then I can't reach the GW SVI. The printer 802.1x is disabled. I use 802.1x on the switch authenticating with Aruba Clearpass.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 17:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/5219839#M592990</guid>
      <dc:creator>tygerdavid1</dc:creator>
      <dc:date>2024-11-04T17:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange MAC adresses from sharp printers</title>
      <link>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/5219927#M592991</link>
      <description>&lt;P&gt;I get your point about simultaneous MAB/802.1X - it's not pretty in ISE, but it can get you out of a messy situation.&lt;/P&gt;
&lt;P&gt;It's a pity that the switch is so old -&amp;nbsp; I don't suppose it support on-switch packet capture? I'd still want to know what those packets are that are using that strange MAC address.&amp;nbsp; Out of interest, do you have these printers attached to other switch models, and if so, is the behaviour the same?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 19:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/strange-mac-adresses-from-sharp-printers/m-p/5219927#M592991</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-11-04T19:39:28Z</dc:date>
    </item>
  </channel>
</rss>

