<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Aaron:our office have 5 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060357#M7476</link>
    <description>&lt;P&gt;Hi Aaron:&lt;/P&gt;&lt;P&gt;our office have 5 floores in the office building, and we have 4 or 5 switches stacked every floor. and we find several users have this porblem in every floor.&lt;/P&gt;&lt;P&gt;all of the failed mac address in the ACS is the same error message "&lt;SPAN style="font-size: 14.3999996185303px; line-height: normal;"&gt;22056 Subject not found in the applicable identity store(s). : Authentication failed&lt;/SPAN&gt;".&amp;nbsp;&lt;/P&gt;&lt;P&gt;it if difficult for me to debug in the switch.&lt;/P&gt;&lt;P&gt;do you know this command "&lt;SPAN style="color: rgb(0, 0, 0); font-family: 'Courier New', Courier, mono; font-size: 12.8800001144409px; line-height: 18px;"&gt;authentication mac-move permit&lt;/SPAN&gt;"? &amp;nbsp;I am not sure whether this command could fix the problem or not.&lt;/P&gt;&lt;H3 class="p_H_Head2" style="font-size: 12.8800001144409px; color: rgb(51, 102, 102); font-weight: bold; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; line-height: normal;"&gt;Enabling MAC Move&lt;/H3&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274656"&gt;&lt;/A&gt;MAC move allows an authenticated host to move from one port on the switch to another.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274657"&gt;&lt;/A&gt;Beginning in privileged EXEC mode, follow these steps to globally enable MAC move on the switch. This procedure is optional.&lt;/P&gt;&lt;P class="pTableAnchor" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 2px; margin-right: 0em; margin-bottom: 0px; margin-left: 0em; line-height: normal;"&gt;&lt;A name="pgfId-1328027"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV align="left" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.8800001144409px; line-height: normal;"&gt;&lt;TABLE border="1" bordercolor="#808080" cellpadding="3" cellspacing="0" width="96%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&amp;nbsp;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&lt;DIV class="pCH1_CellHead1" style="color: rgb(51, 102, 102); font-size: 13.5240001678467px; margin: 0em; text-indent: 0em;"&gt;&lt;A name="pgfId-1328035"&gt;&lt;/A&gt;Command&lt;/DIV&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&lt;DIV class="pCH1_CellHead1" style="color: rgb(51, 102, 102); font-size: 13.5240001678467px; margin: 0em; text-indent: 0em;"&gt;&lt;A name="pgfId-1328037"&gt;&lt;/A&gt;Purpose&lt;/DIV&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSF_CellStepFirst" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328039"&gt;&lt;/A&gt;Step 1&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328140"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;configure terminal&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328142"&gt;&lt;/A&gt;Enter global configuration mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328045"&gt;&lt;/A&gt;Step 2&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328144"&gt;&lt;/A&gt;authentication mac-move permit&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328146"&gt;&lt;/A&gt;Enable MAC move on the switch.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328160"&gt;&lt;/A&gt;Step 3&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328166"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;end&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328168"&gt;&lt;/A&gt;Return to privileged EXEC mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328154"&gt;&lt;/A&gt;Step 4&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328170"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;show running-config&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328172"&gt;&lt;/A&gt;Verify your entries.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328148"&gt;&lt;/A&gt;Step 5&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328178"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;copy running-config startup-config&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328180"&gt;&lt;/A&gt;(Optional) Save your entries in the configuration file.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274685"&gt;&lt;/A&gt;This example shows how to globally enable MAC move on a switch:&lt;/P&gt;&lt;DIV class="pEx1_Example1" style="color: rgb(0, 0, 0); font-family: 'Courier New', Courier, mono; margin: 0px 0em; line-height: 18px; font-size: 12.8800001144409px;"&gt;&lt;A name="pgfId-1274686"&gt;&lt;/A&gt;Switch(config)# authentication mac-move permit&lt;/DIV&gt;</description>
    <pubDate>Fri, 18 Sep 2015 09:10:43 GMT</pubDate>
    <dc:creator>yangsonggui</dc:creator>
    <dc:date>2015-09-18T09:10:43Z</dc:date>
    <item>
      <title>Cisco ACS 5.1 802.1x auth fails on LAN when WLAN connected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060345#M7464</link>
      <description>&lt;P&gt;I am running Cisco ACS 5.1 802.1x with certificate based authentication for Wired and Wireless connections. The issue that I am having is that when a user comes in from home with their laptop the wireless connection works, they pass the authentication and have network access fine. But when the plug the laptop into a docking station the LAN connection fails and gets put in the Auth Failure Vlan.&amp;nbsp; &lt;/P&gt;&lt;P&gt;A reboot of the phone/ shut/no shut fixes this, but I really need to find a resolution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an intermittent fault and only effects users with both LAN and WLAN enabled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running ACS 5.1.0.44, all Cisco 3750s - c3750-ipservicesk9-mz.122-55.SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Certificates are issues by group policy and only using computer authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be greatly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060345#M7464</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2020-02-21T18:27:40Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.1 802.1x auth fails on LAN when WLAN connected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060346#M7465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I forgot to mention, we are running Mitel 3300 MCD 5, with Mitel 5330 phones. The problem we are having with a Laptop plugged into the back of a phone,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Aug 2012 12:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060346#M7465</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2012-08-28T12:24:18Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.1 802.1x auth fails on LAN when WLAN connected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060347#M7466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; After a long TAC case with Cisco we discovered that the Mitel phone was not sending the EAPoL-Logoff packet so the switch still thought that the device off the back of the phone was connected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; There are no EAPoL-Logoff messages seen on switch when laptop is disconnected/port is shut down.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_1.99/Dot1X_Deployment/Dot1x_Dep_Guide.html#wp386903"&gt;http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_1.99/Dot1X_Deployment/Dot1x_Dep_Guide.html#wp386903&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This feature is supported by most IP phones -&amp;nbsp; I do not know if Mitel phones support that but we cannot see this message in the debugs you sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround we can configure inactivity timer (by default it is infinity):&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_55_se/commmand/reference/cli1.html#wp11888691"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_55_se/commmand/reference/cli1.html#wp11888691&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This did resolve all our issues, &lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jan 2013 13:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060347#M7466</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2013-01-21T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Hi Aaron, just a quick</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060348#M7467</link>
      <description>&lt;P&gt;Hi Aaron, just a quick question. Was this resolved or are you still using the workaround? We are seeing the same / similar problem.&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 14:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060348#M7467</guid>
      <dc:creator>lewiscf77</dc:creator>
      <dc:date>2015-05-22T14:52:30Z</dc:date>
    </item>
    <item>
      <title>Hi CraigI am afraid I am</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060349#M7468</link>
      <description>&lt;P&gt;Hi Craig&lt;/P&gt;&lt;P&gt;I am afraid I am still using the workaround and have had to on subsequent deployments as well, the limitation is on the Mitel side so until they address the issue it maybe the best option. I came across someone else that had a similar issue on my travels and they addresses it by using error disable recovery. Something like,&lt;STRONG&gt; errdisable recovery cause security-violation &lt;/STRONG&gt;do deal with it, the downside to this is I think the port drops so if you are using a POE handset it will re-boot, but depending on you the size of your organisation this maybe between that a lot of re-auth request.&lt;/P&gt;&lt;P&gt;Anything else on this please just let me know.&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 15:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060349#M7468</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2015-05-22T15:17:18Z</dc:date>
    </item>
    <item>
      <title>Aaron, many thanks for the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060350#M7469</link>
      <description>&lt;P&gt;Aaron, many thanks for the incredibly quick response. We have spent a considerable time looking at this. We had been advised that this issue was resolved with a later phone firmware version. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We will implement the workout, as it sounds like the other one won’t help us as we are running POE switches.&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 15:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060350#M7469</guid>
      <dc:creator>lewiscf77</dc:creator>
      <dc:date>2015-05-22T15:31:55Z</dc:date>
    </item>
    <item>
      <title>No problem at all. I came</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060351#M7470</link>
      <description>&lt;P&gt;No problem at all. I came across this about 3 years ago now and I am sure they said something similar then. I work&amp;nbsp;for a Mitel and Cisco partner so managed to get both involved in the troubleshooting at the time, but have not investigated since. What MCD release are you on? I had loads of other issues on pre MCD 4 as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;I have used the re-auth timer a few times now on separate deployments&amp;nbsp;and never had any issues so for now that's a safe bet&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 16:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060351#M7470</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2015-05-22T16:18:31Z</dc:date>
    </item>
    <item>
      <title>Hi  aaron.tunnicliff :I have</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060352#M7471</link>
      <description>&lt;P&gt;Hi &amp;nbsp;&lt;SPAN class="fullname" style="color: rgb(153, 153, 153);"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A about="/users/aarontunnicliff" class="username" datatype="" href="https://supportforums.cisco.com/users/aarontunnicliff" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;aaron.tunnicliff&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(153, 153, 153);"&gt;&amp;nbsp;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;I have a similiar problem with your, below is the detail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am confused some failure authentication session could not disappeared even this failure MAC address did not find in the MAC address table or it did not connect to the switch. kindly hope you give me some adivise about this issue, thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;I am running Cisco ACS(&amp;nbsp;Version : 5.4.0.46.0a)&amp;nbsp;&amp;nbsp;802.1x with certificate based authentication for Wired connections. the issus is i found some authentication failed messages in some switch port. when I troubleshooting in ACS, it is an error: "22056 Subject not found in the applicable identity store(s). : Authentication failed&amp;nbsp;". but I could not find the MAC address on this port. &amp;nbsp;the authentication failed message should disappeared after 60 seconds normally it the device pull out the cable. but i found the authentication failed session always in the switch and the ACS.&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;for example:&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;in the port Gi1/0/15, there has an Avaya phone and a PC authentication success, but there has another MAC address failed. it was&amp;nbsp;strange the this port did not connect any other device. so i am so confused about this situation. i tried to add one command :"authentication timer inactivity 30", but it seem like no use.&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;switch#show authe se | inc Gi1/0/15&lt;BR /&gt;Gi1/0/15 &amp;nbsp; 90b1.1c9b.d9c4 &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;DATA &amp;nbsp; &amp;nbsp; Authz Success &amp;nbsp;0A19F5820001536935ED8383&lt;BR /&gt;Gi1/0/15 &amp;nbsp; 24d9.214e.39be &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;VOICE &amp;nbsp; &amp;nbsp;Authz Success &amp;nbsp;0A19F5820001452D31ECA0FD&lt;BR /&gt;Gi1/0/15 &amp;nbsp; 8c70.5a29.39be &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;DATA &amp;nbsp; &amp;nbsp; Authz Failed &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0A19F582000150163568626F&lt;BR /&gt;switch#show mac add | inc Gi1/0/15&lt;BR /&gt;&amp;nbsp;100 &amp;nbsp; &amp;nbsp;90b1.1c9b.d9c4 &amp;nbsp; &amp;nbsp;STATIC &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi1/0/15&lt;BR /&gt;&amp;nbsp;300 &amp;nbsp; &amp;nbsp;24d9.214e.39be &amp;nbsp; &amp;nbsp;STATIC &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi1/0/15&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;switch#show run int Gi1/0/15&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;Current configuration : 540 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/15&lt;BR /&gt;&amp;nbsp;switchport access vlan 100&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 300&lt;BR /&gt;&amp;nbsp;duplex full&lt;BR /&gt;&amp;nbsp;authentication event server dead action reinitialize vlan 100&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;&amp;nbsp;authentication timer inactivity 30&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 5.00&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;switch module:&amp;nbsp;WS-C3750X-48PF-S&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;switch IOS:&amp;nbsp;c3750e-universalk9-mz.150-2.SE4.bin&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 09:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060352#M7471</guid>
      <dc:creator>yangsonggui</dc:creator>
      <dc:date>2015-09-02T09:22:37Z</dc:date>
    </item>
    <item>
      <title>HelloThis is my default port</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060353#M7472</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;This is my default port config,&lt;/P&gt;&lt;P&gt;&amp;nbsp;description 802.1x Voice and Data&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 100&lt;BR /&gt;&amp;nbsp;srr-queue bandwidth share 10 10 60 20&lt;BR /&gt;&amp;nbsp;srr-queue bandwidth shape 10 0 0 0&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event fail action authorize vlan 112&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 112&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication timer inactivity 3600&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;auto qos voip trust&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 3&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I notice that you are using Authentication host-mode multi-auth, I would typically use this if I had&amp;nbsp;a L2 switch&amp;nbsp;of a normal switch port&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;multi-auth—&lt;/STRONG&gt;&lt;EM&gt;Multiauthentication allows one authentication on a voice VLAN and multiple authentications on the data VLAN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This does not explain why you are seeing an additional MAC, does it show in the mac address table at all?&lt;/P&gt;&lt;P&gt;Maybe try swapping over to use multi-domain and see if that helps?&lt;/P&gt;&lt;P&gt;I have also ran into many bugs in the past so I would rule that out either..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 09:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060353#M7472</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2015-09-02T09:38:41Z</dc:date>
    </item>
    <item>
      <title>Thanks! Aaron.the additional</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060354#M7473</link>
      <description>&lt;P&gt;Thanks! Aaron.&lt;/P&gt;&lt;P&gt;the additional MAC could not found int the mac address table. and i have check the switch port, it just connect one Avaya phone and the end user laptop, no other device. I monitored the port, it did not have the additional MAC but it suddenly appeared and I have no idear about it. and the most important it this failure authentication session could not clear until I manually "clear authentication session mac x.x.x.x".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 06:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060354#M7473</guid>
      <dc:creator>yangsonggui</dc:creator>
      <dc:date>2015-09-03T06:08:25Z</dc:date>
    </item>
    <item>
      <title>HelloIs this just one phone</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060355#M7474</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Is this just one phone\port in a fully operational deployment or are you still trialling it on a few users?&lt;/P&gt;&lt;P&gt;I think the next thing to do is clear the authentication on this port and unplug both devices. The run, &lt;SPAN style="font-family: courier new,courier,monospace;"&gt;debug authentication all&lt;/SPAN&gt;, reconnect the devices and see if it happens again.&amp;nbsp;Then send post the logs.&lt;/P&gt;&lt;P&gt;Do you see the failed mac address in your ACS logs?&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 08:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060355#M7474</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2015-09-03T08:26:20Z</dc:date>
    </item>
    <item>
      <title>Strange, because I</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060356#M7475</link>
      <description>&lt;P&gt;Strange, because I experienced that as soon as WLAN connection is established, the PC stops running 802.1X on the LAN NIC.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2015 18:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060356#M7475</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2015-09-06T18:58:08Z</dc:date>
    </item>
    <item>
      <title>Hi Aaron:our office have 5</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060357#M7476</link>
      <description>&lt;P&gt;Hi Aaron:&lt;/P&gt;&lt;P&gt;our office have 5 floores in the office building, and we have 4 or 5 switches stacked every floor. and we find several users have this porblem in every floor.&lt;/P&gt;&lt;P&gt;all of the failed mac address in the ACS is the same error message "&lt;SPAN style="font-size: 14.3999996185303px; line-height: normal;"&gt;22056 Subject not found in the applicable identity store(s). : Authentication failed&lt;/SPAN&gt;".&amp;nbsp;&lt;/P&gt;&lt;P&gt;it if difficult for me to debug in the switch.&lt;/P&gt;&lt;P&gt;do you know this command "&lt;SPAN style="color: rgb(0, 0, 0); font-family: 'Courier New', Courier, mono; font-size: 12.8800001144409px; line-height: 18px;"&gt;authentication mac-move permit&lt;/SPAN&gt;"? &amp;nbsp;I am not sure whether this command could fix the problem or not.&lt;/P&gt;&lt;H3 class="p_H_Head2" style="font-size: 12.8800001144409px; color: rgb(51, 102, 102); font-weight: bold; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; line-height: normal;"&gt;Enabling MAC Move&lt;/H3&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274656"&gt;&lt;/A&gt;MAC move allows an authenticated host to move from one port on the switch to another.&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274657"&gt;&lt;/A&gt;Beginning in privileged EXEC mode, follow these steps to globally enable MAC move on the switch. This procedure is optional.&lt;/P&gt;&lt;P class="pTableAnchor" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 2px; margin-right: 0em; margin-bottom: 0px; margin-left: 0em; line-height: normal;"&gt;&lt;A name="pgfId-1328027"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV align="left" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.8800001144409px; line-height: normal;"&gt;&lt;TABLE border="1" bordercolor="#808080" cellpadding="3" cellspacing="0" width="96%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&amp;nbsp;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&lt;DIV class="pCH1_CellHead1" style="color: rgb(51, 102, 102); font-size: 13.5240001678467px; margin: 0em; text-indent: 0em;"&gt;&lt;A name="pgfId-1328035"&gt;&lt;/A&gt;Command&lt;/DIV&gt;&lt;/TH&gt;&lt;TH scope="col" style="font-size: 13.5240001678467px;"&gt;&lt;DIV class="pCH1_CellHead1" style="color: rgb(51, 102, 102); font-size: 13.5240001678467px; margin: 0em; text-indent: 0em;"&gt;&lt;A name="pgfId-1328037"&gt;&lt;/A&gt;Purpose&lt;/DIV&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSF_CellStepFirst" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328039"&gt;&lt;/A&gt;Step 1&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328140"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;configure terminal&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328142"&gt;&lt;/A&gt;Enter global configuration mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328045"&gt;&lt;/A&gt;Step 2&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328144"&gt;&lt;/A&gt;authentication mac-move permit&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328146"&gt;&lt;/A&gt;Enable MAC move on the switch.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328160"&gt;&lt;/A&gt;Step 3&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328166"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;end&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328168"&gt;&lt;/A&gt;Return to privileged EXEC mode.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328154"&gt;&lt;/A&gt;Step 4&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328170"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;show running-config&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328172"&gt;&lt;/A&gt;Verify your entries.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pCSN_CellStepnext" style="font-size: 12.2360000610352px; font-weight: bold; margin: 0em 0em 6px 0.5in; text-indent: -0.4in;"&gt;&lt;A name="pgfId-1328148"&gt;&lt;/A&gt;Step 5&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328178"&gt;&lt;/A&gt;&lt;B class="cBold"&gt;copy running-config startup-config&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1" style="font-size: 12.2360000610352px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A name="pgfId-1328180"&gt;&lt;/A&gt;(Optional) Save your entries in the configuration file.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;&lt;A name="pgfId-1274685"&gt;&lt;/A&gt;This example shows how to globally enable MAC move on a switch:&lt;/P&gt;&lt;DIV class="pEx1_Example1" style="color: rgb(0, 0, 0); font-family: 'Courier New', Courier, mono; margin: 0px 0em; line-height: 18px; font-size: 12.8800001144409px;"&gt;&lt;A name="pgfId-1274686"&gt;&lt;/A&gt;Switch(config)# authentication mac-move permit&lt;/DIV&gt;</description>
      <pubDate>Fri, 18 Sep 2015 09:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060357#M7476</guid>
      <dc:creator>yangsonggui</dc:creator>
      <dc:date>2015-09-18T09:10:43Z</dc:date>
    </item>
    <item>
      <title>HelloYes I do tend to use mac</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060358#M7477</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Yes I do tend to use mac-move permit if laptop users are using wired, in a hot-desking sort of situation it allows a mac address to appear on multiple switch ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the ACS logs, does it tell you what subject is being offered up that is not found?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 09:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-1-802-1x-auth-fails-on-lan-when-wlan-connected/m-p/2060358#M7477</guid>
      <dc:creator>at2885</dc:creator>
      <dc:date>2015-09-18T09:34:38Z</dc:date>
    </item>
  </channel>
</rss>

