<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error disable ports with cisco phone and computer daisy chained together in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485346#M86640</link>
    <description>&lt;P&gt;I have a WS-C2960S-48FPS-L stack running software version&amp;nbsp; 15.0(2)SE2&amp;nbsp; , I keep getting intermittent error disable on some&lt;/P&gt;&lt;P&gt;ports after configuring 802.1x on the ports&lt;/P&gt;&lt;P&gt;Port config&lt;/P&gt;&lt;P&gt;interface GigabitEthernet3/0/37&lt;BR /&gt;&amp;nbsp;switchport access vlan 101&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 11&lt;BR /&gt;&amp;nbsp;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 101&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 963&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;mls qos trust device cisco-phone&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout supp-timeout 3&lt;BR /&gt;&amp;nbsp;auto qos voip cisco-phone&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;/P&gt;&lt;P&gt;syslog server output .&lt;/P&gt;&lt;P&gt;Apr 15 07:38:45 10.42.245.5 5057: .Apr 15 12:38:32.441: %LINEPROTO-5-UPDOWN: Line protocol on Interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, changed state to down&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;153 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5056: Apr 15 12:38:31.418: %PM-4-ERR_DISABLE: security-violation error detected on Gi3/0/37,&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;putting Gi3/0/37 in err-disable state (CPAHP-CR-STK1-3)&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;154 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5055: .Apr 15 12:38:31.419: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, new MAC address (d4be.d92d.2363) is seen.AuditSessionID&amp;nbsp; Unassigned&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options ( mac address from phone on data)&lt;BR /&gt;155 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5054: .Apr 15 12:38:31.377: %AUTHMGR-5-START: Starting 'dot1x' for client (d4d7.48ff.e809) on&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Interface Gi3/0/37 AuditSessionID 0A2AF505000008E5648AEE19&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;156 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5053: .Apr 15 12:38:31.361: %SWITCH_QOS_TB-5-TRUST_DEVICE_DETECTED: cisco-phone detected on&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;port Gi3/0/37, port's configured trust state is now operational.&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;157 » 4/15/14&lt;BR /&gt;7:38:31.000 AM&lt;BR /&gt;Apr 15 07:38:31 10.42.245.5 5052: .Apr 15 12:38:20.031: %LINEPROTO-5-UPDOWN: Line protocol on Interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, changed state to up&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;158 » 4/15/14&lt;BR /&gt;7:38:31.000 AM&lt;BR /&gt;Apr 15 07:38:31 10.42.245.5 5051: .Apr 15 12:38:19.030: %LINK-3-UPDOWN: Interface GigabitEthernet3/0/37, changed state to&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;up&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;I am using Cisco 4945 IP phones at this site, at another site running the same phones the same IOS and the same mod switch&lt;/P&gt;&lt;P&gt;with the configs I am not experiencing any issues.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;At both site computers are daisy chained through the phone. I see the phone is trusted first so it would be sending tagged&lt;/P&gt;&lt;P&gt;packets the switch trying to authenticate the computer picks up both mac address and going into error disable. if I shut&lt;/P&gt;&lt;P&gt;and no shut the port it clears and only show the 2 mac addresses phone and compute .&lt;BR /&gt;Any input would be greatly appreciated.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:38:23 GMT</pubDate>
    <dc:creator>John Coccioletti</dc:creator>
    <dc:date>2019-03-11T04:38:23Z</dc:date>
    <item>
      <title>Error disable ports with cisco phone and computer daisy chained together</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485346#M86640</link>
      <description>&lt;P&gt;I have a WS-C2960S-48FPS-L stack running software version&amp;nbsp; 15.0(2)SE2&amp;nbsp; , I keep getting intermittent error disable on some&lt;/P&gt;&lt;P&gt;ports after configuring 802.1x on the ports&lt;/P&gt;&lt;P&gt;Port config&lt;/P&gt;&lt;P&gt;interface GigabitEthernet3/0/37&lt;BR /&gt;&amp;nbsp;switchport access vlan 101&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 11&lt;BR /&gt;&amp;nbsp;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 101&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 963&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;mls qos trust device cisco-phone&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout supp-timeout 3&lt;BR /&gt;&amp;nbsp;auto qos voip cisco-phone&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;/P&gt;&lt;P&gt;syslog server output .&lt;/P&gt;&lt;P&gt;Apr 15 07:38:45 10.42.245.5 5057: .Apr 15 12:38:32.441: %LINEPROTO-5-UPDOWN: Line protocol on Interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, changed state to down&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;153 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5056: Apr 15 12:38:31.418: %PM-4-ERR_DISABLE: security-violation error detected on Gi3/0/37,&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;putting Gi3/0/37 in err-disable state (CPAHP-CR-STK1-3)&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;154 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5055: .Apr 15 12:38:31.419: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, new MAC address (d4be.d92d.2363) is seen.AuditSessionID&amp;nbsp; Unassigned&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options ( mac address from phone on data)&lt;BR /&gt;155 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5054: .Apr 15 12:38:31.377: %AUTHMGR-5-START: Starting 'dot1x' for client (d4d7.48ff.e809) on&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Interface Gi3/0/37 AuditSessionID 0A2AF505000008E5648AEE19&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;156 » 4/15/14&lt;BR /&gt;7:38:44.000 AM&lt;BR /&gt;Apr 15 07:38:44 10.42.245.5 5053: .Apr 15 12:38:31.361: %SWITCH_QOS_TB-5-TRUST_DEVICE_DETECTED: cisco-phone detected on&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;port Gi3/0/37, port's configured trust state is now operational.&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;157 » 4/15/14&lt;BR /&gt;7:38:31.000 AM&lt;BR /&gt;Apr 15 07:38:31 10.42.245.5 5052: .Apr 15 12:38:20.031: %LINEPROTO-5-UPDOWN: Line protocol on Interface&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;GigabitEthernet3/0/37, changed state to up&lt;BR /&gt;host=10.42.245.5&amp;nbsp;&amp;nbsp; Options|&amp;nbsp; sourcetype=cisco_router&amp;nbsp;&amp;nbsp; Options| &amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;source=/opt/splunk/spool/cisco_router/10.42.245.5/syslog.log&amp;nbsp;&amp;nbsp; Options&lt;BR /&gt;158 » 4/15/14&lt;BR /&gt;7:38:31.000 AM&lt;BR /&gt;Apr 15 07:38:31 10.42.245.5 5051: .Apr 15 12:38:19.030: %LINK-3-UPDOWN: Interface GigabitEthernet3/0/37, changed state to&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;up&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;I am using Cisco 4945 IP phones at this site, at another site running the same phones the same IOS and the same mod switch&lt;/P&gt;&lt;P&gt;with the configs I am not experiencing any issues.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;At both site computers are daisy chained through the phone. I see the phone is trusted first so it would be sending tagged&lt;/P&gt;&lt;P&gt;packets the switch trying to authenticate the computer picks up both mac address and going into error disable. if I shut&lt;/P&gt;&lt;P&gt;and no shut the port it clears and only show the 2 mac addresses phone and compute .&lt;BR /&gt;Any input would be greatly appreciated.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485346#M86640</guid>
      <dc:creator>John Coccioletti</dc:creator>
      <dc:date>2019-03-11T04:38:23Z</dc:date>
    </item>
    <item>
      <title>HelloIs it possible that your</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485347#M86649</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;Is it possible that your users are unpatching PC's from the phones and moving them to other phones?&lt;/P&gt;&lt;P&gt;If so, the "Cisco Discovery Protocol Enhancement for Second Port Disconnect" should inform the upstream switch. This enhancement is supported in certain phone firmwares and switch ios - see below link&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html#pgfId-389517"&gt;http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html#pgfId-389517&lt;/A&gt;&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 20:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485347#M86649</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2014-04-15T20:51:05Z</dc:date>
    </item>
    <item>
      <title>No they all employees have </title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485348#M86656</link>
      <description>&lt;P&gt;No they all employees have&amp;nbsp; assigned seating. This problem actually appeared when I first&amp;nbsp; NAC ed the switchports.&lt;/P&gt;&lt;P&gt;It came up error disabled. I did a mac address look-up on the port and&amp;nbsp; notice that the mac address of the phone was appearing in both the voice and data vlans , 3 mac address on the port which is most likely causing the issue. I checked Cisco and I found there was a firmware issue with an different phone module , not this mod. 7945. I checked the other site were there isn't any issues and all the phone parameters match exactly.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 21:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485348#M86656</guid>
      <dc:creator>John Coccioletti</dc:creator>
      <dc:date>2014-04-15T21:01:27Z</dc:date>
    </item>
    <item>
      <title>Hi,you need to configure</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485349#M86666</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you need to configure:&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain (1 PC + 1 IP-PHONE)&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain (many PCs + 1 IP-Phone )&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard Horst&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 09:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485349#M86666</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-04-16T09:35:59Z</dc:date>
    </item>
    <item>
      <title>Thank you so much I will try</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485350#M86671</link>
      <description>&lt;P&gt;Thank you so much I will try it, I really do appreciate the help.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 12:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485350#M86671</guid>
      <dc:creator>John Coccioletti</dc:creator>
      <dc:date>2014-04-16T12:28:19Z</dc:date>
    </item>
    <item>
      <title>.don´t forget to send the</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485351#M86677</link>
      <description>&lt;P&gt;.don´t forget to send the cisco-av-pair&amp;nbsp; "device-traffic-class=voice" from Radius to the switch.&lt;/P&gt;&lt;P&gt;If you´re using ACS...&lt;/P&gt;&lt;FIELDSET class="cuesGroupBox"&gt;&lt;TABLE border="0" height="24" width="7"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;TABLE border="0" cellspacing="0" class="cuesBreadcrumbTable" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD nowrap="nowrap"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Policy Elements &lt;/SPAN&gt;&amp;gt;&lt;/TD&gt;&lt;TD class="cuesBreadcrumbMore" nowrap="nowrap" style="DISPLAY: none"&gt;... &amp;gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" title="Authorization and Permissions "&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Authorization and Permissions &lt;/SPAN&gt; &amp;gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" title="Network Access"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Network Access&lt;/SPAN&gt; &amp;gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" title="Authorization Profiles"&gt;&lt;A class="cuesBreadcrumbLink"&gt;Authorization Profiles&lt;/A&gt; &amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD id="staticProxyAclValue" style="DISPLAY: none"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Value&lt;/TD&gt;&lt;TD width="10"&gt;&lt;DIV class="cuesRequiredField"&gt;&lt;IMG alt="Erforderliches Feld" src="https://community.cisco.com/acsadmin/cues_images/RequiredFieldT.gif" title="Erforderliches Feld" /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cuesErrorText" id="proxyAclValue_err" style="DISPLAY: none"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;TEXTAREA cols="57" disabled="disabled" name="proxyAclValue" rows="4"&gt;&lt;/TEXTAREA&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD id="dynamicProxyAclValue" style="DISPLAY: none"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SELECT disabled="disabled" id="dynamicProxyAclDictionary" name="dynamicProxyAclDictionary" style="WIDTH: 180px"&gt;&lt;OPTION selected="selected" value="AD-AD1"&gt;AD-AD1&lt;/OPTION&gt;&lt;OPTION value="InternalHosts"&gt;Internal Hosts&lt;/OPTION&gt;&lt;OPTION value="InternalUsers"&gt;Internal Users&lt;/OPTION&gt;&lt;OPTION value="LDAP-NACProfiler"&gt;LDAP-NAC Profiler&lt;/OPTION&gt;&lt;/SELECT&gt;&lt;/TD&gt;&lt;TD width="10"&gt;&lt;DIV class="cuesRequiredField"&gt;&lt;IMG alt="Erforderliches Feld" src="https://community.cisco.com/acsadmin/cues_images/RequiredFieldT.gif" title="Erforderliches Feld" /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cuesErrorText" id="AD-AD1ProxyAclComponentId_err" style="DISPLAY: none"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV id="AD-AD1ProxyAclDivSelector" style="DISPLAY: none"&gt;&lt;INPUT id="AD-AD1attributeId" name="AD-AD1attributeId" type="hidden" /&gt;&lt;DIV id="AD-AD1ProxyAclSelectorContainer" style="MARGIN: 0px"&gt;&lt;INPUT disabled="disabled" id="AD-AD1ProxyAclComponentId" name="AD-AD1ProxyAclComponentId" readonly="readonly" style="WIDTH: 200px" /&gt;&lt;INPUT id="AD-AD1ProxyAclSelectorId" name="AD-AD1ProxyAclSelectorId" type="hidden" /&gt;&lt;INPUT id="AD-AD1ProxyAclSelectorChanged" name="AD-AD1ProxyAclSelectorChanged" type="hidden" /&gt; &lt;INPUT disabled="disabled" id="AD-AD1ProxyAclSelectorButton" type="button" value="Select" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cuesErrorText" id="InternalHostsProxyAclComponentId_err" style="DISPLAY: none"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV id="InternalHostsProxyAclDivSelector" style="DISPLAY: none"&gt;&lt;INPUT id="InternalHostsattributeId" name="InternalHostsattributeId" type="hidden" /&gt;&lt;DIV id="InternalHostsProxyAclSelectorContainer" style="MARGIN: 0px"&gt;&lt;INPUT disabled="disabled" id="InternalHostsProxyAclComponentId" name="InternalHostsProxyAclComponentId" readonly="readonly" style="WIDTH: 200px" /&gt;&lt;INPUT id="InternalHostsProxyAclSelectorId" name="InternalHostsProxyAclSelectorId" type="hidden" /&gt;&lt;INPUT id="InternalHostsProxyAclSelectorChanged" name="InternalHostsProxyAclSelectorChanged" type="hidden" /&gt; &lt;INPUT disabled="disabled" id="InternalHostsProxyAclSelectorButton" type="button" value="Select" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cuesErrorText" id="InternalUsersProxyAclComponentId_err" style="DISPLAY: none"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV id="InternalUsersProxyAclDivSelector" style="DISPLAY: none"&gt;&lt;INPUT id="InternalUsersattributeId" name="InternalUsersattributeId" type="hidden" /&gt;&lt;DIV id="InternalUsersProxyAclSelectorContainer" style="MARGIN: 0px"&gt;&lt;INPUT disabled="disabled" id="InternalUsersProxyAclComponentId" name="InternalUsersProxyAclComponentId" readonly="readonly" style="WIDTH: 200px" /&gt;&lt;INPUT id="InternalUsersProxyAclSelectorId" name="InternalUsersProxyAclSelectorId" type="hidden" /&gt;&lt;INPUT id="InternalUsersProxyAclSelectorChanged" name="InternalUsersProxyAclSelectorChanged" type="hidden" /&gt; &lt;INPUT disabled="disabled" id="InternalUsersProxyAclSelectorButton" type="button" value="Select" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cuesErrorText" id="LDAP-NACProfilerProxyAclComponentId_err" style="DISPLAY: none"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV id="LDAP-NACProfilerProxyAclDivSelector" style="DISPLAY: none"&gt;&lt;INPUT id="LDAP-NACProfilerattributeId" name="LDAP-NACProfilerattributeId" type="hidden" /&gt;&lt;DIV id="LDAP-NACProfilerProxyAclSelectorContainer" style="MARGIN: 0px"&gt;&lt;INPUT disabled="disabled" id="LDAP-NACProfilerProxyAclComponentId" name="LDAP-NACProfilerProxyAclComponentId" readonly="readonly" style="WIDTH: 200px" /&gt;&lt;INPUT id="LDAP-NACProfilerProxyAclSelectorId" name="LDAP-NACProfilerProxyAclSelectorId" type="hidden" /&gt;&lt;INPUT id="LDAP-NACProfilerProxyAclSelectorChanged" name="LDAP-NACProfilerProxyAclSelectorChanged" type="hidden" /&gt; &lt;INPUT disabled="disabled" id="LDAP-NACProfilerProxyAclSelectorButton" type="button" value="Select" /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/FIELDSET&gt;&lt;FIELDSET class="cuesGroupBox"&gt;&lt;LEGEND class="cuesGroupBoxTitle"&gt;Voice VLAN&lt;/LEGEND&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV name="message" style="WIDTH: 146px"&gt;Permission to Join:&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SELECT id="voiceVlan" name="voiceVlan" style="WIDTH: 100px"&gt;&lt;OPTION value="Not in Use"&gt;Not in Use&lt;/OPTION&gt;&lt;OPTION selected="selected" value="STATIC"&gt;Static&lt;/OPTION&gt;&lt;/SELECT&gt;&lt;/TD&gt;&lt;TD id="staticVoiceVlanValue" style="DISPLAY: block"&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Yes (device-traffic-class=voice)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/FIELDSET&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485351#M86677</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-04-16T13:12:52Z</dc:date>
    </item>
    <item>
      <title>ACS is good we have hundred</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485352#M86683</link>
      <description>&lt;P&gt;ACS is good we have hundred of switches with the same policy no issues. I tried adding the commands to the switch port .Also&amp;nbsp; if I make changes to the ACS policy it will effect the enterprise.&lt;/P&gt;&lt;P&gt;added to switch port :&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;port went into error disable - I could not clear it&lt;/P&gt;&lt;P&gt;&amp;nbsp;11&amp;nbsp;&amp;nbsp;&amp;nbsp; 203a.xxxx.xxxx &amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi2/0/31&amp;nbsp;&amp;nbsp;&amp;nbsp; cisco&amp;nbsp; phone&lt;BR /&gt;&amp;nbsp;101&amp;nbsp;&amp;nbsp;&amp;nbsp; 1803.xxxx.xxxx &amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi2/0/31 computer&lt;BR /&gt;&amp;nbsp;101&amp;nbsp;&amp;nbsp;&amp;nbsp; 203a.xxxx.xxxx &amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi2/0/31&amp;nbsp; cisco phone&lt;/P&gt;&lt;P&gt;Very Respectfully&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 15:30:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485352#M86683</guid>
      <dc:creator>John Coccioletti</dc:creator>
      <dc:date>2014-04-16T15:30:00Z</dc:date>
    </item>
    <item>
      <title>What happens when you1. only</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485353#M86687</link>
      <description>&lt;P&gt;What happens when you&lt;/P&gt;&lt;P&gt;1. only connect the IP-Phone. Is the Phone in the voice vlan?&lt;/P&gt;&lt;P&gt;Verify with "Show authentication session "&lt;/P&gt;&lt;P&gt;2. Disconnect the Phone and connect the PC&lt;/P&gt;&lt;P&gt;Is the PC in the Data VLAN&lt;/P&gt;&lt;P&gt;How do you authenticate the IP-Phone (MAC-ADDRESS or USER/PASSWORD) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Horst&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 16:30:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485353#M86687</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-04-16T16:30:15Z</dc:date>
    </item>
    <item>
      <title>phone is authenticated</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485354#M86690</link>
      <description>&lt;P&gt;phone is authenticated through mac address&amp;nbsp; and is in the voice Vlan&amp;nbsp; 11&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;BR /&gt;&amp;nbsp; 11&amp;nbsp;&amp;nbsp;&amp;nbsp; 20bb.xxxx.xxxx &amp;nbsp;&amp;nbsp; STATIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi2/0/35 Cisco phone 7945&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Total Mac Addresses for this criterion: 1&lt;BR /&gt;CPAHP-CR-STK2#sh run int Gi2/0/35&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 661 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2/0/35&lt;BR /&gt;&amp;nbsp;switchport access vlan 101&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 11&lt;BR /&gt;&amp;nbsp;power inline auto max 15400&lt;BR /&gt;&amp;nbsp;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 101&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 963&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;mls qos trust device cisco-phone&lt;BR /&gt;&amp;nbsp;mls qos trust cos&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout supp-timeout 3&lt;BR /&gt;&amp;nbsp;auto qos voip cisco-phone&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;====================================&lt;/P&gt;&lt;P&gt;computer authenticates in data Vlan 101 which is correct&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 17:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485354#M86690</guid>
      <dc:creator>John Coccioletti</dc:creator>
      <dc:date>2014-04-16T17:34:52Z</dc:date>
    </item>
    <item>
      <title>is this output a "Show vlan" </title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485355#M86692</link>
      <description>&lt;P&gt;is this output a "Show vlan"&amp;nbsp; or the result of "Show authentication session" ?&lt;/P&gt;&lt;P&gt;Very helpful is a "debug radius" . Can you post both Outputs?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 16:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485355#M86692</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-04-17T16:12:50Z</dc:date>
    </item>
    <item>
      <title>Hi anthonny225, I have</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485356#M86694</link>
      <description>&lt;P&gt;Hi anthonny225,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have experienced an issue like yours.&lt;/P&gt;&lt;P&gt;The interface was entering into err-disabled status as i connected the phone at this interface.&lt;/P&gt;&lt;P&gt;I have tried a lot to solve this issue but i didnt have success.&lt;/P&gt;&lt;P&gt;You can try to change the IOS version, that was the way i solve my problem. I was having problems using IOS 15.2(2)E1. Changing to the 15.0(2)SE7, wich is a MD version,&amp;nbsp;my problem was solved.&lt;/P&gt;&lt;P&gt;I hope it can help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2014 14:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/2485356#M86694</guid>
      <dc:creator>Bruno Siqueira</dc:creator>
      <dc:date>2014-12-22T14:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error disable ports with cisco phone and computer daisy chained together</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/3338808#M86695</link>
      <description>&lt;P&gt;Hi...Any Luck in Solving such issues As i am suffering from a very Similar one&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Below is the&amp;nbsp;associated discussion&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;************************&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/t5/lan-switching-and-routing/catalyst-45-series-sup8e-802-1x-ports-getting-error-disabled/m-p/3338773#M406548" target="_blank"&gt;https://supportforums.cisco.com/t5/lan-switching-and-routing/catalyst-45-series-sup8e-802-1x-ports-getting-error-disabled/m-p/3338773#M406548&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;***************************&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bregards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 15:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/3338808#M86695</guid>
      <dc:creator>MEB</dc:creator>
      <dc:date>2018-02-27T15:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: phone is authenticated</title>
      <link>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/3338903#M86696</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you please add &lt;STRONG&gt;authentication violation replace&lt;/STRONG&gt; on switchport and test? &lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Usually when a phone is brought online, its MAC will be placed in data VLAN and after that it will be both in data and voice VLAN.&lt;/P&gt;
&lt;P&gt;This command will replace the phone's MAC (from data VLAN) with the MAC address of the PC.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 16:34:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/error-disable-ports-with-cisco-phone-and-computer-daisy-chained/m-p/3338903#M86696</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2018-02-27T16:34:06Z</dc:date>
    </item>
  </channel>
</rss>

