cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4480
Views
10
Helpful
3
Replies

Access-session Template Monitor Command and IP Device Tracking

Alex Pfeil
Level 7
Level 7

I am deploying 802.1x and the command access-session template monitor was in a best practices configuration I came across.  I placed this command on a C3560CX 8 port switch and it caused the switch to turn on IP Device Tracking on the trunk port immediately.  A show ip device tracking before entering the access-session template monitor command, showed a couple of devices. Afterwards, the show ip device tracking command displayed hundreds within seconds. Has anybody ran across this? Can anybody explain this? 

I entered commands in 1 at a time and ran the show ip device tracking all command after each one so I know that command caused the issue.  I can even remove that command, and the show ip device tracking all removes all of the entries immediately.

I look forward to any response.

Please rate helpful posts.

 

1 Accepted Solution

Accepted Solutions

Hi.


device tracking is required for dot1x to work especially with dacls. If you
have it enabled on trunk then there are many devices behind the trunk which
are learnt through device tracking.

View solution in original post

3 Replies 3

ognyan.totev
Level 5
Level 5

Hi, in some of guides there was best practice command on trunk port:

ip device tracking maximum 0 

Hi.


device tracking is required for dot1x to work especially with dacls. If you
have it enabled on trunk then there are many devices behind the trunk which
are learnt through device tracking.

Oron Yaniv
Level 1
Level 1

a little bit late, but i hope it will help. i am using a template and enroll it on the uplink interface (9400 Switches)

the "device-role switch" cut all MAC addresses on the 

 

!

device-tracking policy device_tracking_uplink
trusted-port
device-role switch
no protocol udp
!

 

Good Luck