Hi,
MDA requires that the device behind the phone successfully authenticate to gain access to the network. Because the data device is not directly connected to the switch, the switch cannot rely on link state to know when to start authenticating the data device. Therefore, the switch waits until it detects traffic from the second device (such as an EAPoL-Start from an IEEE 802.1X supplicant or DHCP or ARP traffic from a non-IEEE-802.1X-capable device), at which point it sends a unicast EAPoL Request packet to the device to initiate the authentication.
If the data device is not ready to or not capable of performing IEEE 802.lX, the switch will time out and continue to the next authentication method (e.g. MAB) and/or authorization type (e.g. Guest VLAN). If the device later becomes capable of performing IEEE 802.1X (e.g. because the operating system finished booting or a supplicant was manually enabled), then the data device should send an EAPoL-Start message to explicitly tell the switch to begin authentication.
Keep this document handy, will answer all your queries.
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-605524.html#wp9000518
Regards
Gagan
rate if it helps!!!!