01-25-2020 10:45 PM
Hi All,
We are using ISE v2.2 for radius authentication of endpoints. Everything is working fine. Except in one Switch where Cisco VOIP 3905 is used. These devices are not authenticating with ISE and taking the Data domain instead of voice. By statically adding the VOIP mac in the IP-Phone group in ISE, It is working fine. Kindly help on this.
01-26-2020 01:03 AM - edited 01-26-2020 01:04 AM
Hi,
On the switch access port which is connected to phoneport, what authentication mode you are using ? The recomended mode to use phone and data together in same port is multi-domain.
Interface gi0/x
Authentication host-mode multi-domain
Multi-domain—While in this mode, the authenticator will allow one host from the data domain and one from the voice domain; this is a typical configuration on switchports with IP phones connected.
01-26-2020 09:03 PM
A few things to check.
Is the phone showing up in the cdp neighbors?
Are you using the radius device sensor for profiling?
Are the correct profiling attributes showing up in the device sensor cache?
01-27-2020 09:02 AM
@IMG USA wrote:
Hi All,
We are using ISE v2.2 for radius authentication of endpoints. Everything is working fine. Except in one Switch where Cisco VOIP 3905 is used. These devices are not authenticating with ISE and taking the Data domain instead of voice. By statically adding the VOIP mac in the IP-Phone group in ISE, It is working fine. Kindly help on this.
Did you check the prescriptive wired guide
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide