cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2413
Views
0
Helpful
20
Replies

ISE 1.4 access point mab

adamgibs7
Level 6
Level 6

Dears,

i have access point connected in the network through 4500 switch with power injector the access point which are connected on 4500 are falling in proper authorization policy but the access point which are connected to 3560 switch  with 15.X IOS   i can see the injector mac address falling in the authorization policy and the real access point mac address is not seen in the ISE anywhere and the access point doesnt register to the WLC.

thanks

20 Replies 20

Dear Jan,

once the port is in dot1x configuration it doesn't get an ip address , but when I remove the dot1x configuration it is able to get the ip address.

thanks

Dear Jan,

I have enable dhcp snooping on the switch still I am not able to get the ip address I have verified by removing dot1x configuration from the port and I am able to get the IP address but with dot1x configuration I am not able to get.

thanks

Jack, i was just making sure that there was no problem with multiple devices on the same port, multi-auth and multi-domain is basically only different in the fact the multi-auth can have multiple devices in both voice and data vlans, while multi-domain can have one mac in the data vlan, and one mac in voice vlan

Dear Jan,

here are the attached

Just a note :

You really hould not use port-security on dot1x enabled ports, it's not recommended, and will give you weird issues. You should remove all port-security commands before enabling dot1x.

I agree, port security will not buy you anything but problems and confusion in this case. I would turn it off as well.