12-15-2024 11:46 PM
Dear Cisco ISE lover,
I have tried to find out the root cause on port Err-Disable whether it is the link flap or what else once we apply with Dot1x configuration?
Really appreciate for your assistance.
12-15-2024 11:53 PM
Do you see log about violation?
MHM
12-16-2024 01:45 AM
Can see only the Err-Disable status.
Don't know which it the root cause.
12-16-2024 02:00 AM
Ok'
Share
Show authentication session interface x/x detail
MHM
12-16-2024 01:15 AM
do you have phone and PC both connected to the port ? try connecting just PC and share your port config and switch log.
12-16-2024 01:46 AM - edited 12-16-2024 01:47 AM
Yes, we configure multi-auth with phone and pc.
But for disable error happen only with pc only.
12-16-2024 01:54 AM
share the port config and switch log, make sure cdp is enabled on the port, this will help VoIP phone to inform it about the dedicated voice VLAN
12-16-2024 02:41 AM
CDP is disable due to security purpose.
12-16-2024 03:51 AM
Could you please share the output of the "sh run interface < one of the interfaces where the err-disable happens" for review? you might have switch port security applied to those ports and a violation is triggered when more than a device is connected to the port. If you have switch port security configured on those ports then the recommendation would be to remove it and rely only on dot1x.
12-16-2024 06:16 PM
We don't have port security applies.
12-16-2024 04:57 AM
Hi @oumodom ,
please take a look at Recovery ErrDisable Port State on Cisco IOS Platform.
Hope this helps !!!
12-16-2024 07:15 PM
I will share the status then with above info @Marcelo Morais
12-16-2024 08:08 AM
See How to Ask The Community for Help to help us help you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide