cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
821
Views
9
Helpful
12
Replies

Port Err-Disable cisco switch usually happens on Dot1x user with ISE

oumodom
Level 1
Level 1

Dear Cisco ISE lover,

I have tried to find out the root cause on port Err-Disable whether it is the link flap or what else once we apply with Dot1x configuration?

Really appreciate for your assistance.  

12 Replies 12

Do you see log about violation?

MHM

Can see only the Err-Disable status.
Don't know which it the root cause. 

Ok' 

Share 

Show authentication session interface x/x detail 

MHM

ammahend
VIP Alumni
VIP Alumni

do you have phone and PC both connected to the port ? try connecting just PC and share your port config and switch log.

-hope this helps-

Yes, we configure multi-auth with phone and pc. 
But for disable error happen only with pc only.

share the port config and switch log, make sure cdp is enabled on the port, this will help VoIP phone to inform it about the dedicated voice VLAN

-hope this helps-

CDP is disable due to security purpose. 

Could you please share the output of the "sh run interface < one of the interfaces where the err-disable happens" for review? you might have switch port security applied to those ports and a violation is triggered when more than a device is connected to the port. If you have switch port security configured on those ports then the recommendation would be to remove it and rely only on dot1x.

We don't have port security applies.

Hi @oumodom ,

 please take a look at Recovery ErrDisable Port State on Cisco IOS Platform.

 

Hope this helps !!!

I will share the status then with above info @Marcelo Morais 

thomas
Cisco Employee
Cisco Employee

See How to Ask The Community for Help to help us help you.