cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
565
Views
0
Helpful
4
Replies

dot1x and ip phone

Kashish_Patel
Level 2
Level 2

We have dot1x enabled with MDA. Consider this scenario:

Only one Cisco IP phone is connected to the switchport (no PC). And phone fails both dot1x and MAB. Switch will place it in DATA vlan by default. This works as expected....Why doesn't IP phone work while in DATA vlan? It keeps showing "registering", "configuring IP" etc. IP helpers are same for both data and voice vlan.

4 Replies 4

Eduardo Aliaga
Level 4
Level 4

If the phone has passed authentication and authorization succesfully then it's a connectivity issue. The ip phone keeps saying "registering" because it can't reach the Call Manager. Could you please check connectivity ?

Phone has not passed authentication. I am letting it fail intentionally to understand the behavior. It lands in DATA domain and can be seen on switch. But phone shows "registering".

Hello Kashish

If hte phone has failed authentication then the behavior depends on both the switch configuration and the radius configuration.

For example if the switch has "authentication open" in the switchport configuration, then all traffic will be allowed.

If the radius configuration says that a failed authentication is OK then all traffic will be allowed, if the radius configuration says that a failed authentication is not OK it can deny all traffic.

what radius server are you using ? what is your switch configuration ?

dynamitec1
Level 1
Level 1

Kashish,

Pretty sure you meant MDA puts it on either on DATA or VOICE "domain."

You have to create a RULE in your RADIUS server that places VOIP phones into VOICE domain.

If you look at topics I responded to, you will see what I have gone through.



Sent from Cisco Technical Support iPhone App

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: