cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5547
Views
0
Helpful
17
Replies

amber lights after 802.1x but still communicating

Hello,

 

I recently created a network policy server(windows based) to deploy the 802.1x port based authentication. the switches(2960x) configuration was performed to point to the radius server and the dot1x applied per port. The group policy was applied successfully on all pcs. Since then a lot of amber leds appeared on the switch, All ports are connected to cisco phones type 7821 and 7942.however all phones are registered to the CME and all pcs are able to communicate and access the internet.  a " sh int status"  shows all port connected.

 

any clues about the amber lights?

17 Replies 17

Hello,

 

the bug below has been updated 7 days ago, looks like there is a fix in the listed IOS versions:

 

port LED may turn to amber
CSCvj16691
Description
Symptom:
port LED may turn to amber

Conditions:
This issue may be seen after switch reload or after OIR or without any trigger

Workaround:
Switch reload/port shut down and then no shut down/OIR may fix this issue

Further Problem Description:
this issue is not seen 100% and it is cosmetic issue

 

Known Fixed Releases

 

Gibraltar-16.12.1c
Gibraltar-16.12.1s
Fuji-16.9.4
17.3.2a
17.3.2EFT
17.3.2
17.3.1
17.3.1a
17.3.1EFT
17.2.2
17.2.1v
17.2.1
17.2.1a
17.2.1EFT
17.2.1r
17.1.2
17.1.1
17.1.1s
17.1.1a
17.1.1t
16.12.4
16.12.4a
16.12.3s
16.12.3
16.12.3a
16.12.2t
16.12.2
16.12.2s
16.12.2a
16.12.1b
16.12.1c
16.12.1w
16.12.1s
16.12.1t
16.12.1a
16.12.1e
16.12.1z
16.12.1y
16.12.1x
16.12.1d
16.12.1
16.10.3
16.10.2
16.9.6
16.9.5f
16.9.5
16.9.4
16.9.4c
16.6.8
16.6.7
16.6.7a
16.12.5
16.12.5b
16.9.7
16.6.9

cbcalhoun
Level 1
Level 1

I am running 16.6.9 and it still seems to occur.

 

-CC

kefayath
Level 1
Level 1

Hi brother... this amber light is because the the data vlan in STP blocking state i beleive. If you run show spanning-tree int gi */*/*, it will show the vlans in forwarded state. and in your case i beleive it should show only for the voice vlan, and thats y your ip phone traffic is opened and this is because of CDP bypass feature enbaled by default. and this command resove the issue 'authentication control-direction in'.

Review Cisco Networking for a $25 gift card