cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
899
Views
0
Helpful
3
Replies

Need a solution for cisco dot1x enabled switchport gets disabled when I connect a pc with a polycom ip phone

Kirangeek
Level 1
Level 1

I have no issues when I use only pc in the port, it gets authenticated and works fine.
When I connect a PC via a polycom phone then it gets error disabled.

It will go to error disable only when I connect the (PC and polycom) together & at once I connect to switchport then it goes to error disabled
But if i connect the polycom first to the switchport & let it boot(after getting its config) if I connect the PC it has no issues it works fine.

Authentication is done via the mac address of the work station & polycom phone as you may know it doesnt authenticate.

Problem I see here is my switch is seeing the authentication requests of both the devices from only one vlan and dot1x config is seeing it is wrong & shuttting the port. Is there any solution to avoid the error disable.

I donot want to activate 'multi-host' mode as it accepts more than one device and only authenticates the first device.
I tried 'multi-domain' it didnot work but I can try it once again if any one suggests with some changes.

Switch models getting effected;

2960 : 15.0(1)SE2 Ios Version
3560 : 12.2(55) SE5 Ios Version

Example port configuration:

        

interface FastEthernet0/6
description PC 

switchport access vlan xx
switchport mode access
switchport voice vlan yy
srr-queue bandwidth share 10 10 60 20
srr-queue bandwidth shape 10 0 0 0
priority-queue out
authentication control-direction in
authentication event fail retry 1 action authorize vlan zz
authentication event no-response action authorize vlan aa
authentication port-control auto
mls qos trust dscp
dot1x pae authenticator
dot1x timeout tx-period 1
dot1x max-req 1
storm-control broadcast level 10.00
storm-control action trap
no keepalive
spanning-tree portfast

I am new to the forum so my post may not be perfect, if any information is missing I will provide on request.

3 Replies 3

Kirangeek
Level 1
Level 1

Hi Iam,

Which device you have as Radius server? Is it Cisco ACS? If it is Cisco have you tried setting AV pair to autorize voice device?

Below link may help to set this up.

http://www.cisco.com/en/US/tech/tk389/tk814/technologies_configuration_example09186a00808abf2d.shtml

Regards

Najaf

Hello Najaf,

Thank you very much for the doc.

However in my set up ip phones are not authenticated because these polycom ip phones does not speak dot1x at all. As they donot speak dot1x ip phones will place themselves into a voice vlan after a try to authenticaet. Untill ios is upgraded to new version there were no issues after the upgrade i am seeing these issues.

Review Cisco Networking for a $25 gift card