7960 Phones going into Err-disable state with 802.1X

Unanswered Question
Mar 30th, 2007

We have have a few instances of dot1x ports getting a err-disable with the offending mac being the phone MAC. Since the port is in single host mode that is the default behavior. It would appear its something with the phone bleeding packets from the voice VLAN onto the data VLAN untagged. Anyone else seen this and how did it get resolved?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Amit Singh Fri, 03/30/2007 - 06:21

Could you please paste the exact error that you are getting. I would like to see the " show log" from the switch.

-amit singh

miwitte Fri, 03/30/2007 - 06:47

The offending MAC is the phone 0015.c6b7.2fdc

Mar 29 21:15:51 EST: %DOT1X-5-SECURITY_VIOLATION: Security violation on interface GigabitEthernet4/29, New MAC address 0015.c6b7.2fdc is seen on the interface in Single Host mode

Mar 29 21:15:51 EST: %PM-4-ERR_DISABLE: security-violation error detected on Gi4/29, putting Gi4/29 in err-disable state


This Discussion