I have been struggeling with getting our Juniper IC4500 NAC send VLAN assignments to my Cisco Switches for some time now.
Last night I managed to get the switch to accept VLAN tags for ports with a Cisco Iphone on it and assign it the proper VLAN tag.
Nov 29 11:10:43.306: %MAB-5-SUCCESS: Authentication successful for client (001a.a1d0.46e4) on Interface Fa0/2 AuditSessionID AC1202A00000001102E90153
Nov 29 11:10:43.306: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (001a.a1d0.46e4) on Interface Fa0/2 AuditSessionID AC1202A00000001102E90153
Nov 29 11:10:43.306: %AUTHMGR-5-VLANASSIGN: VLAN 400 assigned to Interface Fa0/2 AuditSessionID AC1202A00000001102E90153
Thats all well and fine.
Next issue. I want to connect a PC behind the IPhone as well.
Strangely this also works, but it assigns the PC the same VLAN as the IPhone.
The solution to get the IPhone VLAN tag working, as far as I can tell, was to complete remove the switchport voice vlan xxx tag from the switch port.
Normally, I'd just use
switchport access vlan xxx
switchport voice vlan xxx
However, with the current setup and the IC4500, it seems I have to remove the voice parameter. I'm rather new to dot1x at root, so this might be a general consenses for all I know.
Anyway, is something switch related I have to consider to get the vlan assigned correctly to the attached PC behind the phone, or is this a phone or radius issue within the IC unit.
Any advice would be greatly appreciated!!
This is my current switchport config, its on a Cisco Cat 3560 using IPSERVICES:
authentication mac-move permi
aaa authentication login default line local
aaa authentication dot1x default group radius
aaa authorization network default group radius
aaa accounting dot1x default start-stop group radius
switchport access vlan 5
switchport mode access
authentication host-mode multi-host
authentication port-control auto
authentication timer reauthenticate server
dot1x pae authenticator
dot1x max-reauth-req 1
Frank James Wilson
Network & Security Bama Gruppen AS