Cisco Support Community
Community Member

802.1x, MAC addresses with status DROP

Hi all,

we have rolled out 802.1x enterprise-wide. RADIUS-servers are ACS 1121 ( Currently we are rolling-out Win7-clients.

The access-layer is built on Catalyst 3560g-48-poe, (IOS 12.2(53)SE2).

On certain switches we have the problen (only Win7-clients; XPs do not cause it) that client MAC-addresses are registered in VLAN4 (Data-VLAN) as well as in VLAN 996 (Quarantine-VLAN)  according to the screen-shot below:

switch#sh mac- int gi0/27

Mac Address Table


Vlan Mac Address    Type         Ports

------ -------------------     -------         -------

4     2c27.d71d.6279 STATIC     Drop

996 2c27.d71d.6279 DYNAMIC Gi0/27

Total Mac Addresses for this criterion: 2

Unfortunately the MAC address in VLAN 4 will never age-out, which means that they keep the above status. To wipe-out the MAC addresses we have to reboot the switch, which is no solution for us.

Has anyone faced something similar to this problem ? What is causing this problem ? How can we get rid of these MAC addresses without rebooting the switch ?

Any hints are very much appreciated

Best regards




Cisco Employee

Did you ever get this

Did you ever get this resolved?

Community Member

Hi Neno,This has been

Hi Neno,

This has been resolved by upgrading the switches to the newest release.

Cisco Employee

Thanks for the reply! Can you

Thanks for the reply! Can you give me the specific version. I am dealing with an issue now and running 150-2.SE6. It is not exactly the latest but pretty recent and I want to confirm 100% before I request a change control window for the upgrade.


Community Member

Hi Neno and rhub. 

Hi Neno and rhub. 

I'm dealing with the same issue running c2960-lanlitek9-mz.150-2.SE5, could you give please more info about your advance in this topic, maybe if you have get some documentation about it, it would be really useful for me.

Best Regards.

Juan Esteban  

Cisco Employee

It looked like this was a bug

It looked like this was a bug with the version of code. So I would suggest upgrading your code. Also, please note that LAN Lite is does not support many 802.1x features. 

Thank you for rating helpful posts!

Community Member

Hi Juan and Neno,

Hi Juan and Neno,

we upgraded all 3560-switches with IOS 15.0.2. but I did not have the possibility to test it; I will do it asap and let you know abut the results.

Best regards


Cisco Employee

Sounds good! Let us know :)

Sounds good! Let us know :)

CreatePlease to create content