hi , i'm installing ipphone on 3560 with 802.1x authentication and host mode multi-domain ,all works fine for ipphone but PC behind ipphone can't
receive an ip address via dhcp although dot1x guest vlan data is configured, is supplicant and 802.1x authentication mandatory on pc as on ipphone or can i have only authentication on ipphone and none on PC ?
is there some issue known for that situation ?
how long is a mac addres locked if dot1x authen failed ? is that timer configurable ? is the mac address locked for the port or for all switch port ?
The jist of this is, with MDA configured, it will never allow access to anything, unless it sees a client on the wire. Whever you plug it in, it will try to authenticate the device with 802.1X. If 802.1X times out, then fallback options like MAB, the Guest-VLAN come into play.
Can you cut-n-paste your current port-config?
Largely, you should be seeing the same thing with MDA that you'd see when you plug directly into the switch to begin with. Beware that 802.1X takes 90-sec to timeout by default. This could be the issue you're facing here.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :