Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Attention: The Cisco Support Community site will be in read only mode on Dec14, 2017 from 12:01am PST to 11:30am for standard maintenance. Sorry for the inconvenience.

New Member

dot1x with voice vlan

Hi guys,

recently i have configured the dot1x security feature on the cisco c3650x switches with IOS 15.2(1)E. But when I added voice vlan to the port, the ip phone can't register.

My switch port configuration as below:

interface GigabitEthernet0/47

switchport mode access

switchport voice vlan 60

switchport port-security maximum 2

switchport port-security

switchport port-security aging time 1

switchport port-security violation restrict

switchport port-security aging type inactivity

switchport port-security mac-address sticky

srr-queue bandwidth share 10 10 60 20

queue-set 2

priority-queue out

authentication event fail action authorize vlan 203

authentication event no-response action authorize vlan 203

authentication host-mode multi-host

authentication port-control auto

mls qos trust device cisco-phone

mls qos trust cos

macro description USER

dot1x pae authenticator

auto qos voip cisco-phone

spanning-tree portfast

spanning-tree bpduguard enable

service-policy input AutoQoS-Police-CiscoPhone

Guys, please advice is there any other feature shuld be activated on swith to resolve this issue? i done all configuration on guidance of cisco documents.

BR

Rashad

4 REPLIES
VIP Purple

Re: dot1x with voice vlan

At least you have to specify the right host-mode for the switchport:

authentication host-mode multi-domain


And if you are running .1x, you don't need port-security any longer.

You find many information in the "Cisco IOS Quick Reference Guide for IBNS":

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/whitepaper_c27-574041.pdf

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni


--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
New Member

Re: dot1x with voice vlan

I just changed the multi-host mode to multi-domain and removed all port-security features under port. But again the same thing.

BR

Rashad

VIP Purple

Re: dot1x with voice vlan

What do you see on the RADIUS-Server when the phone tries to authenticate?

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni


--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
New Member

Re: dot1x with voice vlan

just nothing.

BR

Rashad

448
Views
0
Helpful
4
Replies
CreatePlease to create content