<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ICX 6430 Mac-Auth / Dot1x Issues /  SW: Version 08.0.30uT311 in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-6430-Mac-Auth-Dot1x-Issues-SW-Version-08-0-30uT311/m-p/48004#M3642</link>
    <description>&lt;P&gt;Hi, i'm trying to configure a switch to work with Dot1x and Mac-authentication, on the same interface.&lt;/P&gt;&lt;P&gt;But i've been having an issue, it only works half way!&lt;/P&gt;&lt;P&gt;Currently, most our users are connected behind a Sangoma S500 IP Phone. And everything works fine (phone calls &amp;amp; data).&lt;/P&gt;&lt;P&gt;But we'd like to make our infrastructure more secure, and prevent anyone to just plug their equipment into our network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Up until now, what we have done is configure a printer radius profile, and a Sangoma radius profile, with MAC authentication (login/password is the MAC of the printer/Phone), and corresponding vlans in the radius profiles, 113-printers, 99-phones, 120-userdata.&lt;/P&gt;&lt;P&gt;On the switch, we've activated Mac-authentication on the port the printer is connected to, and it works fine&lt;/P&gt;&lt;P&gt;Here's the issue. When Mac-authentication &amp;amp; Dot1x is activated on the same interface, and a sangoma phone is connected to it, with a laptop connected to the sangoma; the laptop gets authenticated with Dot1x and put into the corresponding vlan 120.&lt;/P&gt;&lt;P&gt;The Sangoma phone gets put in vlan 99, which is the correct vlan. But we can't actually make calls. somehow, the voice traffic is stopped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's more, when we deactivate "no dot1x port-control auto" on the interface, the laptop loses its authentication, but the phone can make calls.&lt;/P&gt;&lt;P&gt;We need both the laptop and the phone to work together, as they did when mac-auth &amp;amp; dot1x was not activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not familiar with that technology, so i'm sure the problem must be between the seat and the keyboard ^^&lt;/P&gt;&lt;P&gt;Do you guys have any thoughts on what's going on ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll add that, although Sangoma phones have the capacity to do Dot1x by adding a login/password in the settings, we just would like to authenticate them via MAC, for practical reasons, and do everything remotely from the radius and switches.&lt;/P&gt;&lt;P&gt;But again, i'm not familiar with this technology, so i'm not sure what are the dos and donts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below, you will find the current conf on our test switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current configuration:&lt;BR /&gt;!&lt;BR /&gt;ver 08.0.30uT311&lt;BR /&gt;!&lt;BR /&gt;stack unit 1&lt;BR /&gt;module 1 icx6430-24-port-management-module&lt;BR /&gt;module 2 icx6430-sfp-4port-4g-module&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR /&gt;!&lt;BR /&gt;vlan 2 by port&lt;BR /&gt;!&lt;BR /&gt;vlan 99 name TELEPHONIE by port&lt;BR /&gt;tagged ethe 1/1/2 ethe 1/1/4 to 1/1/5 ethe 1/1/11 to 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 112 name MANAGEMENT by port&lt;BR /&gt;tagged ethe 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 113 name PRINTERS by port&lt;BR /&gt;!&lt;BR /&gt;vlan 120 name STAFF by port&lt;BR /&gt;tagged ethe 1/1/2 ethe 1/1/10 ethe 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 401 name STUDENTS by port&lt;BR /&gt;tagged ethe 1/1/11 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 666 name VLAN666 by port&lt;BR /&gt;untagged ethe 1/1/3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;authentication&lt;BR /&gt;auth-order mac-auth dot1x&lt;BR /&gt;auth-default-vlan 666&lt;BR /&gt;restricted-vlan 401&lt;BR /&gt;auth-fail-action restricted-vlan&lt;BR /&gt;no filter-strict-security enable&lt;BR /&gt;re-authentication&lt;BR /&gt;dot1x enable&lt;BR /&gt;dot1x enable ethe 1/1/4 to 1/1/5 ethe 1/1/10 to 1/1/11&lt;BR /&gt;dot1x guest-vlan 401&lt;BR /&gt;mac-authentication enable&lt;BR /&gt;mac-authentication enable ethe 1/1/4 to 1/1/5 ethe 1/1/7&lt;BR /&gt;mac-authentication dot1x-override&lt;BR /&gt;!&lt;BR /&gt;aaa authentication web-server default local&lt;BR /&gt;aaa authentication dot1x default radius&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login privilege-mode&lt;BR /&gt;enable aaa console&lt;BR /&gt;hostname TEST&lt;BR /&gt;ip address X.X.X.X 255.255.255.0&lt;BR /&gt;no ip dhcp-client enable&lt;BR /&gt;ip default-gateway X.X.X.X&lt;BR /&gt;!&lt;BR /&gt;username test password ..................&lt;BR /&gt;radius-server host X.X.X.X auth-port 1812 acct-port 1813 default key XXXX dot1x&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/2&lt;BR /&gt;dual-mode 120&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/4&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/5&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/11&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/12&lt;BR /&gt;dual-mode 120&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;lldp med network-policy application voice tagged vlan 99 priority 5 dscp 46 ports ethe 1/1/11&lt;BR /&gt;lldp run&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;TEST# sh mac-auth sess bri&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Port Number of Number of Number of Untagged Dynamic&lt;BR /&gt;Attempted Users Authorized Users Denied Users VLAN Type Port ACL&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;1/1/4 0 0 0 Auth-Default-VLAN No&lt;BR /&gt;1/1/5 2 1 1 Radius-VLAN No&lt;BR /&gt;1/1/7 0 0 0 Auth-Default-VLAN No&lt;/P&gt;&lt;P&gt;TEST# sh dot1x sess bri&lt;BR /&gt;-------------------------------------------------------------------------------------------------&lt;BR /&gt;Port Number of Number of Number of Untagged Dynamic Dynamic&lt;BR /&gt;Users Authorized Users Denied Users VLAN Type PORT ACL MAC-Filt&lt;BR /&gt;--------------------------------------------------------------------------------------- ---------&lt;BR /&gt;1/1/4 0 0 0 Auth-Default-VLAN No No&lt;BR /&gt;1/1/5 2 1 1 Radius-VLAN No No&lt;BR /&gt;1/1/10 0 0 0 Auth-Default-VLAN No No&lt;BR /&gt;1/1/11 0 0 0 Auth-Default-VLAN No No&lt;/P&gt;&lt;P&gt;TEST# sh mac-auth sess all&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;Port MAC IP Vlan Auth ACL Age&lt;BR /&gt;Addr Addr State&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;1/1/5 842a.XXXX.XXXX N/A 120 No none Ena&lt;BR /&gt;1/1/5 0050.XXXX.XXXX N/A 99 Yes none S45&lt;/P&gt;&lt;P&gt;TEST# sh dot1x sess all&lt;BR /&gt;------------------------------------------------------------------------------------------------------&lt;BR /&gt;Port MAC IP User Vlan Auth ACL Age PAE&lt;BR /&gt;Addr Addr Name State State&lt;BR /&gt;------------------------------------------------------------------------------------------------------&lt;BR /&gt;1/1/5 842a.XXXX.XXXX N/A DOMAIN\u.sers 120 permit none Ena AUTHENTICATED&lt;BR /&gt;1/1/5 0050.XXXX.XXXX N/A N/A 99 blocked none H45 HELD&lt;/P&gt;&lt;P&gt;TEST# sh dot1x conf&lt;BR /&gt;PAE Capability : Authenticator Only&lt;BR /&gt;Status : Enabled&lt;BR /&gt;Auth Order : mac-auth dot1x&lt;BR /&gt;Default VLAN : 666&lt;BR /&gt;Auth VLAN Mode : Single Untagged Mode&lt;BR /&gt;Restricted VLAN : 401&lt;BR /&gt;Critical VLAN : Not configured&lt;BR /&gt;Guest VLAN : 401&lt;BR /&gt;Action on Auth failure : Move to Restricted VLAN (401)&lt;BR /&gt;MAC Session Aging : Enabled&lt;BR /&gt;Filter Strict Security : Disabled&lt;BR /&gt;Re-authentication : Enabled&lt;BR /&gt;Session max sw-age : 120 seconds&lt;BR /&gt;Session max hw-age : 70 seconds&lt;BR /&gt;Quiet-period : 60 seconds&lt;BR /&gt;TX-period : 30 seconds&lt;BR /&gt;Reauth-period : 3600 seconds&lt;BR /&gt;Supplicant-timeout : 30 seconds&lt;BR /&gt;Max Reauth requests : 2&lt;BR /&gt;Protocol Version : 1&lt;/P&gt;&lt;P&gt;TEST# sh int eth 1/1/5&lt;BR /&gt;GigabitEthernet1/1/5 is up, line protocol is up&lt;BR /&gt;Port up for 20 hour(s) 32 minute(s) 17 second(s)&lt;BR /&gt;Hardware is GigabitEthernet, address is 609c.XXXX.XXXX (bia 609c.XXXX.XXXX)&lt;BR /&gt;Configured speed auto, actual 100Mbit, configured duplex fdx, actual fdx&lt;BR /&gt;Configured mdi mode AUTO, actual MDI&lt;BR /&gt;Member of 2 L2 VLANs, port is tagged, port state is FORWARDING&lt;BR /&gt;BPDU guard is Disabled, ROOT protect is Disabled, Designated protect is Disabled&lt;BR /&gt;Link Error Dampening is Disabled&lt;BR /&gt;STP configured to ON, priority is level0, mac-learning is enabled&lt;BR /&gt;Flow Control is config enabled, oper enabled, negotiation disabled&lt;BR /&gt;Mirror disabled, Monitor disabled&lt;BR /&gt;Mac-notification is disabled&lt;BR /&gt;Not member of any active trunks&lt;BR /&gt;Not member of any configured trunks&lt;BR /&gt;No port name&lt;BR /&gt;Inter-Packet Gap (IPG) is 96 bit times&lt;BR /&gt;MTU 1500 bytes&lt;BR /&gt;300 second input rate: 504 bits/sec, 0 packets/sec, 0.00% utilization&lt;BR /&gt;300 second output rate: 1872 bits/sec, 3 packets/sec, 0.00% utilization&lt;BR /&gt;1410114 packets input, 775226560 bytes, 0 no buffer&lt;BR /&gt;Received 35555 broadcasts, 36942 multicasts, 1337617 unicasts&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 ignored&lt;BR /&gt;0 runts, 0 giants&lt;BR /&gt;2726534 packets output, 1341509092 bytes, 0 underruns&lt;BR /&gt;Transmitted 398920 broadcasts, 817239 multicasts, 1510375 unicasts&lt;BR /&gt;0 output errors, 0 collisions&lt;BR /&gt;Relay Agent Information option: Disabled&lt;/P&gt;&lt;P&gt;TEST# sh vlan eth 1/1/5&lt;BR /&gt;Total PORT-VLAN entries: 8&lt;BR /&gt;Maximum PORT-VLAN entries: 64&lt;/P&gt;&lt;P&gt;Legend: [Stk=Stack-Id, S=Slot]&lt;/P&gt;&lt;P&gt;PORT-VLAN 99, Name TELEPHONIE, Priority level0, Spanning tree On&lt;BR /&gt;Untagged Ports: None&lt;BR /&gt;Tagged Ports: (U1/M1) 2 4 5 11 12 24&lt;BR /&gt;Uplink Ports: None&lt;BR /&gt;DualMode Ports: None&lt;BR /&gt;Mac-Vlan Ports: None&lt;BR /&gt;Monitoring: Disabled&lt;BR /&gt;PORT-VLAN 666, Name VLAN666, Priority level0, Spanning tree On&lt;BR /&gt;Untagged Ports: (U1/M1) 3&lt;BR /&gt;Tagged Ports: None&lt;BR /&gt;Uplink Ports: None&lt;BR /&gt;DualMode Ports: None&lt;BR /&gt;Mac-Vlan Ports: (U1/M1) 4 5 7 10 11&lt;BR /&gt;Monitoring: Disabled&lt;/P&gt;&lt;P&gt;TEST# sh aaa&lt;BR /&gt;***** TACACS server not configured&lt;BR /&gt;Radius default key: ...&lt;BR /&gt;Radius retries: 3&lt;BR /&gt;Radius timeout: 3 seconds&lt;BR /&gt;Radius Server: IP=X.X.X.X Auth Port=1812 Acct Port=1813 Usage=any&lt;BR /&gt;Key=.....&lt;BR /&gt;opens=3709 closes=2261 timeouts=0 errors=0&lt;BR /&gt;packets in=3709 packets out=3710&lt;BR /&gt;IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 14:03:10 GMT</pubDate>
    <dc:creator>Frenchsysnetadm</dc:creator>
    <dc:date>2022-11-10T14:03:10Z</dc:date>
    <item>
      <title>ICX 6430 Mac-Auth / Dot1x Issues /  SW: Version 08.0.30uT311</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-6430-Mac-Auth-Dot1x-Issues-SW-Version-08-0-30uT311/m-p/48004#M3642</link>
      <description>&lt;P&gt;Hi, i'm trying to configure a switch to work with Dot1x and Mac-authentication, on the same interface.&lt;/P&gt;&lt;P&gt;But i've been having an issue, it only works half way!&lt;/P&gt;&lt;P&gt;Currently, most our users are connected behind a Sangoma S500 IP Phone. And everything works fine (phone calls &amp;amp; data).&lt;/P&gt;&lt;P&gt;But we'd like to make our infrastructure more secure, and prevent anyone to just plug their equipment into our network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Up until now, what we have done is configure a printer radius profile, and a Sangoma radius profile, with MAC authentication (login/password is the MAC of the printer/Phone), and corresponding vlans in the radius profiles, 113-printers, 99-phones, 120-userdata.&lt;/P&gt;&lt;P&gt;On the switch, we've activated Mac-authentication on the port the printer is connected to, and it works fine&lt;/P&gt;&lt;P&gt;Here's the issue. When Mac-authentication &amp;amp; Dot1x is activated on the same interface, and a sangoma phone is connected to it, with a laptop connected to the sangoma; the laptop gets authenticated with Dot1x and put into the corresponding vlan 120.&lt;/P&gt;&lt;P&gt;The Sangoma phone gets put in vlan 99, which is the correct vlan. But we can't actually make calls. somehow, the voice traffic is stopped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's more, when we deactivate "no dot1x port-control auto" on the interface, the laptop loses its authentication, but the phone can make calls.&lt;/P&gt;&lt;P&gt;We need both the laptop and the phone to work together, as they did when mac-auth &amp;amp; dot1x was not activated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not familiar with that technology, so i'm sure the problem must be between the seat and the keyboard ^^&lt;/P&gt;&lt;P&gt;Do you guys have any thoughts on what's going on ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll add that, although Sangoma phones have the capacity to do Dot1x by adding a login/password in the settings, we just would like to authenticate them via MAC, for practical reasons, and do everything remotely from the radius and switches.&lt;/P&gt;&lt;P&gt;But again, i'm not familiar with this technology, so i'm not sure what are the dos and donts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below, you will find the current conf on our test switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current configuration:&lt;BR /&gt;!&lt;BR /&gt;ver 08.0.30uT311&lt;BR /&gt;!&lt;BR /&gt;stack unit 1&lt;BR /&gt;module 1 icx6430-24-port-management-module&lt;BR /&gt;module 2 icx6430-sfp-4port-4g-module&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR /&gt;!&lt;BR /&gt;vlan 2 by port&lt;BR /&gt;!&lt;BR /&gt;vlan 99 name TELEPHONIE by port&lt;BR /&gt;tagged ethe 1/1/2 ethe 1/1/4 to 1/1/5 ethe 1/1/11 to 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 112 name MANAGEMENT by port&lt;BR /&gt;tagged ethe 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 113 name PRINTERS by port&lt;BR /&gt;!&lt;BR /&gt;vlan 120 name STAFF by port&lt;BR /&gt;tagged ethe 1/1/2 ethe 1/1/10 ethe 1/1/12 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 401 name STUDENTS by port&lt;BR /&gt;tagged ethe 1/1/11 ethe 1/1/24&lt;BR /&gt;!&lt;BR /&gt;vlan 666 name VLAN666 by port&lt;BR /&gt;untagged ethe 1/1/3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;authentication&lt;BR /&gt;auth-order mac-auth dot1x&lt;BR /&gt;auth-default-vlan 666&lt;BR /&gt;restricted-vlan 401&lt;BR /&gt;auth-fail-action restricted-vlan&lt;BR /&gt;no filter-strict-security enable&lt;BR /&gt;re-authentication&lt;BR /&gt;dot1x enable&lt;BR /&gt;dot1x enable ethe 1/1/4 to 1/1/5 ethe 1/1/10 to 1/1/11&lt;BR /&gt;dot1x guest-vlan 401&lt;BR /&gt;mac-authentication enable&lt;BR /&gt;mac-authentication enable ethe 1/1/4 to 1/1/5 ethe 1/1/7&lt;BR /&gt;mac-authentication dot1x-override&lt;BR /&gt;!&lt;BR /&gt;aaa authentication web-server default local&lt;BR /&gt;aaa authentication dot1x default radius&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login privilege-mode&lt;BR /&gt;enable aaa console&lt;BR /&gt;hostname TEST&lt;BR /&gt;ip address X.X.X.X 255.255.255.0&lt;BR /&gt;no ip dhcp-client enable&lt;BR /&gt;ip default-gateway X.X.X.X&lt;BR /&gt;!&lt;BR /&gt;username test password ..................&lt;BR /&gt;radius-server host X.X.X.X auth-port 1812 acct-port 1813 default key XXXX dot1x&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/2&lt;BR /&gt;dual-mode 120&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/4&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/5&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/11&lt;BR /&gt;dot1x port-control auto&lt;BR /&gt;!&lt;BR /&gt;interface ethernet 1/1/12&lt;BR /&gt;dual-mode 120&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;lldp med network-policy application voice tagged vlan 99 priority 5 dscp 46 ports ethe 1/1/11&lt;BR /&gt;lldp run&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;TEST# sh mac-auth sess bri&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Port Number of Number of Number of Untagged Dynamic&lt;BR /&gt;Attempted Users Authorized Users Denied Users VLAN Type Port ACL&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;1/1/4 0 0 0 Auth-Default-VLAN No&lt;BR /&gt;1/1/5 2 1 1 Radius-VLAN No&lt;BR /&gt;1/1/7 0 0 0 Auth-Default-VLAN No&lt;/P&gt;&lt;P&gt;TEST# sh dot1x sess bri&lt;BR /&gt;-------------------------------------------------------------------------------------------------&lt;BR /&gt;Port Number of Number of Number of Untagged Dynamic Dynamic&lt;BR /&gt;Users Authorized Users Denied Users VLAN Type PORT ACL MAC-Filt&lt;BR /&gt;--------------------------------------------------------------------------------------- ---------&lt;BR /&gt;1/1/4 0 0 0 Auth-Default-VLAN No No&lt;BR /&gt;1/1/5 2 1 1 Radius-VLAN No No&lt;BR /&gt;1/1/10 0 0 0 Auth-Default-VLAN No No&lt;BR /&gt;1/1/11 0 0 0 Auth-Default-VLAN No No&lt;/P&gt;&lt;P&gt;TEST# sh mac-auth sess all&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;Port MAC IP Vlan Auth ACL Age&lt;BR /&gt;Addr Addr State&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;1/1/5 842a.XXXX.XXXX N/A 120 No none Ena&lt;BR /&gt;1/1/5 0050.XXXX.XXXX N/A 99 Yes none S45&lt;/P&gt;&lt;P&gt;TEST# sh dot1x sess all&lt;BR /&gt;------------------------------------------------------------------------------------------------------&lt;BR /&gt;Port MAC IP User Vlan Auth ACL Age PAE&lt;BR /&gt;Addr Addr Name State State&lt;BR /&gt;------------------------------------------------------------------------------------------------------&lt;BR /&gt;1/1/5 842a.XXXX.XXXX N/A DOMAIN\u.sers 120 permit none Ena AUTHENTICATED&lt;BR /&gt;1/1/5 0050.XXXX.XXXX N/A N/A 99 blocked none H45 HELD&lt;/P&gt;&lt;P&gt;TEST# sh dot1x conf&lt;BR /&gt;PAE Capability : Authenticator Only&lt;BR /&gt;Status : Enabled&lt;BR /&gt;Auth Order : mac-auth dot1x&lt;BR /&gt;Default VLAN : 666&lt;BR /&gt;Auth VLAN Mode : Single Untagged Mode&lt;BR /&gt;Restricted VLAN : 401&lt;BR /&gt;Critical VLAN : Not configured&lt;BR /&gt;Guest VLAN : 401&lt;BR /&gt;Action on Auth failure : Move to Restricted VLAN (401)&lt;BR /&gt;MAC Session Aging : Enabled&lt;BR /&gt;Filter Strict Security : Disabled&lt;BR /&gt;Re-authentication : Enabled&lt;BR /&gt;Session max sw-age : 120 seconds&lt;BR /&gt;Session max hw-age : 70 seconds&lt;BR /&gt;Quiet-period : 60 seconds&lt;BR /&gt;TX-period : 30 seconds&lt;BR /&gt;Reauth-period : 3600 seconds&lt;BR /&gt;Supplicant-timeout : 30 seconds&lt;BR /&gt;Max Reauth requests : 2&lt;BR /&gt;Protocol Version : 1&lt;/P&gt;&lt;P&gt;TEST# sh int eth 1/1/5&lt;BR /&gt;GigabitEthernet1/1/5 is up, line protocol is up&lt;BR /&gt;Port up for 20 hour(s) 32 minute(s) 17 second(s)&lt;BR /&gt;Hardware is GigabitEthernet, address is 609c.XXXX.XXXX (bia 609c.XXXX.XXXX)&lt;BR /&gt;Configured speed auto, actual 100Mbit, configured duplex fdx, actual fdx&lt;BR /&gt;Configured mdi mode AUTO, actual MDI&lt;BR /&gt;Member of 2 L2 VLANs, port is tagged, port state is FORWARDING&lt;BR /&gt;BPDU guard is Disabled, ROOT protect is Disabled, Designated protect is Disabled&lt;BR /&gt;Link Error Dampening is Disabled&lt;BR /&gt;STP configured to ON, priority is level0, mac-learning is enabled&lt;BR /&gt;Flow Control is config enabled, oper enabled, negotiation disabled&lt;BR /&gt;Mirror disabled, Monitor disabled&lt;BR /&gt;Mac-notification is disabled&lt;BR /&gt;Not member of any active trunks&lt;BR /&gt;Not member of any configured trunks&lt;BR /&gt;No port name&lt;BR /&gt;Inter-Packet Gap (IPG) is 96 bit times&lt;BR /&gt;MTU 1500 bytes&lt;BR /&gt;300 second input rate: 504 bits/sec, 0 packets/sec, 0.00% utilization&lt;BR /&gt;300 second output rate: 1872 bits/sec, 3 packets/sec, 0.00% utilization&lt;BR /&gt;1410114 packets input, 775226560 bytes, 0 no buffer&lt;BR /&gt;Received 35555 broadcasts, 36942 multicasts, 1337617 unicasts&lt;BR /&gt;0 input errors, 0 CRC, 0 frame, 0 ignored&lt;BR /&gt;0 runts, 0 giants&lt;BR /&gt;2726534 packets output, 1341509092 bytes, 0 underruns&lt;BR /&gt;Transmitted 398920 broadcasts, 817239 multicasts, 1510375 unicasts&lt;BR /&gt;0 output errors, 0 collisions&lt;BR /&gt;Relay Agent Information option: Disabled&lt;/P&gt;&lt;P&gt;TEST# sh vlan eth 1/1/5&lt;BR /&gt;Total PORT-VLAN entries: 8&lt;BR /&gt;Maximum PORT-VLAN entries: 64&lt;/P&gt;&lt;P&gt;Legend: [Stk=Stack-Id, S=Slot]&lt;/P&gt;&lt;P&gt;PORT-VLAN 99, Name TELEPHONIE, Priority level0, Spanning tree On&lt;BR /&gt;Untagged Ports: None&lt;BR /&gt;Tagged Ports: (U1/M1) 2 4 5 11 12 24&lt;BR /&gt;Uplink Ports: None&lt;BR /&gt;DualMode Ports: None&lt;BR /&gt;Mac-Vlan Ports: None&lt;BR /&gt;Monitoring: Disabled&lt;BR /&gt;PORT-VLAN 666, Name VLAN666, Priority level0, Spanning tree On&lt;BR /&gt;Untagged Ports: (U1/M1) 3&lt;BR /&gt;Tagged Ports: None&lt;BR /&gt;Uplink Ports: None&lt;BR /&gt;DualMode Ports: None&lt;BR /&gt;Mac-Vlan Ports: (U1/M1) 4 5 7 10 11&lt;BR /&gt;Monitoring: Disabled&lt;/P&gt;&lt;P&gt;TEST# sh aaa&lt;BR /&gt;***** TACACS server not configured&lt;BR /&gt;Radius default key: ...&lt;BR /&gt;Radius retries: 3&lt;BR /&gt;Radius timeout: 3 seconds&lt;BR /&gt;Radius Server: IP=X.X.X.X Auth Port=1812 Acct Port=1813 Usage=any&lt;BR /&gt;Key=.....&lt;BR /&gt;opens=3709 closes=2261 timeouts=0 errors=0&lt;BR /&gt;packets in=3709 packets out=3710&lt;BR /&gt;IPv4 Radius Source address: IP=0.0.0.0 IPv6 Radius Source Address: IP=::&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:03:10 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-6430-Mac-Auth-Dot1x-Issues-SW-Version-08-0-30uT311/m-p/48004#M3642</guid>
      <dc:creator>Frenchsysnetadm</dc:creator>
      <dc:date>2022-11-10T14:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 6430 Mac-Auth / Dot1x Issues /  SW: Version 08.0.30uT311</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-6430-Mac-Auth-Dot1x-Issues-SW-Version-08-0-30uT311/m-p/48320#M3652</link>
      <description>&lt;P&gt;Hi, i was able to solve the issue.&lt;/P&gt;&lt;P&gt;It turns out that, i assumed since the IP phones are connected first on the switch port, they had to be authenticated first. So i was systematically changing the order to "auth-order mac-auth dot1x".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i tried changing the order on the interface to "auth-order dot1x mac-auth", and it worked.&lt;/P&gt;&lt;P&gt;We now have mac-authentication and dot1x working on the same interface, with both the iphone going to voice vlan 99, and laptops(user AD accounts) going to vlan 120, and we can make phone calls too.&lt;/P&gt;&lt;P&gt;Nowhere in all the docs i've read was it mentionned that this was the order ^^&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, problem solved, at least for now.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 19:26:32 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-6430-Mac-Auth-Dot1x-Issues-SW-Version-08-0-30uT311/m-p/48320#M3652</guid>
      <dc:creator>Frenchsysnetadm</dc:creator>
      <dc:date>2022-11-14T19:26:32Z</dc:date>
    </item>
  </channel>
</rss>

