Hello,
i am trying to configure 802.1x and Mac Authentication on a switch port.
First i have upgraded the firmware version to v6.3.5.025 to fix that : wi01208586
So my goal is to have a Avaya voip phone (Mac-auth) and a laptop behind the phone (802.1x or Mac-Auth).
When i plug the phone, ADAC detect it with LLDP and tag the port on the voice vlan (192).
When i plug a laptop behind the phone, if the supplicant has been configured then 802.1x works, if there is no supplicant then mac auth works.
My issue are the following:
First: I have configured machine authentication and user authentication on the laptop, so when i start the laptop first i have the machine auth and radius return the vlan 211, then the user open his session and for user authentication radius return vlan 2192. But the switch don't care about the vlan 2192 and keep the port in the vlan 211.
The second issue:
When the laptop is connected behind the phone (802.1x) and when we unplug and plug it, the ERS switch fall back directly to MAC authentication and after a while i have a new 802.1x auth.
Here my switch config:
vlan ports 1/6 tagging unTagPvidOnly filter-unregistered-frames disable
! Vlan 192 is the Voice VLAN configured by ADAC
vlan members 211 1/6
vlan members 2192 1/6
eapol multihost port 1/6 enable eap-mac-max 8 allow-non-eap-enable non-eap-mac-
max 8 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-e
ap-use-radius-assigned-vlan eap-packet-mode unicast adac-non-eap-enable
eapol port 1/6 status auto traffic-control in re-authentication enable re-authe
ntication-period 600
eapol port 1/6 radius-dynamic-server enable
lldp port 1/6 vendor-specific avaya dot1q-framing tagged
adac port 1/6 tagged-frames-pvid 192
adac port 1/6 tagged-frames-tagging tag-all
adac port 1/6 enable
spanning-tree port 1/6 learning fast
Regards
Fabrice
i am trying to configure 802.1x and Mac Authentication on a switch port.
First i have upgraded the firmware version to v6.3.5.025 to fix that : wi01208586
So my goal is to have a Avaya voip phone (Mac-auth) and a laptop behind the phone (802.1x or Mac-Auth).
When i plug the phone, ADAC detect it with LLDP and tag the port on the voice vlan (192).
When i plug a laptop behind the phone, if the supplicant has been configured then 802.1x works, if there is no supplicant then mac auth works.
My issue are the following:
First: I have configured machine authentication and user authentication on the laptop, so when i start the laptop first i have the machine auth and radius return the vlan 211, then the user open his session and for user authentication radius return vlan 2192. But the switch don't care about the vlan 2192 and keep the port in the vlan 211.
The second issue:
When the laptop is connected behind the phone (802.1x) and when we unplug and plug it, the ERS switch fall back directly to MAC authentication and after a while i have a new 802.1x auth.
Here my switch config:
vlan ports 1/6 tagging unTagPvidOnly filter-unregistered-frames disable
! Vlan 192 is the Voice VLAN configured by ADAC
vlan members 211 1/6
vlan members 2192 1/6
eapol multihost port 1/6 enable eap-mac-max 8 allow-non-eap-enable non-eap-mac-
max 8 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-e
ap-use-radius-assigned-vlan eap-packet-mode unicast adac-non-eap-enable
eapol port 1/6 status auto traffic-control in re-authentication enable re-authe
ntication-period 600
eapol port 1/6 radius-dynamic-server enable
lldp port 1/6 vendor-specific avaya dot1q-framing tagged
adac port 1/6 tagged-frames-pvid 192
adac port 1/6 tagged-frames-tagging tag-all
adac port 1/6 enable
spanning-tree port 1/6 learning fast
Regards
Fabrice
Comment