Omnistack 6200 - 802.1x Port Based Authentication

Post Reply
alcatel-guy
Member
Posts: 1
Joined: 16 Jan 2013 15:33

Omnistack 6200 - 802.1x Port Based Authentication

Post by alcatel-guy »

Hello everyone,

I am trying to setup dot1x on omni 6200 platform. Switch is running 1.7.1.10.
Trying to authenticate both IP Phone and PC connected to the switch port.

My base config is as follows:
interface range ethernet 2/e(37-38)
dot1x multiple-hosts authentication
switchport mode trunk
switchport trunk allowed vlan add 114
switchport trunk allowed vlan add 24
dot1x mac-authentication mac-and-dot1x
dot1x port-control auto
no dot1x legacy-supp-mode
dot1x timeout quiet-period 5

Authenticating to Cisco ACS. I am using a Machine authentication bypass policy for IP phones and EAP-MD5 for PCs.
This setup works fine. I can see both the PC and IP phone successfully authenticate to ACS server.

My issue:
If I test this config with just the IP phone then the port never gets "authorized". Is there anyway to make this work where the IP phone can authenticate(or do MAB) to Cisco ACS server on its own (i.e. without the PC).

Thank you !!!
Post Reply

Return to “GENERAL”