Cannot get CoA switch to bounce port
Hi, I am trying to clear up a VLAN change/IP addressing conflict and have configured the profile's associated CoA type to 'port bounce'. I also created an exception action to force CoA with an associate rule in the policy.
I can see the device hit the correct profile upon MAB, and the correct VLAN is applied to the port. However, I never see the port bounce occuring, so the deviec does not know to release/renew it's IP address.
Is there something I'm missing to get the CoA port bounce to happen? Here is my switchport config...
interface GigabitEthernet1/5
description ISE_TEST
switchport access vlan 32
switchport mode access
switchport voice vlan 64
ip access-group ACL-ALLOW in
logging event link-status
authentication event fail action next-method
authentication event server dead action authorize vlan 2700
authentication event server alive action reinitialize
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
authentication periodic
authentication timer restart 600
authentication timer reauthenticate server
authentication violation restrict
mab
dot1x pae authenticator
dot1x timeout tx-period 5
service-policy input QoS-Input-Policy
service-policy output QoS-Host-Port-Output-Policy
end
I did, but my issue was not related to the port bounce itself. It was because arp inspection was identifying the arp based off the ports initial VLAN. Once ISE changed the VLAN, ip arp was denying the port because the address had changed. I disabled arp inspection and it cleared up the issue.
Similar Messages
-
Cannot get Mail Service to bypass port 25
I'm running SLS 10.6. on a Mini connected via Cox home internet. It is a standalone server which will see only light duty handling wikis, blogs, and small mailing lists for just a handful of users.
Port 25 is blocked by default, so I'm trying to use port 587 instead.
I have:
• modified the master.cf file as suggested in several other threads
• opened port 587 on my router (Time Capsule) - I can see the port is open remotely via Network Utility
AFAIK I have everything set up properly according to the documentation, but I cannot send or receive mail. However, if I attempt to send mail via squirrelmail using the web interface the messages do get bounced back, and I can see these bounced back messages with a remote POP mail client.
So what now?Camelot wrote:
My point was that if you change the port (which you can do, and that MacOSXHints article walks through) no mail will flow through your server unless the remote systems that are trying to send you mail (or send mail through you) are reconfigured to use the same port.
e.g. if you switch your mail server from 25 to 2525 then nothing's going to happen until everyone else knows that you're using 2525 for SMTP.
Now, in this case it's (relatively) easy to change your Mail.app client to send mail through port 2525, but there is no way to tell other mail servers to do the same - every other mail server in the world will try to connect to port 25.
Understood. I have seen others post that they have used a relay (say through DNYDNS.org) pointed to another port (587 for example) to get around this. I am on the right track here?
Camelot wrote:
That's why I asked what your goal was here - if your intent/expectation is that this mail server will handle mail for your domain and that other mail servers will be sending messages to you then this approach is doomed to failure. It's only viable if you control all the client systems that are using it.
My goal is for this server to send occasional emails to a few people via mailman lists and wiki groups, as well as push notification for iCal events. It won't be doing any heavy duty email, we have remotely hosted email service for that. -
Cannot get SG300 switch to send RADIUS messages for 802.1x
I want to eventually configure the SG300 to authenticate wired clients with 802.1x and Microsoft NPS (RADIUS). I am currently testing this setup using a single port (Port 7) on my SG300, a test machine, and an AD based Network Policy Server.
The problem I have is that when I change the Administrative Port Control for Port 7 to Force Authorized, I see this log entry:
Informational %SEC-I-PORTAUTHORIZED: Port gi7 is Authorized
And then when I change the port control to Auto the port immediately changes to Unauthorized and I see this log entry:
Warning %SEC-W-PORTUNAUTHORIZED: Port gi7 is unAuthorized
However I never see any RADIUS messages being sent from the SG300 to my RADIUS server or from the SG300 to the test machine plugged into port 7. I am using WireShark on my RADIUS server to watch for messages from the SG300 IP Address and I'm using WireShark on a second test machine that is configured to monitor the NIC card in the test machine plugged into port 7 (I'm using Hyper-V and its facilities for this NIC monitoring setup.)
Here is my configuration:
Switch - 10.1.1.3
RADIUS (Microsoft NPS)- 10.1.1.15
Switch Usage Type - All (Login and 802.1x)
Port 7 configuration:
VLAN Mode is General
Host Authentication is Single Host Authentication
Administrative Port Control is Auto
RADIUS VLAN Assignment is Disabled
Guest VLAN is Enabled
802.1x Based Authentication is Enabled
Additional Configurations under Security - 802.1x/MAC/Web Authentication:
Port Based Authentication is Enabled
Authentication Method is RADIUS
Guest VLAN is Enabled
Guest VLAN ID is 2
All of my VLANs are enabled for Authentication
I've got to be missing something but I do not know what that something is.
One last note:
The SG300 uses the same RADIUS server for management console access and it works without problem. When I log into the switch, WireShark shows the RADIUS messages from the switch to the RADIUS server and back. So I know RADIUS is configured correctly on the switch.Hi,
This is my working configuration where port gi3 has DVA configured as well. You might skip port gi3 but please compare to your config:
interface gi3
dot1x host-mode multi-sessions
exit
vlan database
vlan 30,100
exit
interface vlan 100
dot1x guest-vlan
exit
dot1x system-auth-control
interface range gi1,gi3
dot1x reauthentication
exit
interface range gi1,gi3
dot1x mac-authentication mac-only
exit
interface gi3
dot1x radius-attributes vlan
exit
interface range gi1,gi3
dot1x guest-vlan enable
exit
interface gigabitethernet1
dot1x port-control auto
exit
interface gigabitethernet3
dot1x port-control auto
exit
radius-server host 192.168.1.122 priority 1
radius-server key testing123
aaa authentication dot1x default radius
switch3ba5e1#
Regards,
Aleksandra -
I have a I pad MD522LL/A version 7.0 and cannot get off of mute I have tried items in settings and moving back lock switch as well as volume any help
Hey there,
It sounds like you are unable to get any sound from your built in speaker on your device, even after toggling the side switch. I recommend the troubleshooting from the following article named:
iPhone: No sound or distorted sound from speaker
http://support.apple.com/kb/ts5180
Verify that the volume is set to a level you would normally be able to hear.
Ensure that there is nothing plugged in to the headset jack or the dock connector.
If the iPhone is in a protective case, make sure that the speaker port isn't blocked by the case.
Make sure that the speaker and dock port aren't clogged with debris. If necessary, clean it with a clean, small, dry, soft-bristled brush. Carefully and gently brush away any debris.
If an audio issue occurs when using a specific application, try testing other applications to see if the issue persists.
If the iPhone is paired with a Bluetooth headset or car kit:
Try turning off Bluetooth.
If you experience difficulties with the Bluetooth feature, follow these troubleshooting steps.
Restart the iPhone.
If restarting doesn't fix the issue, ensure that your iPhone is updated to the latest version of iOS.
If the issue is not resolved after restoring the iPhone software, please contact Apple Support.
The article title mentions the iPhone, but the steps are relevant for the iPad as well.
Thank you for using Apple Support Communities.
Regards,
Sterling -
Cannot get iPad 2 charged beyond 1%. All charging ports tried: AC adapter(s), USB 2 port on MacBook Pro. ITunes shows iPad only for a few seconds. iPad displays alternately: Apple logo, battery w/slim red band, then battery w/1% charged information. How can I get it to charge beyond 1% so I can proceed to troubleshoot?
I have had your exact problem with my old 3GS, now I cannot even get it to turn on, I still see that it is supposed to be charging though, but it never charges any so it seems.
I replaced the Lower Dock Connector Assembly back when it still charged while hooked to my PC, and it found it made no real difference.
http://www.amazon.com/gp/product/B003Y5YXLK/ref=oh_details_o05_s00_i00?ie=UTF8&p sc=1
At this point I am not sure if I should replace the battery and hope for the best, or just junk the phone, I cannot really sell it if I cannot reset it... -
How can I get my Apple TV airplay to work from my PC. On the airplay symbol it says Multiple Peakers please choose but I cannot switch off my computer speakers and switch on my Apple TV speakers so cannot get airplay to work from my PC. Everything is OK when using my Ipod touch.
Don't use Multiple Speakers option and just choose the AppleTV
What are you trying to Airplay? If it's iTunes content it's simpler to 'pull' the stream from the Computers icson on AppleTV by selecting the libarry and media.
If you are attempting to Airplay the desktop you can't. -
Switched video settings on my Mac Mini and now the bloody thing shows "Invalid Format" on my TV (used as monitor for years) and I cannot get it to switch back.
What can I do to get it to work again as more than an overpriced paperweight?Hello,
Safe Boot from the HD, (holding Shift key down at bootup), see if you can set a good resolution. -
Cannot get USB port to work after re-installing of SP2 on Satellite Pro L20
After re-installing XP Home SP2 and downloading all the updates & Drivers from here I cannot get my USB port to work properly, if I have more than one peripheral plugged in it says "Bandwidth Exceeded".
I have a Behringer BCD2000 which is a souncard/midi controler for DJ mixing, it worked fine before i reinstalled windows, now it clicks and pops when playing tunes, also the ASIO doesn't work when I run Traktor (Dj software) and the program freezes. Any other external sound card wont work either. I've been all through the device manager no conflicts apart from an ! over Serial under hidden devices.
I'm lost, is my only option buying a PCMCIA sound card, it worked fine before so surely there is a software solution to this?
If anyone can help I'd be most appreciative.Hello
Try to disable USB Error Detection:
1. Right-click My Computer and then click Properties.
2. Select Device Manager to view the Device Manager
3. Locate and click the Universal Serial Bus Controller entry.
4. Double-click Universal Host Controller and then click the Advanced tab of the Universal Host Controller Properties.
5. Put a checkmark in the box for Disable USB Error Detection. Click OK.
6. Restart the computer to see if "Bandwidth Exceeded" message occurs again
Did you use recovery media to reinstall WXP? When someone write it worked before and now not it is really not easy to say why this happen. Try to configure notebook as before and maybe it will work again. Behringer BCD2000 is not known to me and I dont know how it works and which software must be preinstalled there.
Can you use different USB devices like external HDD, USB mouse, USB memory stick or printer? -
I have recently update to the OS Maverik and I use a projector with a mini display port adaptor to my MacBook Air, ever since the only thing that projects is my desktop picture. I cannot get it to project my school work that I need to teach my students. Help!
Hi Becki514,
Welcome to the Support Communities!
The following articles may help you with your projector issue:
Apple computers: Troubleshooting issues with video on internal or external displays
http://support.apple.com/kb/ht1573
Apple Mini DisplayPort adapters: Frequently asked questions (FAQ)
http://support.apple.com/kb/ht3382
Mac notebooks: How to use your computer in closed clamshell (display closed) mode with an external display
http://support.apple.com/kb/ht3131
I hope this information helps ....
Have a great day!
- Judy -
Whenever I switch on my iPad Air, I am presented with a full screen piture of a blue sky, stars and white clouds, which I cannot get out of. How do I do so, please?
Sorry, please ignore this question. I have just realised that the answer is the same as the one I recieved to a previous similar one.
-
Slmodem/wvdial: cannot get information for serial port
Hi,
I have the following problem when trying to set up my Intel WinModem with arch:
After configuring wvdial I get an error when trying to launch it
/dev/ttySL0: Cannot get information for serial port
Does anybody know about this problem? There is absolutely no information about it on the internet.
Thanks for any help!!!!!Hi,
I have the following problem when trying to set up my Intel WinModem with arch:
After configuring wvdial I get an error when trying to launch it
/dev/ttySL0: Cannot get information for serial port
Does anybody know about this problem? There is absolutely no information about it on the internet.
Thanks for any help!!!!! -
HT4085 I am having problems with my side switch. I cannot get it to work. Any advice
I cannot get my side switch to rotate. Any suggestions?
Understanding the Side Switch
http://support.apple.com/kb/HT4085 -
I have a MacBook Pro and all of a sudden I cannot get wireless internet connectivity to my router or any other router, I get connectivity through the ethernet port but not wireless. This was working well till this morning
BXB1905 wrote:
I tried the Apple diagnostics it did not work.
What do you mean it did not work! What were the results of the diagnostic tests?
Have you contacted your ISP to determine if the problem is on their end?
Have you changed your router channel? Sometimes this resolves wireless problems.
Your profile confirms you are using Lion. Check out the following:
Troubleshooting Wi-Fi issues in OS X Lion and Mac OS X v10.6
Configuring 802.1X in Mac OS X Lion and Later -
just switched from a charter email to a gmail. i am syncing fine with ipad and iphone. But cannot get email to sync through outlook 2007.
could someone help me?How does iCloud have anything to do with this, you have 2 email accounts, neither of them an iCloud account?
If you want to get Gmail on your iPhone add it to your iPhone. Same goes for Outlook. -
My "voice on" is on whenever I switch on the phone and I cannot get to enter my password code to activiate the phone.
From the "More Like This" section to the right... https://discussions.apple.com/message/17176752#17176752
Maybe you are looking for
-
SetSize() not working properly in FlowLayout
I've a JPanel which holds 11 JButtons. The JPanel's layout is FlowLayout. I've Images on all the JButtons. I've setSize of the JPanel according to the JButtons width & Height which is also set according to the Images width & Height. But the JButtons
-
Hi hope somebody can help? i have acrobat 6 pro, worked well for last two years but then just stopped working. Have reinstalled but still will not open, ronning windows 7. Help please!! Janice
-
Please help
-
CD is stuck inside laptops player, how do I get it out?
I was ripping a CD the carrier will open and exit, but the CD stayed in my laptop. How do I get the CD to eject?
-
I installed the update for iphoto propperly, but in the app store icon in dock the red 1 still shows up and I cant get rid of it.file://localhost/Volumes/Daten/Users/AG/Desktop/Bildschirmfoto%202012-10-08% 20um%2011.11.13.pngfile://localhost/Volumes/