802.1x MDA LLDP Disabled on Switch (3750) but detected on phone?

I have been playing around with 802.1x and some IP phones.  The test senario we have is that LLDP is globally disabled on the switch and enabled on the phone.  When the phone boots up a non-LLDP enabled device is allowed to use the data vlan to boot and learn (via DHCP) the voice vlan.
http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/IP_Tele/IP_Telephony_DIG.html#pgfId-389460
We found that if LLDP is disabled on the switch it still detects LLDP on the phone and blocks the LLDP enabled phone from using the data vlan.  This causes the phone to "hang" waiting for DHCP.
Turning LLDP off on the switch port did not seem to help as the switch tests for LLDP reguardless and then blocks access to the data vlan.  It seems like *if* LLDP is disabled on the switch it should treat all devices as non-LLDP devices and allow the use of the data vlan.  Even if the device (IP Phone) is capable of LLDP.
Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(55)SE8, RELEASE SOFTWARE (fc2)

Turned out that this was being caused by not having a valid DATA vlan set (leaving it in vlan 1).  It looks like with MDA you cannot assign the data VLAN the phone will use to boot in a Radius reply.  It has to be assigned manually?
Is there another way to tell the switch to allow the phone on data vlan 20 for a short period of time?
interface x/y/z
 switchport access vlan 20
 switchport mode access
 switchport nonegotiate
 switchport voice vlan 60
 switchport port-security maximum 5
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 authentication event fail retry 1 action authorize vlan 20
 authentication event no-response action authorize vlan 20
 authentication host-mode multi-domain
 authentication order mab dot1x
 authentication priority mab dot1x
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 mab
 snmp trap mac-notification change added
 dot1x pae authenticator
 dot1x timeout quiet-period 3
 dot1x timeout server-timeout 2
 dot1x timeout tx-period 5
 dot1x timeout supp-timeout 2
 spanning-tree portfast

Similar Messages

  • 802.1x between Switch 3750 and ACS 4.2 Authentication faild --need help

    I configured the Switch 3750 and ACS for 802.1x authentication.
    when I used the windows as the 802.1x client, it prompted "click here to enter user name and pasword for the network " as normal.
    The problem is that after I entered username and password (i am sure i enter the identical username and password as in ACS) the authentication failed,
    What is the most possibly problem?
    Thx in advance!!!
    The configuration is Sw3750 is:
    aaa new-model
    aaa authentication login default local
    aaa authentication enable default line
    aaa authentication dot1x default group radius
    aaa authorization network default group radius
    dot1x system-auth-control
    interface GigabitEthernet1/0/18
    description Link to test 802.1x
    switchport access vlan 119
    switchport mode access
    dot1x pae authenticator
    dot1x port-control auto
    spanning-tree portfast
    radius-server host 10.1.1.333 auth-port 1645 acct-port 1646
    radius-server source-ports 1645-1646
    radius-server key keepopen0
    In the ACS:
    Network Configuration -->aaa client ip address: 10.1.119.1(the vlan 119's ip address), shared secret: keepopen0
    user setup -->real name:test1, password: test1.
    Attached is the debug information

    What do you see in acs failed attempts?

  • How can I disable auto-switching desktops?

    I've long appreciated the spaces/mission control feature of OS X. However, it seems more oriented to organizing desktops by application rather than by project.
    Like many users, I suspect, I use different desktops for different projects, each of which requires a variety of applications (finder, word docs, spreadsheets, etc). When I'm working on project 1 in desktop 1, I never want to be whisked away to desktop 2. In fact, I never want to be switched to a different desktop automatically. If I click on an application, I want it to open a new window for that application. If a new iteration of an app can't be opened (ie, Mail), I'd like it to pull Mail to me rather than send me off to it. Aren't apps supposed to come when we call, not the other way around?
    I have unchecked "...switch to a space with open windows of that application" in System Prefences, but my desktop continues to auto-switch, especially with Finder.
    In short: is there a way disable auto-switching entirely? I'd like to be able to assign windows and navigate manually without being constantly pulled away from the project I'm working on.
    Thanks for the help; I really appreciate people spending their time helping others on forums like this one.

    Try setting up another admin user account to see if the same problem continues. If Back-to-My Mac is selected in System Preferences, the Guest account will not work. The intent is to see if it is specific to one account or a system wide problem. This account can be deleted later.
    Isolating an issue by using another user account
    If the problem is still there, try booting into the Safe Mode.  Shut down the computer and then power it back up. Immediately after hearing the startup chime, hold down the shift key and continue to hold it until the gray Apple icon and a progress bar appear. The boot up is significantly slower than normal. This will reset some caches, forces a directory check, and disables all startup and login items, among other things. If the system operates normally, there may be 3rd party applications which are causing a problem. Try deleting/disabling the third party applications after a restart. For each disable/delete, you will need to restart if you don't do them all at once.
    Safe Mode
    Safe Mode - About
    General information.
    Isolating issues in Mac OS X
    Troubleshooting Permission Issues
    Step by Step to Fix Your Mac

  • I am using Photoshop CS5 on a new iMac with a wireless keyboard.  I used to be able to hit F11 to perform a custom sharpening action but now the F11 key is the volume control key and I have tried everything to disable or switch the volume key. I have also

    I am using Photoshop CS5 on a new iMac with a wireless keyboard.  I used to be able to hit F11 to perform a custom sharpening action but now the F11 key is the volume control key and I have tried everything to disable or switch the volume key. I have also tried assigning other function keys to initiate the action. Is there a simple solution to this? What am I missing?

    Try unmounting the volume on your iMac using Disk Utility. Then mount it again. You may need to reboot the laptop or relaunch its Finder process (using the Force Quit window) after remounting the drive on your iMac. Remember that no process may be accessing any files on the drive you plan to unmount, or the unmount will fail. Unmounting and remounting an external drive on my iMac made it become visible on my MacBook Pro after it had disappeared.

  • Satellite A200-1GC (PSAE3E) How to disable WLAN switch?

    Hello everybody,
    is there any way to disable that stupid wlan switch, which prevents any new wlan card to run properly? I've tried to install several different wlan cards: Intel 5100, Intel 5300 etc. Every card was working properly (device manager), but the wlan led does not lit. Windows 7 64 Bit always says, that i should turn on the switch. But the switch is already turined on. I've installed value added package also. The key combination Fn+F8 simply does not work. When i install the old wlan card Intel 3945, then everything works fine: the wlan led lits and so on. Any comments from toshiba support people maybe?
    Regards,
    Igor

    I've found a solution by myself. I've cut the wire on my WIFI 5100 which leads to the pin 20 on the card. The switch still doesn't work, which now doesn't prevent my card to be working nomally. Now i have full 300 Mbit speed. :)
    Another option would be to cover the pin 20 on the card with a sticky tape for example.

  • 802.1q trunk b/w 8PoE switch integrated in 1861 CME

    Hi,
    I have to deploy cme7.0 (1861). Actually two 1861 routers are bought but only one of them act as cme while the 8PoE integrated switch of other 1861 is used. half of the IP phones are connected to the 8PoE integrated switch in CME (1861 router) while half of the phones are connected to 8PoE of 1861 (only 1861's PoE is used in this setup). i want to know whether i can cascade the two switches or in other words whether i can form a 802.1q trunk b/w these switches to carry the voice and data vlans.
    Regards
    Naresh Rathore

    Yes, you can.

  • Why have many of my add-ons and extensions been disabled after switching to firefox 6

    Many of my add-ons and extensions have been disabled after switching to Firefox 6.
    None of the Java extensions can be used;
    my Microsoft frame is disabled;
    my media player is gone;
    and my google toolbar with all of my important bookmarks is missing.
    How can Firefox 6 be considered an "upgrade"?
    How can I '''retrieve Firefox 4 or 5'?''--there's no point in using a browser that limits so many necessary add-on sites!

    Hi, mhaoo7--
    Tried your plugins updating suggestion; no go.
    Then tried updating to FF7.
    This time the Yahoo! toolbar was no longer compatible with FF.
    Scoured sites discussing problems with versions 6 & 7
    and decided to retire to version 3.6.19.
    Now both Google and Yahoo! toolbars are re-installed and
    working....Only deficit may be that FF no longer supports or
    soon will not support this version.
    I have stashed all of my necessary bookmarks on Google's toolbar;
    I like its drop-down menu as it doesn't change the page/window I'm
    in the process of using;
    I don't want to see that menu listed separately in a new window (too chaotic).
    Same for the Google dictionary and Thesaurus, which are straightforward
    and easy to use, again requiring nothing more complicated than a drop-down menu
    to search for words and concepts.
    --I checked Firefox 6 and 7's Dictionary/Thesaurus options but unfortunately
    found none.
    So if Firefox continues to upgrade with diminished returns, I'll likely have to go
    to Google Chrome.
    Would rather not do that.
    Maybe I can keep FF 3.6.19 without incurring nasty repercussions.
    Hope so.
    Have enjoyed being with Firefox for a few years.
    Thank you for your attention.
    marlem388

  • Firefox continues to have"Not Reponding" issues. Upadated all plug-ins and disables most of them but issue still occurs, often.

    Firefox continues to have"Not Responding" issues. Updated all plug-ins and disabled most of them but issue still occurs, OFTEN.

    Thank you for your reply,
    I know that plugins aren't being outright disabled and that people need to be encouraged to keep up to date, it's just that there's a lopsided amount of focus on them as a security vector from Mozilla.
    I must point out however, that javascript security at the moment seems to consist of an on-off switch on almost every browser in existence: there is no obvious way to set "I don't want that site to know where my mouse is for my privacy", "I don't want that site to dynamically load content because it slows my browser" or the sort.
    While there is CAPS ( http://www.mozilla.org/projects/security/components/ConfigPolicy.html ) it is not configurable from within the browser (and its existence at all is obfuscated) and considering a lot of javascript is obfuscated to discourage run-time modification (say using web development toolbars) or discourage CAPS usage, there's little way to know what exactly to use CAPS on without reverse engineering. The average user would not be able to do this.
    Javascript security needs to be more, much more than an on/off switch.

  • How do I download Adobe Flash Player on my MacBook Pro?  It says that I have to disable my antivirus software but I never installed one. Does it come with the Mac in the first place?

    How do I download Adobe Flash Player on my MacBook Pro?  It says that I have to disable my antivirus software but I never installed one. Does it come with the Mac in the first place? If so, how can I disable it or get Adobe Flash Player?

    That message is just a standard one issued, mainly for Windows users, you can disregard it if you didn't install any anti-virus. (OS X has one installed by Apple that doesn't interfere)
    It's just some forms of anti-malware are really paranoid and lock the entire machine down. (like Norton)
    If you need assistance installing Flash
    How to install/uninstall Flash, fix problems
    How to uninstall/install software on your Mac

  • I have a few devices on one apple id and would like to switch out one of my phones so they have there own apple id do I have to restore the phone as new or can i somehow switch it without losing all apps and music in iTunes

    I have a few devices on one apple id and would like to switch out one of my phones so they have there own apple id do I have to restore the phone as new or can i somehow switch it without losing all apps and music in iTunes?

    Hello lynnettefromsk,
    The article linked below details all of the locations that you may need to change your Apple ID. This process should not affect the state of anything on the device at the time.
    Apple ID: What to do after you change your Apple ID
    http://support.apple.com/kb/HT5796
    Cheers,
    Allen

  • My iPod Touch 5th generation says disabled connect to itunes but when we connect to itunes it says on itunes that the ipod is locked with a passcode and to go onto the ipod and type in the passcode to proceed. What do I do

    My iPod Touch 5th generation says disabled connect to itunes but when we connect to itunes it says on itunes that the ipod is locked with a passcode and to go onto the ipod and type in the passcode to proceed but the ipod is still locked. what do i do?

    http://support.apple.com/kb/HT1212

  • HT201263 After I installed the iOS 7 software on my iPhone 5 it asked me for a passcode number. I do not have a passcode number. Now the device is disabled. I spent hours on the phone with Apple. following all steps to make a forced restore. It didn't wor

    I downloaded iOS 7 to my iPhone 5. On the process I must have put in an unknown passcode. Now the phone is disabled. I spent hours on the phone with Apple tech tech help. It told me to do a forced restore. I have not had success doing that. I tuned does not recognize the device   It is still disabled. HELP

    See Here  >  http://support.apple.com/kb/HT1808
    You may need to try this More than Once...
    Be sure to Follow ALL the Steps...
    Some users have reported that as many as 8 or 9 attempts were necassary before success.
    Take your time and pay particular attention to Steps 3 and 4...
    However...
    if the Device has been Modified... this will Not necessarily work.

  • HT201263 so my friend disabled my ipod to the point that the ipod said "iPod disabled connect to iTunes" but my computer wont connect to iTunes beacuse iTunes is saying that it's not connected to the internet when my interenet is working just fine, so wha

    So my friend had my iPod and he disabled it to where it said "iPod disabled connect to iTunes" but my computer will not connect to iTunes and I really need to know if there's a way I can restore my iPod?

    Restore, if iTunes will let you.  Everything except the password will be restored.  Connect via cable to the computer that you use for sync.  Be forewarned that it takes a long time.  From iTunes, select the iPad/iPod and then select the Summary tab.  Follow directions for Restore and be sure to say "yes" to the backup.  You will be warned that all data (apps, music, movies, etc.) will be erased but, as the Restore finishes, you will be asked if you wish the contents of the backup to be copied to the iPad/iPod.  Again, say "yes."
    At the end of the basic Restore, you will be asked if you wish to sync the iPad/iPod.  As before, say "yes."  Note that that sync selection will disappear and the Restore will end if you do not respond within a reasonable time.  If that happens, only the apps that are part of the IOS will appear on your device.  Corrective action is simple -  choose manual "Sync" from the bottom right of iTunes.
    If you're unable to do the Restore, go into Recovery Mode per the instructions here.

  • I have made many purchase on app but when i want to made an in-app purchase of a game, it appears "your purchase could not be completed". i have disabled the restriction already but it still doesn't work. anyone can give a hint or a hand here?  cheers~~~

    i have made many purchase on app but when i want to made an in-app purchase of a game, it appears "your purchase could not be completed". i have disabled the restriction already but it still doesn't work. anyone can give a hint or a hand here?  cheers~~~

    http://www.apple.com/support/itunes/contact/

  • I tried changing my password, and it changed to one that wasnt it, and i dont know it. So i tried it too many times and now its saying it is disabled, connect to itunes. but a problem is that my power button on top is broken. how to i fix it?

    I tried changing my password, and it changed to one that wasnt it, and i dont know it. So i tried it too many times and now its saying it is disabled, connect to itunes. but a problem is that my power button on top is broken. how to i fix it?

    Disabled
    Place the iOS device in Recovery Mode and then connect to your computer and restore via iTunes. The iPod will be erased.
    iOS: Wrong passcode results in red disabled screen                         
    If recovery mode does not work try DFU mode.                        
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings        
    For how to restore:
    iTunes: Restoring iOS software
    To restore from backup see:
    iOS: How to back up     
    If you restore from iCloud backup the apps will be automatically downloaded. If you restore from iTunes backup the apps and music have to be in the iTunes library since synced media like apps and music are not included in the backup of the iOS device that iTunes makes.
    You can redownload most iTunes purchases by:
    Downloading past purchases from the App Store, iBookstore, and iTunes Store        

Maybe you are looking for

  • Foreign key fields not getting populated in datacontrol palette for EJB app

    Hi, I am quite new to ADF and EJB.I developed a jdeveloper application with JSF and EJB tiers.(I am using jdeveloper 10.1.3.5) For database the default HR database is used.I created the entities for the EMPLOYEES and DEPARTMENTS table. I also created

  • Can't import videos on iPad into Aperture

    Using the camera connection kit, I've transferred photos and video from my SD card to my iPad. Both videos and photos show up fine there. When I try to use Aperture to import the photos from the iPad, the videos don't show up in the import screen, on

  • SNMP Agent for Solaris

    We're looking for a direction regarding an SNMP agent for our Solaris Platforms. The standard agent bundled with Solaris seems to have many issues and CERT outstanding advisories. I'm wondering what others out there are running, Net-SNMP?, the ESD ag

  • Does nano work with PodFreq?

    Hi, I just got a 4G black iPod nano last week, and I want to use it in my car. Too bad, I only have radio and CD player in my car, so FM transmitter seems to be the best solution for me. I know that the iTrip won't work with nano since the nano doesn

  • RequestFocus in JTextField

    I am not able to get the focus in my JTextField, when I run the following in an appletviewer: import javax.swing.*; public class TestClass extends JApplet {      JLabel label1;      JTextField tx;      JPanel panel;      public void init()