Start a Conversation

Unsolved

D

1 Message

108

January 25th, 2023 02:00

Dot1X - N2048P

Hi all,

 

I'm testing Clearpass Policy server and NAC. 

Would anyone be able to review this config and see if it looks ok? We do have laptops plugged into IP Phones, which plug into the network, but are replacing deskphones soon, so have disabled auth on that

We seem to have an issue when a laptop is disconnected and reconnected straight away, it takes a while to actually contact the NAC again. The ethernet adaptor doesn't seem to actually send authentication against Clearpass so wondering if it's a switch timer issue.


spanning-tree portfast
switchport mode general
switchport general pvid 10
switchport general allowed vlan add 10
switchport general allowed vlan add 100 tagged
switchport general allowed vlan remove 1
authentication host-mode multi-domain
authentication max-users 4
authentication periodic
authentication timer restart 40
dot1x timeout quiet-period 30
dot1x timeout supp-timeout 10
dot1x timeout tx-period 10
dot1x max-req 5
mab
authentication order dot1x mab
authentication priority dot1x mab
switchport voice vlan 100
switchport voice vlan override-authentication

 

Thanks very much!

No Responses!
No Events found!

Top