- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PORT PROFILE NOT WORKING FOR ALL CONNECTED PORTS FOR SAME VLAN.
Hi, I have set an access port profile which works for most of the devices connected to the ports of Meraki( port is green and there is comms happening) switch on same VLAN but does not work for some devices(port is stuck on alerting mode). The port has a message " PORT NOT FORWARDING DUE TO ACCESS POLICY" It works though when the port profile is disable for that port and kept open(port is green and there is comms happening) and the VLAN info are registered manually. IS there a way to fix this issue?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does that port profile have an access policy configured?
And if so, what is the configuration of that access policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Brash,
Yes it is set to Wired Authentication under Access type and RSTP enabled and STP guard disabled. This profile works for different types of devices throughout the switches but does not work for some devices.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By wired authentication I am assuming you mean 802.1x. If so what type of device is plugged into it as it needs to be a device that supports 802.1x
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes , its 802.1x. I have devices like power distribution units and AMX connected to it. There are 3 different models of power distribution units connected to it. The profiling works for AMX and 1 model of power distribution unit but does not work for other two.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Basically those devices are failing the 802.1x authentication, so are effectively being disconnected, to keep your network secure. Have you put some kind of provision/setup in your RADIUS server (and/or the device) for how those devices are to be authenticated? You need something for any/every device type connected to a port with that profile.
