Hi Team
I have polycom phones configured to do 802.1x with Meraki MS 120. when i configure it in multi-domain or multi mode, the phone works and gets voice Vlan. but the laptops that connected to the phones keep getting auth - reathu.
I did a packet capture . I see the CiscoMer_cc:6b:14 source is keep sending request identity all the time. the destination is sending the identity reply.
I will add a screen capture of the Wireshark
any idea, please?
the only way this works is in multi host. but that is not what we want.
Solved! Go to solution.
I'm pretty sure your RADIUS server needs to be sending it to the switch, not the other way around. We use NPS and it sends the attribute with the radius accept. The bigger issue we had with poly devices was that our voip provider did not enable
Which caused issues with the devices behind the poly phones. Once they enabled them, all our issues went away.
Hi,
Have you tried multi-auth ( the last one ) ?
yes I have, the same issue. the only one that work is the multi host
Did you make sure you are sending the radius attribute noted in the config guide?
Multi-Domain
With multi-domain authentication, one device can be authenticated on each of the data and voice VLANs; if a second device is detected on one of the VLANs, the device will not be granted access. In this mode, Hybrid Authentication is used and Voice VLAN authentication is required. This mode is recommended for switchports connected to a phone with a device behind the phone. Authentication is independent on each VLAN and will not affect the forwarding state of each other.
Cisco Meraki switches require the following attribute pairs within the Access-Accept frame to put devices on the voice VLAN:
Cisco-AVPair
device-traffic-class=voice
Yes, we saw the raduis attribute in the packet capture. the meraki is sending it to ISE.
I'm pretty sure your RADIUS server needs to be sending it to the switch, not the other way around. We use NPS and it sends the attribute with the radius accept. The bigger issue we had with poly devices was that our voip provider did not enable
Which caused issues with the devices behind the poly phones. Once they enabled them, all our issues went away.
@bigben386 thank you for your reply , are those needs to be enabled on the polycom ?
Yes they all need to be enabled in the poly config for devices behind the poly to function properly. It helps inform the switch when devices connected behind the poly change.