Wednesday, October 17, 2018

802.1x CoA with MDA (pc behind a phone) and remidiation\mitigation vlan.

Hi, Trying to find a proper solution i came across when deploying the following topology : Pc->phone->switch both endpoints are authorized using 802.1x eap-tls. During posture evaulation for pc's it is some time needed to send a CoA to the authenticating port in order to bounce the port hence moving he pc to miigation vlan. My problem is that the CoA action only flaps the port, causing both the phone and the pc to reauthenticate BUT the pc stays with the same address. The phone itself ispowered by poe and therefore my pc can't sense the port bounce command. Now my pc is stuck on remediation vlan without any connectiviy :/

Can yout hink on some workaround for that?



No comments:

Post a Comment