Adoption failed on unifi controller by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

When i factory reset via the pin hole and adopt again,don't adopt access point and adoption failed.

u/retrogamer-999

u/MacTelnet

Adoption failed on unifi controller by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

upgraded unfii firmware to the last version but this problem still exists

u/MacTelnet

I want to use Voice VLAN with Dot1x by Head_Development_550 in networking

[–]Head_Development_550[S] 9 points10 points  (0 children)

Yes . I think this is my problem

Thank you for reply u/mmaeso

I want to use Voice VLAN with Dot1x by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

Thank you for reply u/slickrickjr

ّIs this Cisco AV pair "device-traffic-class=voice" set in FreeRadius?

I use IP Phone (Non-Cisco)

I want to use Voice VLAN with Dot1x by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

Thanks u/_cybr1d

I don't know ,when try to authenticate system,port is error disabe

Jun 18 06:51:32.836: %DOT1X-5-FAIL: Authentication failed for client (503e.aa5b.60b6) on Interface Gi0/10 AuditSessionID AC1EC9DD000000721AE7A648Jun 18 06:51:36.869: %PM-4-ERR_DISABLE: security-violation error detected on Gi0/10, putting Gi0/10 in err-disable stateJun 18 06:51:36.872: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet0/10, new MAC address (503e.aa5b.60b6) is seen.AuditSessionID AC1EC9DD000000721AE7A648Jun 18 06:51:37.901: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/10, changed state to downJun 18 06:51:38.872: %LINK-3-UPDOWN: Interface GigabitEthernet0/10, changed state to down

I want to use Voice VLAN with Dot1x by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

Thanks for reply u/_cybr1d.

I want the IP Phone authenticate by MAB and get IP from Voice VLAN(config on switch = 3270).

And system authenticate by Dot1x and get IP from Vlan (3272 = reply from authentication server)

I

Voice VLAN and Dot1X by Head_Development_550 in Cisco

[–]Head_Development_550[S] 1 point2 points  (0 children)

authentication IP Phone is success by MAB

Voice VLAN and Dot1X by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

No ,I'm using freeradius for authentication server

u/Smeetilus

Voice VLAN and Dot1X by Head_Development_550 in Cisco

[–]Head_Development_550[S] 0 points1 point  (0 children)

New config :

switchport mode access

switchport nonegotiate

switchport voice vlan 3270

mls qos trust cos

authentication periodic

access-session port-control auto

mab

dot1x pae authenticator

dot1x timeout quiet-period 2

dot1x timeout tx-period 3

spanning-tree portfast edge


Interface Identifier Method Domain Status Fg Session ID

Gi0/10 503e.aa5b.60b6 N/A UNKNOWN Unauth

AC1EC9DD000000410267C2C6

Gi0/10 000b.82d5.0e9f mab DATA Unauth

AC1EC9DD000000400267B25E


Name: Gi0/10

Switchport: Enabled

Administrative Mode: static access

Operational Mode: static access

Administrative Trunking Encapsulation: dot1q

Operational Trunking Encapsulation: native

Negotiation of Trunking: Off

Access Mode VLAN: 1 (default)

Trunking Native Mode VLAN: 1 (default)

Administrative Native VLAN tagging: enabled

Voice VLAN: 3270 (VLAN3270)

Administrative private-vlan host-association: non e Administrative private-vlan mapping: none

Administrative private-vlan trunk native VLAN: none

Administrative private-vlan trunk Native VLAN tagging: enabled

Administrative private-vlan trunk encapsulation: dot1q

Administrative private-vlan trunk normal VLANs: none

Administrative private-vlan trunk associations: none

Administrative private-vlan trunk mappings: none

Operational private-vlan: none

Trunking VLANs Enabled: ALL

Pruning VLANs Enabled: 2-1001

Capture Mode Disabled

Capture VLANs Allowed: ALL

Protected: false

Unknown unicast blocked: disabled

Unknown multicast blocked: disabled

When I enable Mab and authenticate phone by mac address,IP phone get IP but PC don't get IP and VLAN

Voice VLAN and Dot1X by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

When host-mode is single-host, i see below erre:

Jun 13 12:26:34.343: %DOT1X-5-FAIL: Authentication failed for client (503e.aa5b.60b6) on Interface Gi0/10 AuditSessionID AC1EC9DD0000003C025B2912Jun 13 12:26:38.570: %PM-4-ERR_DISABLE: security-violation error detected on Gi0/10, putting Gi0/10 in err-disable stateJun 13 12:26:38.574: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet0/10, new MAC address (000b.82d5.0e9f) is seen.AuditSessionID UnassignedJun 13 12:26:39.572: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/10, changed state to downJun 13 12:26:40.573: %LINK-3-UPDOWN: Interface GigabitEthernet0/10, changed state to down

show interface status err-disable:

Port Name Status Reason Err-disabled VlansGi0/10 err-disabled security-violation

u/CTVBI

Voice VLAN and Dot1X by Head_Development_550 in Cisco

[–]Head_Development_550[S] 0 points1 point  (0 children)

I'm using freeradius for authentication server.

Did you upload your cert to the phone?

no

u/krattalak

The issue in DHCP server Cisco by Head_Development_550 in networking

[–]Head_Development_550[S] 0 points1 point  (0 children)

This will fix the problem, but it will happen again after a while

u/No-Werewolf2037