Re: 7962 phones shutdown due to DOT1x violation

From: Daniel Haun <haundh_at_ah.org>
Date: Tue, 22 Jun 2010 08:40:19 -0700

Are you using the 802.1x passthrough feature, where the phone's downstream switchport uses 802.1x but the phone itself just uses CDP? I believe that's known to not work in the 8.5 phone firmware. I had to upgrade my 7961 phones to 9.0.

Daniel
#22791

>>> olugbenga lasisi <logpoet_at_gmail.com> 6/22/2010 7:49 AM >>>
Hi experts,

I have a number of 7962 phones conneceted to my switch and register wilth
the CUCM correctly, but lately i noticed that the phones get offline
occassionally and sends the error messages below to the syslog.

"Jun 18 11:43:36 c07switch 101925: 2986524: Jun 18 11:43:36.352 EDT:
%DOT1X-SP-5-SECURITY_VIOLATION: Security violation on interface FastEthe

rnet4/9, New MAC address 6416.8d50.b5eb is seen on the interface in mode

Jun 18 11:43:36 c07switch 101926: 2986525: Jun 18 11:43:36.352 EDT:
%PM-SP-4-ERR_DISABLE: security-violation error detected on Fa4/9, puttin

g Fa4/9 in err-disable state."

*It's weird 'cos the only thing i think might casue this is a bridge between
voice and data traffic. Any one has any clue on this?*

**

Gbenga*.*

Blogs and organic groups at http://www.ccie.net
Received on Tue Jun 22 2010 - 08:40:19 ART

This archive was generated by hypermail 2.2.0 : Sun Aug 01 2010 - 09:11:38 ART