<div dir="ltr"><div>The vendor listed for that MAC address is Dell. <a href="http://www.coffer.com/mac_find/?string=00%3A21%3A70%3Ac8%3A58%3Acb">http://www.coffer.com/mac_find/?string=00%3A21%3A70%3Ac8%3A58%3Acb</a></div>
<div> </div><div>Perhaps you have someone or someones trying to plug a laptop into the phone. That would explain why the switch sees a second mac and why the port is put into err-disable and is in single host mode.</div>
</div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, Jun 19, 2013 at 2:48 PM, <span dir="ltr"><<a href="mailto:george.hendrix@l-3com.com" target="_blank">george.hendrix@l-3com.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" vlink="purple" link="blue">
<div>
<p class="MsoNormal">Hey guys,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"> We have an issue what seems to be mostly on 3560/3750 and older 4500 switches. We have not had the issue at all on any phone connected to our 4510s with Sup-7 engines. At random when the phone/client is already connected to the switch,
the port goes into err-disable. The ports are in single host mode.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">interface FastEthernet1/0/5<u></u><u></u></p>
<p class="MsoNormal">switchport access vlan 2<u></u><u></u></p>
<p class="MsoNormal">switchport mode access<u></u><u></u></p>
<p class="MsoNormal">switchport voice vlan 3<u></u><u></u></p>
<p class="MsoNormal">srr-queue bandwidth share 10 10 60 20<u></u><u></u></p>
<p class="MsoNormal">srr-queue bandwidth shape 10 0 0 0<u></u><u></u></p>
<p class="MsoNormal">priority-queue out<u></u><u></u></p>
<p class="MsoNormal">authentication event server dead action authorize<u></u><u></u></p>
<p class="MsoNormal">authentication event server alive action reinitialize<u></u><u></u></p>
<p class="MsoNormal">authentication port-control auto<u></u><u></u></p>
<p class="MsoNormal">authentication periodic<u></u><u></u></p>
<p class="MsoNormal">mls qos trust cos<u></u><u></u></p>
<p class="MsoNormal">no snmp trap link-status<u></u><u></u></p>
<p class="MsoNormal">dot1x pae authenticator<u></u><u></u></p>
<p class="MsoNormal">dot1x timeout server-timeout 30<u></u><u></u></p>
<p class="MsoNormal">spanning-tree portfast<u></u><u></u></p>
<p class="MsoNormal">spanning-tree bpduguard enable<u></u><u></u></p>
<p class="MsoNormal">spanning-tree guard loop<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The error I see in the log before the port goes err-disable is below:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Security violation on the interface GigabitEthernet0/23, new MAC address (0021.70c8.58cb) is seen.AuditSessionID Unassigned<u></u><u></u></p>
<p class="MsoNormal">security-violation error detected on Gi0/23, putting Gi0/23 in err-disable state<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The switch seems to be treating the phone like a new DATA client.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">TAC seems to think possibly the phone is not transmitting CDP long enough that the switch puts the phone mac address into the DATA group and when it does, it err-disables the port.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Has anyone else seen this happen with firmware version SCCP 9.3.1.1 on 7962 model phones?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
<p class="MsoNormal"><span style="font-family:"Arial","sans-serif";font-size:12pt">Bill
</span><span style="color:gray;font-size:12pt"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<br>_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a><br>
<a href="https://puck.nether.net/mailman/listinfo/cisco-voip" target="_blank">https://puck.nether.net/mailman/listinfo/cisco-voip</a><br>
<br></blockquote></div><br></div>