Wired Intelligent Edge

 View Only
  • 1.  Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted Feb 10, 2025 04:50 PM

    Hi,

    I'm kinda out of ideas, So I'm hoping on some experiences from my fellow network engineers.

    Situation:
    Client asked to install some Mitel Phones on a new site. where we have UBT on Access switches and no vlan available on the switches. NAC with Clearpass and access devices are AOS-CX 6200

    Mitel 6863i Phone does reboot multiple times (3/4 times when fresh out-of-the box)

    There's an FTP server for firmware and it's getting there through SCOPE options when getting a DHCP adres.

    Everything fine so far, so Phone boots, gets an IP, downloads and installs firmware

    REBOOT

    And now the phone is stuck in a DHCP Discover and Offer loop. Phone does not Request a DHCP adress.

    After a ton of troubleshooting we can conclude Clearpass is not interfering. Phone gets authenticated, the phone gets a role and the phone keeps authenticated while rebooting.

    How do I know?

    After another ton of tests I disabled 802.1X configuration on the switch and the phone boots like a charm. :O.

    One step closer, So I started tested with several port options:

    aaa port-access onboarding-method concurrent enable

    aaa authentication port-access auth-precedence mac-auth dot1x

    aaa authentication port-access dot1x authenticator

    eapol-timeout X

    initial-auth-response-timeout X

    max-eapol-requests X

    max-retries X

    Several different values, different combinations. But nothing seems to work

    only difference with these extra options is that i can trigger some progress by manually rebooting the phone.

    Have been in a call with ERT egineers from Aruba (Clearpass/switching) no solution yet.



  • 2.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 29 days ago

    Could it be that your phones (after fully provisioned, upgraded to latest version) attempt 802.1X authentication but fail as they have not been configured correctly, or that ClearPass is not configured to handle 802.1X for those phones (client root CA imported, trusted for EAP)?

    It would help to see the show the 'show port-access clients 1/1/1 detail' (assuming phone connected on interface 1/1/1) when the issue happens to see the mac/802.1X status.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 29 days ago

    Also it would  help to look into Access Tracker record. Specifically in Output section. Is it possible that you send the wrong attribute values to the switch, like vlan that do not exist on switch? Maybe spelling of vlan name (been there, lost a lot of time)?

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 4.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 28 days ago

    we've gone through all Clearpass config with Aruba ERT Engineer 
    He told me Clearpass config was perfect as everything goes perfect in the initial boot. 

    phone never reauthenticates as the reboot does not disconnect the line. 




  • 5.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 22 hours ago

    @GorazdKikelj

    Have gone through Clearpass config with ARUBA Clearpass engineer, and we can conclude the roles are applied perfectly. 
    As the phone reboots, no reauthentication happens, so no further involvment of Clearpass. 

    KR

    Dylan 




  • 6.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 28 days ago

    Hi @Herman Robers

    I've checked with Wireshark to confirm, but no EAPOL has ever been sent and 802.1x is not enabled on the phone. 

    output: 

    6200#  sh port-acc clients interface 1/1/5 detail
     
    Port Access Client Status Details:
     
    RADIUS overridden user roles are suffixed with '*'
     
    Client 00:08:5d:b4:95:b0, 00085db495b0
    ======================================
      Session Details
      ---------------
        Port         : 1/1/5
        Session Time : 326925s
        IPv4 Address :
        IPv6 Address :
        Device Type  :
     
      VLAN Details
      ------------
        VLAN Group Name :
        VLANs Assigned  : 1720
          Access          : 1720
          Native Untagged :
          Allowed Trunk   :
     
      Authentication Details
      ----------------------
        Status          : mac-auth Authenticated
        Auth Precedence : mac-auth - Authenticated, dot1x - Not attempted
        Auth History    : mac-auth - Authenticated, 326925s ago
     
      MACsec Details
      --------------
        MKA Session Status :
        MACsec Status      :
     
      Authorization Details
      ----------------------
        Role   : DUR_CL_TEL_1x20_Untag-3148-8
        Status : Applied
     
     
    Role Information:
     
    Name  : DUR_CL_TEL_1x20_Untag-3148-8
    Type  : clearpass
    Status: Completed
    ----------------------------------------------
        Reauthentication Period             : 4294967295 secs
        Client Inactivity Timeout           : None
        Access VLAN Name                    : CL-TEL
        Policy                              : AllowAll_DUR_CL_TEL_1x20_Untag-3148-8
     
     
    Access Policy Details:
     
    Policy Name   : AllowAll_DUR_CL_TEL_1x20_Untag-3148-8
    Policy Type   : Downloaded
    Policy Status : Applied
    Base Policy   : N/A
    ACL Names     : N/A
     
    SEQUENCE    CLASS                        TYPE ACTION
    ----------- ---------------------------- ---- ----------------------------------
    10          AllTraffic_DUR_CL_TEL_1x2... ipv4 permit
     
     
    Class Details:
     
    class ip AllTraffic_DUR_CL_TEL_1x20_Untag-3148-8
        10 match any any any




  • 7.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 25 days ago

    I had a similar issue and the problem was the phones were sticking on their current configuration which was originally a tagged vlan.

    Phones also stuck on "discovering"

    After I cleared the phone configs  - like a factory reset of sorts on the phone they worked fine.

    I was moving away from tagged vlan to untagged at the time, but the tagged vlan config appeared to be "sticky" on the phones themselves.




  • 8.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 25 days ago

    Maybe run a port-mirror and see what is is happening on the interface and if the traffic is tagged or untagged and to get a clue where the mismatch is.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 22 hours ago

    @Herman Robers

    Done that, everything seems as it should be. 

    Traffic is definitly untagged as supposed to be. but Mitel Phone is not Requesting the IP. 

    At this moment we are looking to upgrade the firmware of the phones. As it looks like the firmware could be the issue. Other type doesn't have the problem. 

    Kind regards

    Dylan 




  • 10.  RE: Mitel not getting IP's when rebooting in iniatial setup (CPPM and AOS-CX)

    Posted 22 hours ago

    I think our test phones have been resetted about 75 times :) 
    But thanks for you input, could be useful for others.