<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB Configuration Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025407#M147577</link>
    <description>&lt;P&gt;with acs 4.2 installed in my network,&amp;nbsp;&amp;nbsp; PEAP, EAP-TLS, md5... authentications work normally.&amp;nbsp; But Mac-Based-Authentication&amp;nbsp;&amp;nbsp; doesnt work at all.&amp;nbsp; i tested every thing but no luck .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what i have setup on Swith for MAB:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default none&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;radius-server host 192.168.2.16 auth-port 1645 acct-port 1646 key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;dot1x mac-auth-bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS server, i created Netword-Profile for MAB, i added those Agentless hosts mac-adds,&amp;nbsp;&amp;nbsp; Even i created User-Name&amp;amp;password by those Agentless hosts mac-adds on acs,&amp;nbsp;&amp;nbsp; ..... still nothing seems to be working.&amp;nbsp;&amp;nbsp; i have selected ACS_Internal-Database for mac authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS while i check the&amp;nbsp;&amp;nbsp; Failed-attempt log, nothing is logged there.&amp;nbsp; i dont know where is the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please tell me where im wrong on my config?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:42:10 GMT</pubDate>
    <dc:creator>Imran Ahmad</dc:creator>
    <dc:date>2019-03-11T02:42:10Z</dc:date>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025407#M147577</link>
      <description>&lt;P&gt;with acs 4.2 installed in my network,&amp;nbsp;&amp;nbsp; PEAP, EAP-TLS, md5... authentications work normally.&amp;nbsp; But Mac-Based-Authentication&amp;nbsp;&amp;nbsp; doesnt work at all.&amp;nbsp; i tested every thing but no luck .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what i have setup on Swith for MAB:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default none&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;radius-server host 192.168.2.16 auth-port 1645 acct-port 1646 key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;dot1x mac-auth-bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS server, i created Netword-Profile for MAB, i added those Agentless hosts mac-adds,&amp;nbsp;&amp;nbsp; Even i created User-Name&amp;amp;password by those Agentless hosts mac-adds on acs,&amp;nbsp;&amp;nbsp; ..... still nothing seems to be working.&amp;nbsp;&amp;nbsp; i have selected ACS_Internal-Database for mac authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS while i check the&amp;nbsp;&amp;nbsp; Failed-attempt log, nothing is logged there.&amp;nbsp; i dont know where is the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please tell me where im wrong on my config?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025407#M147577</guid>
      <dc:creator>Imran Ahmad</dc:creator>
      <dc:date>2019-03-11T02:42:10Z</dc:date>
    </item>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025408#M147578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After long investigation,&amp;nbsp; i found that&amp;nbsp;&amp;nbsp; Agentless hosts are authenticated but&amp;nbsp; after 10-minutes.&amp;nbsp;&amp;nbsp;&amp;nbsp; i mean it takes&amp;nbsp; arround&amp;nbsp; 10-minutes to authenticate&amp;nbsp;&amp;nbsp;&amp;nbsp; agentless hosts .&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any expert knows where is the issue ????&lt;/P&gt;&lt;P&gt;But with other authentication methods like&amp;nbsp; peap, eap-tls&amp;nbsp; my acs works/authenticates very fast.&lt;/P&gt;&lt;P&gt;any idea, why it is taking 10-minutes to auth ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 07:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025408#M147578</guid>
      <dc:creator>Imran Ahmad</dc:creator>
      <dc:date>2012-10-23T07:56:42Z</dc:date>
    </item>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025409#M147579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Imran. I am doing some reading/research in preparation for implementing 802.1X/ISE on our network. I think the reason you are seeing a delay is that by default your settings are looking for dot1x authentication first and only if the ACS receives no response to the EAP requests will MAB kick in. So, I think you need to adjust your EAP authentication times and/or change the authentication order so that it checks MAB first then dot1x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 19:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025409#M147579</guid>
      <dc:creator>Inayat Bunglawala</dc:creator>
      <dc:date>2012-10-23T19:16:38Z</dc:date>
    </item>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025410#M147580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Inayat,&lt;/P&gt;&lt;P&gt;Yes you were right.&amp;nbsp;&amp;nbsp; i changed the&amp;nbsp; auth-timeouts, and it is authenticating MAB-clients very fast.&amp;nbsp; &lt;/P&gt;&lt;P&gt;Thank you for your support&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need a user-guide on how to Setup Authentication for Wireless users,&amp;nbsp; we have agentfull and agentless wireless-hosts (having Iphones...).&amp;nbsp;&amp;nbsp; so the authentication methods will be&amp;nbsp; md5, eap-tls and&amp;nbsp; mab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will use&amp;nbsp; (LinkSys-Wireless Router)&amp;nbsp; as the authenticator for wireless-hosts ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;I need a user-guide for&amp;nbsp; how to setup the wireless-hosts( supplicants)&amp;nbsp; and how to setup&amp;nbsp; Link-Sys&amp;nbsp; and the Cisco-Switch in the middle.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if you have any link, plz refer me&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 11:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025410#M147580</guid>
      <dc:creator>Imran Ahmad</dc:creator>
      <dc:date>2012-10-24T11:44:53Z</dc:date>
    </item>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025411#M147581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best step by step documentation guide I have found for implementing 802.1X/ISE is here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns744/landing_DesignZone_TrustSec.html"&gt;http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns744/landing_DesignZone_TrustSec.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgrds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inayat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 11:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025411#M147581</guid>
      <dc:creator>Inayat Bunglawala</dc:creator>
      <dc:date>2012-10-25T11:46:44Z</dc:date>
    </item>
    <item>
      <title>MAB Configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025412#M147582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the sample configuration you need&amp;nbsp; to have on switch interface for MAB to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;BR /&gt;description&amp;nbsp; IP Phone + PC&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode&amp;nbsp; access&lt;BR /&gt;switchport voice vlan 40&lt;BR /&gt;ip access-group ACL-ALLOW&amp;nbsp; in&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication&amp;nbsp; open&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x&amp;nbsp; mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication&amp;nbsp; periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae&amp;nbsp; authenticator&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-configuration-issue/m-p/2025412#M147582</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2013-07-15T08:50:39Z</dc:date>
    </item>
  </channel>
</rss>

