<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE MAB Host Lookup - PAP or EAP-MD5 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048672#M184539</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cath-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question #1:&lt;/STRONG&gt; Yes, I think you are correct. I believe that the "Host Lookup" is type of "protocol" used to process the MAB. If you look at the top of the authenticaiton session what do you under "Authentication Protocol?" My guess is that you see "Lookup" (see attached screen shot)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question #2: &lt;/STRONG&gt;You can force the switch to use EAP-MD5 by appending &lt;SPAN style="text-decoration: underline;"&gt;"EAP" &lt;/SPAN&gt; to the &lt;SPAN style="text-decoration: underline;"&gt;"MAB"&lt;/SPAN&gt; command under the individual ports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface fa0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab eap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Things to conisider&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1) &lt;/STRONG&gt;If you make that change the default/built-in condition in ISE "&lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt;" will have to be changed since the &lt;/P&gt;&lt;P&gt;service-type radius attribute will change from "Call Check" to "Framed." Thus, your MAB devices can easily skip the MAB authenticaiton rule and be denied on the network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;2) &lt;/STRONG&gt;Because the MAC address is sent in the clear text&amp;nbsp; "Attribute 31" (Calling-Station-Id), MAB EAP does not offer any additional security by encrypting the MAC address in the password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;3) &lt;/STRONG&gt;Because the service type for MAB EAP is the same as an IEEE 802.1X request, the RADIUS server will not be able to easily differentiate MAB EAP requests from IEEE 802.1X requests&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good document that you can reference as well:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-663759.html"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-663759.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for rating!&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/6/0/109067-MAB.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Oct 2012 23:07:40 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2012-10-24T23:07:40Z</dc:date>
    <item>
      <title>ISE MAB Host Lookup - PAP or EAP-MD5</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048671#M184535</link>
      <description>&lt;P&gt;In the docs, it says that MAB uses PAP/ASCII or EAP-MD5 to pass the MAC as username / password.&lt;/P&gt;&lt;P&gt;In the attached setup, MAB is talking place successfully for an iPhone, without having PAP or EAP-MD5 enabled as Allowed Protocols.&amp;nbsp; &lt;/P&gt;&lt;P&gt;Is the "Host Lookup" under allowed protocols, provides for the MAC address to be passed in PAP / EAP-MD5 even if these two protocols are not enabled below under the Authentication Protocols section of the configuration?&lt;/P&gt;&lt;P&gt;How could we dictate to our switch to start using EAP-MD5 to pass the MAC?&amp;nbsp; If you look at the attached authentication details output, it lists in the AV Pair a EAP-Key.&amp;nbsp; Is that it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048671#M184535</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2019-03-11T02:43:01Z</dc:date>
    </item>
    <item>
      <title>ISE MAB Host Lookup - PAP or EAP-MD5</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048672#M184539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cath-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question #1:&lt;/STRONG&gt; Yes, I think you are correct. I believe that the "Host Lookup" is type of "protocol" used to process the MAB. If you look at the top of the authenticaiton session what do you under "Authentication Protocol?" My guess is that you see "Lookup" (see attached screen shot)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question #2: &lt;/STRONG&gt;You can force the switch to use EAP-MD5 by appending &lt;SPAN style="text-decoration: underline;"&gt;"EAP" &lt;/SPAN&gt; to the &lt;SPAN style="text-decoration: underline;"&gt;"MAB"&lt;/SPAN&gt; command under the individual ports:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface fa0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab eap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Things to conisider&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1) &lt;/STRONG&gt;If you make that change the default/built-in condition in ISE "&lt;STRONG&gt;Wired-MAB&lt;/STRONG&gt;" will have to be changed since the &lt;/P&gt;&lt;P&gt;service-type radius attribute will change from "Call Check" to "Framed." Thus, your MAB devices can easily skip the MAB authenticaiton rule and be denied on the network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;2) &lt;/STRONG&gt;Because the MAC address is sent in the clear text&amp;nbsp; "Attribute 31" (Calling-Station-Id), MAB EAP does not offer any additional security by encrypting the MAC address in the password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;3) &lt;/STRONG&gt;Because the service type for MAB EAP is the same as an IEEE 802.1X request, the RADIUS server will not be able to easily differentiate MAB EAP requests from IEEE 802.1X requests&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a good document that you can reference as well:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-663759.html"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/config_guide_c17-663759.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for rating!&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/6/0/109067-MAB.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 23:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048672#M184539</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-10-24T23:07:40Z</dc:date>
    </item>
    <item>
      <title>ISE MAB Host Lookup - PAP or EAP-MD5</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048673#M184546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the explanation and for the &lt;STRONG&gt;mab eap&lt;/STRONG&gt; command.&amp;nbsp; I didn't know.&lt;/P&gt;&lt;P&gt;Thanks also for the link to the MAB deployment guide.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cath.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 10:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-mab-host-lookup-pap-or-eap-md5/m-p/2048673#M184546</guid>
      <dc:creator>cpaquet</dc:creator>
      <dc:date>2012-10-25T10:55:56Z</dc:date>
    </item>
  </channel>
</rss>

