<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAC and username in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-and-username/m-p/1831426#M217457</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you implement Wired 802.1x the flow should be as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Plug the machine to the switchport.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The switch sends an EAPoL Start message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.1) If the machine is 802.1x compliant (supports EAP methods) the EAP negotion will start. The machine will be prompt for username/password (PEAP) or the appropriate certificate (EAP-TLS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.2) If the machine is not 802.1x compliant (does not support EAP) then the Switch EAPoL start will time out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) The switch configuration will detect the EAPoL timeout and "fallback" to the next configured method, which in this case, should be MAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) The machine that failed to respond the EAPoL Start will then provide username/password both as the device MAC Address. MAB credentials will be passed to the authentication server for validation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: 802.1x and MAB will never occur at the same time for the same machine/device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the attached .pdf file for additional information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this was helpful please rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Feb 2012 19:35:19 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2012-02-08T19:35:19Z</dc:date>
    <item>
      <title>MAC and username</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-and-username/m-p/1831425#M217456</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;we have a large network and the policy of company is combination of MAC address + username (dot1X)&lt;/P&gt;&lt;P&gt;Do we have any kind of solution for combination of mac address and username on our switch?&lt;/P&gt;&lt;P&gt;I mean when the computer plug to the port , it checks for mac address and username both is same time&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-and-username/m-p/1831425#M217456</guid>
      <dc:creator>networkware</dc:creator>
      <dc:date>2019-03-11T01:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: MAC and username</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-and-username/m-p/1831426#M217457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you implement Wired 802.1x the flow should be as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Plug the machine to the switchport.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The switch sends an EAPoL Start message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.1) If the machine is 802.1x compliant (supports EAP methods) the EAP negotion will start. The machine will be prompt for username/password (PEAP) or the appropriate certificate (EAP-TLS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.2) If the machine is not 802.1x compliant (does not support EAP) then the Switch EAPoL start will time out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) The switch configuration will detect the EAPoL timeout and "fallback" to the next configured method, which in this case, should be MAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) The machine that failed to respond the EAPoL Start will then provide username/password both as the device MAC Address. MAB credentials will be passed to the authentication server for validation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: 802.1x and MAB will never occur at the same time for the same machine/device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the attached .pdf file for additional information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this was helpful please rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 19:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-and-username/m-p/1831426#M217457</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-02-08T19:35:19Z</dc:date>
    </item>
  </channel>
</rss>

