<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB and dot1x Authentication by different Radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-and-dot1x-authentication-by-different-radius/m-p/3051338#M23308</link>
    <description>&lt;P&gt;Hello fellows,i need to do something strange. Here's my scenario, i have a freeradius with mysql for authentication and vlan assignment &amp;nbsp;with mab, but now i need the endpoints than support EAPoL (windows machines, maybe some printers, etc) to authenticate against dot1x (username and pass) not mab anymore. MySQL database has mac address of all my device but domain controller has all users. So my question is&amp;nbsp;if exist a method that authenticator (switch) can recognize mab or dot1x authentication method and send access request packet to different radius, in case of MAB to freeradius and mysql in case of dot1x to Domain controller with NPS role enabled. If this cannot be done i must figure it out how can freeradius query ldap or AD and mysql simiultaneously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:35:25 GMT</pubDate>
    <dc:creator>stefparaskevakis</dc:creator>
    <dc:date>2019-03-11T07:35:25Z</dc:date>
    <item>
      <title>MAB and dot1x Authentication by different Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-and-dot1x-authentication-by-different-radius/m-p/3051338#M23308</link>
      <description>&lt;P&gt;Hello fellows,i need to do something strange. Here's my scenario, i have a freeradius with mysql for authentication and vlan assignment &amp;nbsp;with mab, but now i need the endpoints than support EAPoL (windows machines, maybe some printers, etc) to authenticate against dot1x (username and pass) not mab anymore. MySQL database has mac address of all my device but domain controller has all users. So my question is&amp;nbsp;if exist a method that authenticator (switch) can recognize mab or dot1x authentication method and send access request packet to different radius, in case of MAB to freeradius and mysql in case of dot1x to Domain controller with NPS role enabled. If this cannot be done i must figure it out how can freeradius query ldap or AD and mysql simiultaneously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-and-dot1x-authentication-by-different-radius/m-p/3051338#M23308</guid>
      <dc:creator>stefparaskevakis</dc:creator>
      <dc:date>2019-03-11T07:35:25Z</dc:date>
    </item>
    <item>
      <title>I believe this can be done</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-and-dot1x-authentication-by-different-radius/m-p/3051339#M23310</link>
      <description>&lt;P&gt;I believe this can be done with IBNS 2.0 -&amp;nbsp;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-729965.html&lt;/P&gt;
&lt;P&gt;Check Cisco live online library, there is a good presentation on IBNS 2.0. This was introduced from IOS version 15.2&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 13:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-and-dot1x-authentication-by-different-radius/m-p/3051339#M23310</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-04-03T13:49:12Z</dc:date>
    </item>
  </channel>
</rss>

