<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029573#M23881</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In MAB, authentication use Internal Endpoint where&amp;nbsp;&lt;STRONG&gt;If user not found "CONTINUE"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It will move to authorization policy. MAC address gets added in ISE database&amp;nbsp;as per profiled Endpoint.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Even if it doesn't match any profiling policy, it will&amp;nbsp;become part of Unknown endpoint.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate helpful posts!!!!!&lt;/P&gt;</description>
    <pubDate>Mon, 20 Feb 2017 21:00:23 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2017-02-20T21:00:23Z</dc:date>
    <item>
      <title>MAB Authentication operation and its interaction with Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029572#M23880</link>
      <description>&lt;P&gt;We are using a default Wired_MAB configuration.&lt;/P&gt;
&lt;P&gt;As I understand it a device tries to authenticate and as part of this the identity store i.e. the local internal identity store is queried.&lt;/P&gt;
&lt;P&gt;If this is a new device it isn't in the Identity Store, however our new device seems to get added.&lt;/P&gt;
&lt;P&gt;Is it the case that authentication proceeds after MAB with ISE continuing to Authorization Rules, if a device passes profiling it is added to the Identity Store and having been added, at THAT point authentication can now be successful?&lt;/P&gt;
&lt;P&gt;It has always seemed&amp;nbsp;odd to me that there does not seem to be a failure&amp;nbsp;condition within Authentication for MAB devices, however if a device fails to profile i.e. Authorize, it also fails authentication.&lt;/P&gt;
&lt;P&gt;Can someone clarify this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029572#M23880</guid>
      <dc:creator>bbriggs</dc:creator>
      <dc:date>2019-03-11T07:28:48Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029573#M23881</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In MAB, authentication use Internal Endpoint where&amp;nbsp;&lt;STRONG&gt;If user not found "CONTINUE"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It will move to authorization policy. MAC address gets added in ISE database&amp;nbsp;as per profiled Endpoint.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Even if it doesn't match any profiling policy, it will&amp;nbsp;become part of Unknown endpoint.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate helpful posts!!!!!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 21:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029573#M23881</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-20T21:00:23Z</dc:date>
    </item>
    <item>
      <title>Please rate as correct if it</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029574#M23882</link>
      <description>&lt;P&gt;Please rate as correct if it helps!!!!&lt;/P&gt;
&lt;P&gt;Also let me know if you have any concerns on this thread...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 21:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029574#M23882</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-20T21:23:49Z</dc:date>
    </item>
    <item>
      <title>Thanks for that. That's a</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029575#M23883</link>
      <description>&lt;P&gt;Thanks for that. That's a great help.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029575#M23883</guid>
      <dc:creator>bbriggs</dc:creator>
      <dc:date>2017-02-22T17:56:00Z</dc:date>
    </item>
    <item>
      <title>Your Welcome!!!!!</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029576#M23884</link>
      <description>&lt;P&gt;Your Welcome!!!!!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 18:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/3029576#M23884</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-02-22T18:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Your Welcome!!!!!</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/4119957#M561742</link>
      <description>&lt;P&gt;Hi, appreciate this is now an old thread but wondering if you can help me, i have the exact same query as above.&amp;nbsp; I don't want the MAC address to be auto-populated into the inventory in the case where the device is unknown it should remain unknown and rejected.&amp;nbsp; Any idea's how i can resolve this?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 14:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-operation-and-its-interaction-with/m-p/4119957#M561742</guid>
      <dc:creator>JonMoss92624</dc:creator>
      <dc:date>2020-07-16T14:15:00Z</dc:date>
    </item>
  </channel>
</rss>

