<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Start with reading the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018336#M24139</link>
    <description>&lt;P&gt;Start with reading the following document. It will give you some good examples:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html"&gt;Flexible Authentication Order, Priority, and Failed Authentication&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2017 07:11:34 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2017-02-03T07:11:34Z</dc:date>
    <item>
      <title>Flexible Authentication Order, Priority Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018335#M24138</link>
      <description>&lt;P&gt;Can someone out here please explain the meaning of below&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;interface &amp;lt;interface_number&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;authentication order mab dot1x &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;authentication priority dot1x mab&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier New';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;what is the real-time use of order and priority commands ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Is it mandatory to have priority command ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Please give some real-life exmaples&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018335#M24138</guid>
      <dc:creator>prashant dwivedi</dc:creator>
      <dc:date>2019-03-11T07:26:02Z</dc:date>
    </item>
    <item>
      <title>Start with reading the</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018336#M24139</link>
      <description>&lt;P&gt;Start with reading the following document. It will give you some good examples:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html"&gt;Flexible Authentication Order, Priority, and Failed Authentication&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 07:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018336#M24139</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-02-03T07:11:34Z</dc:date>
    </item>
    <item>
      <title>Here is my understanding , if</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018337#M24140</link>
      <description>&lt;P&gt;Here is my understanding , if someone would like to comment and confim if this is correct&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;Use case 1 :&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication order mab dot1x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication priority dot1x mab&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;Result- first client will do MAB ( if this passed ) then will do the dot1x. If MAB auth failed&amp;nbsp; &amp;nbsp;then also do the dot1x. Negative side of this is that each and every device has to go through MAB process- overhead on ISE . if DOT1x is not successful it will get the policy as configured for MAB. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;Use Case 2- &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication order mab dot1x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication priority mab Dot1x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;MAB failed , it will go to Dot1x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;MAB passed- it will not go to DOT1x.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;Use Case 3- &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication order dot1x mab&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;authentication priority mab Dot1x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;End-point will do Dot1x, will only go to MAB if DOT1x Fails.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif'; color: #004b8d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 05:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3018337#M24140</guid>
      <dc:creator>prashant dwivedi</dc:creator>
      <dc:date>2017-02-06T05:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Here is my understanding , if</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3729052#M24141</link>
      <description>&lt;P&gt;Could anyone confirm that if:&lt;/P&gt;
&lt;P&gt;order mab dot1x&lt;/P&gt;
&lt;P&gt;priority dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then a dot1x client will start up as mab but immediately be switched to dot1x upon sending an eapol frame?&lt;/P&gt;
&lt;P&gt;ie it doesn't have to fail the mab process to progress to dot1x and therefore the mab process won't fail due to the dot1x being sucessful?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Oct 2018 08:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3729052#M24141</guid>
      <dc:creator>louis0001</dc:creator>
      <dc:date>2018-10-20T08:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Here is my understanding , if</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3734071#M24142</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 03:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3734071#M24142</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-27T03:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Here is my understanding , if</title>
      <link>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3735905#M24143</link>
      <description>It depends on the policies, I prefer to do the dot1x first and if fails then do MAB.&lt;BR /&gt;If you have MAB policies that can "overlap" with dot1x policies then it might cause issues, e.g. MAB policy for workstation onboarding. &lt;BR /&gt;In most cases dot1x first works better for me.</description>
      <pubDate>Tue, 30 Oct 2018 20:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/flexible-authentication-order-priority-cisco-ise/m-p/3735905#M24143</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2018-10-30T20:12:30Z</dc:date>
    </item>
  </channel>
</rss>

