<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client trying MAB first then dot1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/client-trying-mab-first-then-dot1x/m-p/3728364#M25126</link>
    <description>&lt;P&gt;Read&amp;nbsp;the following document. It will give you some good examples:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html" rel="nofollow noopener noreferrer" target="_blank"&gt;Flexible Authentication Order, Priority, and Failed Authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change the policy order as dot1x &amp;amp; mab.&amp;nbsp;Also change this&amp;nbsp;authentication order &lt;STRONG&gt;dot1x mab&amp;nbsp;&lt;/STRONG&gt;in port configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aravind&lt;/P&gt;</description>
    <pubDate>Fri, 19 Oct 2018 03:56:40 GMT</pubDate>
    <dc:creator>Aravind Ravichandran</dc:creator>
    <dc:date>2018-10-19T03:56:40Z</dc:date>
    <item>
      <title>Client trying MAB first then dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/client-trying-mab-first-then-dot1x/m-p/3728201#M25125</link>
      <description>&lt;P&gt;I'm wondering what I have wrong here. We have 802.1x clients trying MAB and registering a failed authentication on our NPS servers. The ports have a Cisco phone (authenticating via MAB) and a windows 10 PC (authenticating using dot1x)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Policy order on the NPS server:&lt;/STRONG&gt;&lt;BR /&gt;MAB (for phones)&lt;BR /&gt;dot1x (for pc's)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Port config is:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/6&lt;BR /&gt;&amp;nbsp;description PORT 1 OFFICE 1&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 250&lt;BR /&gt;&amp;nbsp;authentication event fail retry 0 action authorize vlan 100&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 200&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 100&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe that the 802.1x client will send an eapol message which will prioritise the dot1x so it's possible the client will try MAB first but will switch to dot1x upon the eapol frame being received.&lt;/P&gt;
&lt;P&gt;I'm wondering if this is what is causing the MAB authentication failure being logged eg MAB failing before dot1x authenticates?&lt;/P&gt;
&lt;P&gt;Am I missing any obvious timer etc in the above config?&lt;/P&gt;
&lt;P&gt;Should I change the NPS order?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 20:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-trying-mab-first-then-dot1x/m-p/3728201#M25125</guid>
      <dc:creator>louis0001</dc:creator>
      <dc:date>2018-10-18T20:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Client trying MAB first then dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/client-trying-mab-first-then-dot1x/m-p/3728364#M25126</link>
      <description>&lt;P&gt;Read&amp;nbsp;the following document. It will give you some good examples:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html" rel="nofollow noopener noreferrer" target="_blank"&gt;Flexible Authentication Order, Priority, and Failed Authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change the policy order as dot1x &amp;amp; mab.&amp;nbsp;Also change this&amp;nbsp;authentication order &lt;STRONG&gt;dot1x mab&amp;nbsp;&lt;/STRONG&gt;in port configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Aravind&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 03:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-trying-mab-first-then-dot1x/m-p/3728364#M25126</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-10-19T03:56:40Z</dc:date>
    </item>
  </channel>
</rss>

