<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [Q] Identity Sequence issue causes MAB to auth against AD ?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866872#M267682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;1) Are you sure that the MAC Address 00-1B-78-00-33-00 had not been created as an AD Account?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I checked with the guy that manages the AD servers and he assures us there is no record anywhere of any mac addresses in AD. I have done my own search and cant find anything in there either. Also, the timestamps of these two authentication attempts are 09:36 and 10:36 (or something like that) and we know we definitely didnt make any changes to AD in that time window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) Which conditions have you defined under the Authorization Rule "MAB-PC"?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===== AUTHORIZATION POLICY =====&lt;/P&gt;&lt;P&gt;General&lt;BR /&gt;Name: MAB-PC&lt;BR /&gt;Status: Enabled&lt;/P&gt;&lt;P&gt;Conditions&lt;BR /&gt;[TICKED] NDG:Location in All Locations:AP&lt;BR /&gt;[NOT TICKED] AD1:ExternalGroups -ANY-&lt;BR /&gt;[TICKED] Compound Condition:&lt;BR /&gt;Dictionary AD-AD1 Attribute [blank]&lt;/P&gt;&lt;P&gt;Current Condition Set:&lt;BR /&gt;Internal Hosts:HostIdentityGroup in AllGroups:NoDot1xClient&lt;/P&gt;&lt;P&gt;Results&lt;BR /&gt;Authorization Profiles&lt;BR /&gt;MAB-PC&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;===== IDENTITY GROUP =====&lt;BR /&gt;Name: NoDot1xClient&lt;BR /&gt;Info: This group is assigned to all MAC address Hosts which do not have dot1x enabled.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;===== AUTHORIZATION PROFILE =====&lt;/P&gt;&lt;P&gt;Authorization Profile&lt;BR /&gt;Name: MAB-PC&lt;BR /&gt;Downloadable ACL Name - Static - Value [Permit-IP]&lt;BR /&gt;VLAN ID/Name - Static - User-trusted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===== Downloadable ACLs ======&lt;/P&gt;&lt;P&gt;Name - Permit-IP&lt;BR /&gt;Downloadable ACL Content: Permit IP Any Any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jan 2012 20:08:26 GMT</pubDate>
    <dc:creator>pmchandler</dc:creator>
    <dc:date>2012-01-16T20:08:26Z</dc:date>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866870#M267676</link>
      <description>&lt;P&gt;We have a strange issue whereby some users have suddenly failed to correctly authenticate against ACS 5.1 - we cant work out why, as nothing has changed and would greatly appreciate your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have dot1x configured on our network with MAB fallback. We havent yet rolled out dot1x to the clients even though the network is set up for this. In the meantime, we are using Mac Authentication Bypass. We do use 802.1x for wireless though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up the folowing Identity Sequence:&lt;/P&gt;&lt;P&gt;AD1 (this is set up as our AD servers for 802.1X user and machine auth)&lt;/P&gt;&lt;P&gt;SecurID Server (we dont use this yet either)&lt;/P&gt;&lt;P&gt;Internal Users (this is just used to authenticate ciscoworks)&lt;/P&gt;&lt;P&gt;Internal Hosts (this contains the list of allowed MAC addresses)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typically what we have seen today is a user initially authenticates successfully by matching the Internal Hosts identity store, but then an hour later, re-authentication fails as the MAC address matches the AD1 id store and subsequently fails due to the MAC address not being present within AD. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the successful connection entry (all MAC addresses substituted form the originals)...&lt;/P&gt;&lt;TABLE id="S1" style="empty-cells: show; width: 100%; font-family: sans-serif; font-size: small; margin-top: 5pt; margin-right: 0pt; margin-bottom: 0pt; margin-left: 0pt; border-top-style: none; border-top-color: #e3e3e3; border-right-style: solid; border-right-color: #808080; border-bottom-style: solid; border-bottom-color: #808080; border-left-style: solid; border-left-color: #808080; border-width: 1px;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000;" valign="middle"&gt;&lt;TH align="center" style="font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; border-top-color: #8499a2; border-right-color: #ffffff; border-bottom-color: #8499a2; border-left-color: #8499a2; background-color: #d9e3e9; border-width: 1px; border-style: solid;" valign="middle"&gt;&lt;P style="text-align: left; padding-top: 1pt;"&gt;Steps&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S2" style="empty-cells: show; width: 100%; font-family: sans-serif; font-size: small; border-top-style: none; border-top-color: #e3e3e3; border-right-style: solid; border-right-color: #808080; border-bottom-style: solid; border-bottom-color: #808080; border-left-style: solid; border-left-color: #808080; border-width: 1px; margin: 0pt;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11001&amp;nbsp; Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11017&amp;nbsp; RADIUS created a new session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11027&amp;nbsp; Detected Host Lookup UseCase (Service-Type = Call Check (10))&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Service Selection Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15012&amp;nbsp; Selected Access Service - Network Access&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Identity Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15006&amp;nbsp; Matched Default Rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15013&amp;nbsp; Selected Identity Store - Internal Hosts&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24412&amp;nbsp; User not found in Active Directory&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24559&amp;nbsp; Searching for user in the RSA identity store.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24556&amp;nbsp; User record was not found in the cache.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24210&amp;nbsp; Looking up User in Internal Users IDStore - 00-1B-78-00-33-00&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24216&amp;nbsp; The user is not found in the internal users identity store.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24209&amp;nbsp; Looking up Host in Internal Hosts IDStore - 00-1B-78-00-33-00&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24211&amp;nbsp; Found Host in Internal Hosts IDStore&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22037&amp;nbsp; Authentication Passed&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22023&amp;nbsp; Proceed to attribute retrieval&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24412&amp;nbsp; User not found in Active Directory&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22016&amp;nbsp; Identity sequence completed iterating the IDStores&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Group Mapping Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24423&amp;nbsp; ACS has not been able to confirm previous successful machine authentication for user in Active Directory&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Exception Authorization Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15042&amp;nbsp; No rule was matched&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Authorization Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15016&amp;nbsp; Selected Authorization Profile - MAB-PC&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11022&amp;nbsp; Added the dACL specified in the Authorization Profile&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11002&amp;nbsp; Returned RADIUS Access-Accept&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the failed connection entry....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S1" style="empty-cells: show; width: 100%; font-family: sans-serif; font-size: small; margin-top: 5pt; margin-right: 0pt; margin-bottom: 0pt; margin-left: 0pt; border-top-style: none; border-top-color: #e3e3e3; border-right-style: solid; border-right-color: #808080; border-bottom-style: solid; border-bottom-color: #808080; border-left-style: solid; border-left-color: #808080; border-width: 1px;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-family: arial; font-weight: bold; font-size: 10pt; color: #000000;" valign="middle"&gt;&lt;TH align="center" style="font-size: 10pt; padding-top: 1pt; padding-right: 2pt; padding-left: 2pt; border-top-color: #8499a2; border-right-color: #ffffff; border-bottom-color: #8499a2; border-left-color: #8499a2; background-color: #d9e3e9; border-width: 1px; border-style: solid;" valign="middle"&gt;&lt;P style="text-align: left; padding-top: 1pt;"&gt;Steps&lt;/P&gt;&lt;/TH&gt; &lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="S2" style="empty-cells: show; width: 100%; font-family: sans-serif; font-size: small; border-top-style: none; border-top-color: #e3e3e3; border-right-style: solid; border-right-color: #808080; border-bottom-style: solid; border-bottom-color: #808080; border-left-style: solid; border-left-color: #808080; border-width: 1px; margin: 0pt;"&gt;&lt;TBODY&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11001&amp;nbsp; Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11017&amp;nbsp; RADIUS created a new session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11027&amp;nbsp; Detected Host Lookup UseCase (Service-Type = Call Check (10))&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Service Selection Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15012&amp;nbsp; Selected Access Service - Network Access&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Identity Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15006&amp;nbsp; Matched Default Rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15013&amp;nbsp; Selected Identity Store - AD1&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24416&amp;nbsp; User's Groups retrieval from Active Directory succeeded&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22037&amp;nbsp; Authentication Passed&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22023&amp;nbsp; Proceed to attribute retrieval&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22038&amp;nbsp; Skipping the next IDStore for attribute retrieval because it is the one we authenticated against&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;22016&amp;nbsp; Identity sequence completed iterating the IDStores&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Group Mapping Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;24423&amp;nbsp; ACS has not been able to confirm previous successful machine authentication for user in Active Directory&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Exception Authorization Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15042&amp;nbsp; No rule was matched&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; background-color: #d9e3e9; text-decoration: underline; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;Evaluating Authorization Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15006&amp;nbsp; Matched Default Rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15016&amp;nbsp; Selected Authorization Profile - DenyAccess&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #000000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15039&amp;nbsp; Selected Authorization Profile is DenyAccess&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="color: #ff0000; padding-top: 1pt; padding-right: 2pt; padding-bottom: 1pt; padding-left: 2pt; border-top-style: none; border-bottom-style: none; border-width: thin; border-color: #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11003&amp;nbsp; Returned RADIUS Access-Reject&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866870#M267676</guid>
      <dc:creator>pmchandler</dc:creator>
      <dc:date>2019-03-11T01:43:44Z</dc:date>
    </item>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866871#M267680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure that the MAC Address 00-1B-78-00-33-00 had not been created as an AD Account? The succes logs show:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24412&amp;nbsp; User not found in Active Directory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the failure shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24416&amp;nbsp; User's Groups retrieval from Active Directory succeeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that the ACS was able to find the MAC Address 00-1B-78-00-33-00 on the AD Domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the failed authentication is due to the Authorization Rule. Which conditions have you defined under the Authorization Rule "MAB-PC"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Was the MAC Address created on the AD Domain as a valid account?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Which conditions are defined under the authorization rule MAB-PC in order to match it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 17:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866871#M267680</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-16T17:27:59Z</dc:date>
    </item>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866872#M267682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;1) Are you sure that the MAC Address 00-1B-78-00-33-00 had not been created as an AD Account?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I checked with the guy that manages the AD servers and he assures us there is no record anywhere of any mac addresses in AD. I have done my own search and cant find anything in there either. Also, the timestamps of these two authentication attempts are 09:36 and 10:36 (or something like that) and we know we definitely didnt make any changes to AD in that time window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) Which conditions have you defined under the Authorization Rule "MAB-PC"?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===== AUTHORIZATION POLICY =====&lt;/P&gt;&lt;P&gt;General&lt;BR /&gt;Name: MAB-PC&lt;BR /&gt;Status: Enabled&lt;/P&gt;&lt;P&gt;Conditions&lt;BR /&gt;[TICKED] NDG:Location in All Locations:AP&lt;BR /&gt;[NOT TICKED] AD1:ExternalGroups -ANY-&lt;BR /&gt;[TICKED] Compound Condition:&lt;BR /&gt;Dictionary AD-AD1 Attribute [blank]&lt;/P&gt;&lt;P&gt;Current Condition Set:&lt;BR /&gt;Internal Hosts:HostIdentityGroup in AllGroups:NoDot1xClient&lt;/P&gt;&lt;P&gt;Results&lt;BR /&gt;Authorization Profiles&lt;BR /&gt;MAB-PC&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;===== IDENTITY GROUP =====&lt;BR /&gt;Name: NoDot1xClient&lt;BR /&gt;Info: This group is assigned to all MAC address Hosts which do not have dot1x enabled.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;===== AUTHORIZATION PROFILE =====&lt;/P&gt;&lt;P&gt;Authorization Profile&lt;BR /&gt;Name: MAB-PC&lt;BR /&gt;Downloadable ACL Name - Static - Value [Permit-IP]&lt;BR /&gt;VLAN ID/Name - Static - User-trusted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===== Downloadable ACLs ======&lt;/P&gt;&lt;P&gt;Name - Permit-IP&lt;BR /&gt;Downloadable ACL Content: Permit IP Any Any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 20:08:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866872#M267682</guid>
      <dc:creator>pmchandler</dc:creator>
      <dc:date>2012-01-16T20:08:26Z</dc:date>
    </item>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866873#M267689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the logs, I suspect that for some reason the ACS is able to authenticate the MAC Address against the AD, therefore, failing the authorization condition match at "Current Condition Set:Internal Hosts:HostIdentityGroup in AllGroups:NoDot1xClient".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS will end up hitting the Deny Access rule as it was not able to comply with the condition for the MAB-PC authorization rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We should dig further trying to determine why the MAC Address is getting authenticated by AD instead of Internal Hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 20:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866873#M267689</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-16T20:12:34Z</dc:date>
    </item>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866874#M267701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Carlos, thanks for your help. Do you have any suggestions for how we can determine why the MAC address is getting authenticated by AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To help me understand the nature of the issue a bit more, could you help me with the following queries about how 802.1X and ACS works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a switch is configured for dot1x with MAB fallback as ours is, does the switch still send the MAC address for a dot1x-enabled client as well as the user and host AD credentials even though the MAC address is not required for auth in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the same switch and a client with dot1x DISABLED, does the switch forward just the MAC address to ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the switch invokes MAB and passes just the MAC address to ACS, does ACS still run the MAC address through the full identity store sequence which starts with AD1, even though dot1x is not running (and therefore AD matching is not relevant)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimately, I am trying to decide if &lt;/P&gt;&lt;P&gt;a) ACS is passing non-dot1x credentials (namely the MAC address) to AD erroneously or &lt;/P&gt;&lt;P&gt;b) if AD is responding (correctly or incorrectly) with a match or&lt;/P&gt;&lt;P&gt;c) if AD is rejecting the MAC address but that the rejection message isnt triggering the next iteration in the identity store sequence.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 20:36:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866874#M267701</guid>
      <dc:creator>pmchandler</dc:creator>
      <dc:date>2012-01-16T20:36:50Z</dc:date>
    </item>
    <item>
      <title>[Q] Identity Sequence issue causes MAB to auth against AD ??</title>
      <link>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866875#M267723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a switch is configured for dot1x with MAB fallback as ours is, does&amp;nbsp; the switch still send the MAC address for a dot1x-enabled client as well&amp;nbsp; as the user and host AD credentials even though the MAC address is not&amp;nbsp; required for auth in this case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CARLOS&gt; A switchport configured for 802.1x with MAB fallback will first send an EAPOL Start message. An 802.1x enabled client would be able to provide the appropriate User and Host information and get authenticated via 802.1x. No MAC address will be send at this point.&lt;/CARLOS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the same switch and a client with dot1x DISABLED, does the switch forward just the MAC address to ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CARLOS&gt; Yes, the switch will send the EAPOL Start messages to the 802.1x Disabled client. It will not be able to respond to the switchport request. After the retries the switchport will fallback to MAB and expect the client to send the MAC Address to get authenticated.&lt;/CARLOS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the switch invokes MAB and passes just the MAC address to ACS, does&amp;nbsp; ACS still run the MAC address through the full identity store sequence&amp;nbsp; which starts with AD1, even though dot1x is not running (and therefore&amp;nbsp; AD matching is not relevant)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CARLOS&gt; Yes, the ACS will still run the authentication against all the Database specified on the Identity Store Sequest from top to bottom&lt;/CARLOS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimately, I am trying to decide if &lt;/P&gt;&lt;P&gt;a) ACS is passing non-dot1x credentials (namely the MAC address)&amp;nbsp; to AD erroneously ---&amp;gt; Do not think this might be the case as it will&amp;nbsp; always pass the credentials to the every database on the specified&amp;nbsp; order&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) if AD is responding (correctly or incorrectly) with a match ---&amp;gt; We know this one is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c)&amp;nbsp;&amp;nbsp; if AD is rejecting the MAC address but that the rejection message isnt&amp;nbsp;&amp;nbsp; triggering the next iteration in the identity store sequence. ----&amp;gt;&amp;nbsp; Do not think AD is rejecting the MAC Address based on:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24432&amp;nbsp; Looking up user in Active Directory - 00-1B-78-00-33-00&lt;/P&gt;&lt;P style="margin-top: 0pt;"&gt;24416&amp;nbsp; User's Groups retrieval from Active Directory succeeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point I have no suggestions on how to determine if the MAC Address is being properly authenticated on the AD Side &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 21:01:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/q-identity-sequence-issue-causes-mab-to-auth-against-ad/m-p/1866875#M267723</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-16T21:01:07Z</dc:date>
    </item>
  </channel>
</rss>

