<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fake MAC Detection - ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/fake-mac-detection-ise/m-p/2894781#M36285</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone is using a fake mac address can ise detect that? I mean if someone changed the mac address of their system and there is authentication based on mac address will ise detect that this is fake address and cannot access a certain resource?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:45:08 GMT</pubDate>
    <dc:creator>muhammad.ali111</dc:creator>
    <dc:date>2019-03-11T06:45:08Z</dc:date>
    <item>
      <title>Fake MAC Detection - ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/fake-mac-detection-ise/m-p/2894781#M36285</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If someone is using a fake mac address can ise detect that? I mean if someone changed the mac address of their system and there is authentication based on mac address will ise detect that this is fake address and cannot access a certain resource?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fake-mac-detection-ise/m-p/2894781#M36285</guid>
      <dc:creator>muhammad.ali111</dc:creator>
      <dc:date>2019-03-11T06:45:08Z</dc:date>
    </item>
    <item>
      <title>If you are talking about</title>
      <link>https://community.cisco.com/t5/network-access-control/fake-mac-detection-ise/m-p/2894782#M36286</link>
      <description>&lt;P&gt;If you are talking about someone spoofing a mac that you have entered into ISE, so it is authenticated alone on the mac address, then no. ISE will only get the mac address from the switch, and there is no way to detect that something is "fake" in authentication, because it actually isn't. Profiling and Posture assesment can be used to enforce other policies, and react if those are not fulfilled, but if you are using MAB that is normally not an option. I always suggest using a DACL when using MAB, to restrict the access that the user gets, if they are authenticated with MAB.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 15:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/fake-mac-detection-ise/m-p/2894782#M36286</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-10T15:32:27Z</dc:date>
    </item>
  </channel>
</rss>

