<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a priority for MAB and 1X in ISE authentication? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4030716#M453900</link>
    <description>Can switches set the authentication order?&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;But the infra here is wireless authentication in PC - WLC - ISE sequence.&lt;BR /&gt;Can you answer me again using wireless authentication as an example, not authentication on Switch&lt;BR /&gt;And please reply more easily. I'm using a translator.</description>
    <pubDate>Mon, 17 Feb 2020 08:04:20 GMT</pubDate>
    <dc:creator>JustTakeTheFirstStep</dc:creator>
    <dc:date>2020-02-17T08:04:20Z</dc:date>
    <item>
      <title>Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4029551#M453898</link>
      <description>&lt;P&gt;I'm testing my wireless authentication.&lt;/P&gt;&lt;P&gt;You have set policies for MAB and 1X.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule1.png" style="width: 696px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67192iEA29A91F1D61A478/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule1.png" alt="rule1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Rule1 = MAB&lt;BR /&gt;Rule2 = 1X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like the ACL, i know that policies are applied from top to bottom.&lt;/P&gt;&lt;P&gt;Wireless authentication performs 1X authentication after MAB authentication in order.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule1_1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67194iA89C8287EBA98042/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule1_1.png" alt="rule1_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is as I wish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, if you change the rule order, only 1X authentication is performed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why not perform the MAB certification of Rule1 when the order is changed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule2.png" style="width: 745px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67193iD7665AAEF13E7679/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule2.png" alt="rule2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Rule2 = 1X&lt;BR /&gt;Rule1 = MAB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule2_1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67195iAF84A94926D67B08/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule2_1.png" alt="rule2_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is 1X authentication a higher priority than MAB?&lt;/P&gt;&lt;P&gt;Why not perform the MAB certification of Rule1 when the order is changed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4029551#M453898</guid>
      <dc:creator>JustTakeTheFirstStep</dc:creator>
      <dc:date>2020-02-21T19:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4029563#M453899</link>
      <description>The order in which this occurs is set on the network device proxying the authentication.  If you set a switch to perform 802.1x first, it will.  If you set the same switch to perform MAB first, it will.  &lt;BR /&gt;&lt;BR /&gt;Now, if a switch is configured for both MAB and Dot1x, and the switch sees an eapol start frame, it will start dot1x with the client.  &lt;BR /&gt;&lt;BR /&gt;The order of your two authentication policy sets are irrelevant because they contain different flows. They are treated top down, but only if they match on the same criteria.  Authorization rules within the policy set specific to MAB  or dot1x are very important because of this but again come down to matching criteria first.  In order to hit #1 you have to be doing MAB, in order to hit #2, you have to be doing dot1x.  So again, this comes back to the network device configuration.</description>
      <pubDate>Fri, 14 Feb 2020 06:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4029563#M453899</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-02-14T06:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4030716#M453900</link>
      <description>Can switches set the authentication order?&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;But the infra here is wireless authentication in PC - WLC - ISE sequence.&lt;BR /&gt;Can you answer me again using wireless authentication as an example, not authentication on Switch&lt;BR /&gt;And please reply more easily. I'm using a translator.</description>
      <pubDate>Mon, 17 Feb 2020 08:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4030716#M453900</guid>
      <dc:creator>JustTakeTheFirstStep</dc:creator>
      <dc:date>2020-02-17T08:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4030998#M453901</link>
      <description>Sorry my bad, I completely glossed over the wireless piece because this is typically a wired question. For completion sake since people may find this in the future, on a switch when doing wired authentication you do this one of two ways.&lt;BR /&gt;1. With IBNS 1.0, you set the order directly on the switchport&lt;BR /&gt;2. With IBNS 2.0, you set the order in your control policy, which the policy then gets applied to the port.  &lt;BR /&gt;&lt;BR /&gt;On wireless, it's a bit different.  The WLAN config dictates if the clients+WLC will do 802.1x or MAC filtering. &lt;BR /&gt;Typically the WLAN will be configured for WPA2 - 802.1x or MAC Filtering but usually not both.  I would say it is not very common for WLANs to be configured for both, and it's not like a switch where you do one then the other.  If you enable both on the same WLAN then the endpoints would need to be configured for 802.1x still.  &lt;BR /&gt;&lt;BR /&gt;There are two common use cases for MAC filtering on a WLAN.&lt;BR /&gt;1. Guest with an open SSID and web redirect&lt;BR /&gt;2. iPSK, where you define separate pre shared keys for different groups of predefined mac addresses in ISE.  This mixes MAC filtering, wpa2, and PSK for the security mode. But it does not include 802.1x. &lt;BR /&gt;&lt;BR /&gt;What are you trying to accomplish?</description>
      <pubDate>Mon, 17 Feb 2020 15:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4030998#M453901</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-02-17T15:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4031954#M453902</link>
      <description>&lt;P&gt;The current MAB rule is Permit if the client's MAC exists in the endpoint group.&lt;/P&gt;&lt;P&gt;But I would like to know why 1X authentication is Rule 1 and MAB authentication is Rule2 and does not go through MAB authentication.&lt;/P&gt;&lt;P&gt;Is there a problem?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 05:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4031954#M453902</guid>
      <dc:creator>JustTakeTheFirstStep</dc:creator>
      <dc:date>2020-02-19T05:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4031995#M453903</link>
      <description>&lt;P&gt;You can't authenticate an endpoint with MAB on an 802.1x secured Wireless SSID. If the SSID is configured for 802.1x, the endpoint must authenticate using an 802.1x authentication method (PEAP, EAP-TLS, etc).&lt;/P&gt;
&lt;P&gt;Unlike Wired switches, there is no concept of falling back to a MAB authentication if 802.1x fails for Wireless.&lt;/P&gt;
&lt;P&gt;You can only authenticate an endpoint with MAB when using an Open or PSK (requires WLC 8.3 code or newer) SSID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 05:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4031995#M453903</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-19T05:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a priority for MAB and 1X in ISE authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4033961#M558231</link>
      <description>&lt;P&gt;Rule 1 has the condition on Wireless MAB so only authentications matching that will report hits. The same goes for Rule 2 on Wireless 802.1X.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 22:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-a-priority-for-mab-and-1x-in-ise-authentication/m-p/4033961#M558231</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-02-21T22:35:39Z</dc:date>
    </item>
  </channel>
</rss>

