<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authentication open and 802.1x failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749530#M488035</link>
    <description>&lt;P&gt;The port should continue to MAB once Dot1x times out or fails.&amp;nbsp; I would get rid of the webauth methods.&amp;nbsp; If the device continues to send Dot1x frames to kick the switch out of MAB they could get indefinite open access to the network.&amp;nbsp; This is the downside to using open mode and the legacy template.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Nov 2018 20:03:03 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-11-19T20:03:03Z</dc:date>
    <item>
      <title>authentication open and 802.1x failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749317#M488029</link>
      <description>&lt;DIV class="entry-content lotusPostDetails"&gt;
&lt;P dir="ltr"&gt;If this config on switch:&lt;/P&gt;
&lt;PRE dir="ltr"&gt;interface GigabitEthernet2/0/30
 switchport access vlan 24
 switchport mode access
 switchport voice vlan 25
 authentication event fail action next-method
 authentication event server dead action authorize vlan 24
 authentication event server dead action authorize voice
 authentication event server alive action reinitialize 
 authentication host-mode multi-auth
 authentication open
 authentication order dot1x mab webauth
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 authentication timer inactivity 30
 authentication fallback Webauth
 mab
 dot1x pae authenticator
 spanning-tree portfast
end
&lt;/PRE&gt;
&lt;P dir="ltr"&gt;When 802.1x client fails authentication, I get open access, and am not being passed to MAB. So my question is, if "authentication open" and authentication order dot1x mab webauth" is configured, IF 802.1x authentication fails, will the port access go to OPEN or will it continue to MAB.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 19 Nov 2018 15:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749317#M488029</guid>
      <dc:creator>edmcnich</dc:creator>
      <dc:date>2018-11-19T15:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: authentication open and 802.1x failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749454#M488031</link>
      <description>&lt;P&gt;Hello edmchich,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configs looks good..&lt;/P&gt;
&lt;P&gt;Couple of things on ISE&lt;/P&gt;
&lt;P&gt;1. Hope the endpoint mac address is part of the endpoint identity group(Administration&amp;gt;identity management&amp;gt;groups&amp;gt;endpoint identity groups) -- May be add the mac under one of those available groups.&lt;/P&gt;
&lt;P&gt;2.Set the authorization profile to have dot1x as first method and MAB as next option and set the condition -- Refer to attachment..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if that helps..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 18:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749454#M488031</guid>
      <dc:creator>mnagired</dc:creator>
      <dc:date>2018-11-19T18:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: authentication open and 802.1x failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749530#M488035</link>
      <description>&lt;P&gt;The port should continue to MAB once Dot1x times out or fails.&amp;nbsp; I would get rid of the webauth methods.&amp;nbsp; If the device continues to send Dot1x frames to kick the switch out of MAB they could get indefinite open access to the network.&amp;nbsp; This is the downside to using open mode and the legacy template.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 20:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3749530#M488035</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-11-19T20:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: authentication open and 802.1x failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3750996#M488037</link>
      <description>&lt;P&gt;Hello edmchich&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you good or still need assistance? if not then we would close this thread?? Let us know&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 19:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-and-802-1x-failure/m-p/3750996#M488037</guid>
      <dc:creator>mnagired</dc:creator>
      <dc:date>2018-11-21T19:34:40Z</dc:date>
    </item>
  </channel>
</rss>

