<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Order MAB DOT1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684450#M495447</link>
    <description>&lt;P&gt;Thanks for the quick reply! I did some testing and added this to the NAC RADIUS server and got it working.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 20:18:24 GMT</pubDate>
    <dc:creator>NetwkChris</dc:creator>
    <dc:date>2018-08-08T20:18:24Z</dc:date>
    <item>
      <title>NAC Order MAB DOT1x</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684188#M495445</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am experiencing an issue with my network that certain PC's have trouble with authentication. What is happening is that the device authenticates with dot1x first, but then after the 1 hr timer forces the device to re-athenticate. Which causes the device to re-authenticate into MAB, it is put it into the vlan that was created for imaging. The device before it goes to the end-user was imaged using MAB first. Then the customer plugs it in and it authenticates via dot1x, but after the re-authentication timer expires it goes into MAB, and doesnt return to dot1x like it is supposed to, so it can get into the data vlan.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone had this issue before?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my port config:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;description NAC&lt;BR /&gt;shut&lt;BR /&gt; switchport mode access&lt;BR /&gt; mtu 9000&lt;BR /&gt; ip device tracking maximum 0&lt;BR /&gt; no cdp enable&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize voice&lt;BR /&gt; authentication event server alive action reinitialize&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order mab dot1x&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate 3599&lt;BR /&gt; authentication violation replace&lt;BR /&gt; mab &lt;BR /&gt; snmp trap mac-notification change added&lt;BR /&gt; snmp trap mac-notification change removed&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; storm-control broadcast include multicast&lt;BR /&gt; storm-control broadcast level 2.00&lt;BR /&gt; storm-control action trap&lt;BR /&gt; spanning-tree portfast edge&lt;BR /&gt; spanning-tree bpduguard enable&lt;BR /&gt; ip verify source vlan dhcp-snooping&lt;BR /&gt;no shut&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 14:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684188#M495445</guid>
      <dc:creator>NetwkChris</dc:creator>
      <dc:date>2018-08-08T14:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Order MAB DOT1x</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684226#M495446</link>
      <description>&lt;P&gt;Yes, that is expected behavior. If you want to change the behavior so reauth performs 802.1X instead of MAB, please see setting up VSA with Authorization profile part on this document:&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/top-ten-mis-configured-cisco-ios-switch-settings-for-ise/ta-p/3643912#toc-hId--1759816418" target="_self"&gt;Top Ten mis-configured Cisco IOS Switch settings for ISE integration&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 15:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684226#M495446</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-08T15:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Order MAB DOT1x</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684450#M495447</link>
      <description>&lt;P&gt;Thanks for the quick reply! I did some testing and added this to the NAC RADIUS server and got it working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 20:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-order-mab-dot1x/m-p/3684450#M495447</guid>
      <dc:creator>NetwkChris</dc:creator>
      <dc:date>2018-08-08T20:18:24Z</dc:date>
    </item>
  </channel>
</rss>

