<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3767605#M497021</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320865"&gt;@Jing Hong Li&lt;/a&gt; / &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was unable to find a way to search the Calling-Station-Id in an Endpoint Identity Group DURING an 802.1X authentication.&amp;nbsp; In the radius packets there is always the Calling-Station-ID - BUT - because this is an 802.1X authentication, the User-Name field is used in all of the lookups.&lt;/P&gt;
&lt;P&gt;The solution (as far as I can see) is to perform a MAB auth, and then an 802.1X auth.&amp;nbsp; The Cisco WLC supports that.&amp;nbsp; If the MAB auth fails, then the WLC won't even attempt the 802.1X auth.&amp;nbsp; This means less work for ISE.&lt;/P&gt;
&lt;P&gt;The link I sent in a previous comment shows how this is done.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Dec 2018 22:09:32 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2018-12-20T22:09:32Z</dc:date>
    <item>
      <title>[ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3764820#M497014</link>
      <description>&lt;P&gt;REF:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/802-1x-and-mac-address-authentication-simultaneously/m-p/3557008/highlight/true#M11666" target="_blank"&gt;Re: 802.1X AND MAC address Authenticati...&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Is this still available for ISE 2.3 and later version ? I can set the condition to be Radius·Calling-Station-ID, but can not set the value to be a Endpoint identity Groups:{Groups_Name}，Can you please help to provide the policy detail ? Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3764820#M497014</guid>
      <dc:creator>Jing Hong Li</dc:creator>
      <dc:date>2020-02-21T19:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765182#M497015</link>
      <description>&lt;P&gt;Yes, ISE 2.3 uses the dictionary attribute IdentityGroup.Name as shown below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2018-12-17 at 8.20.29 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/26352iF3CB1CC3E5316764/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2018-12-17 at 8.20.29 AM.png" alt="Screen Shot 2018-12-17 at 8.20.29 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 16:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765182#M497015</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T16:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765483#M497016</link>
      <description>Hi hslai,
Thanks for create new post and reply.
And from your screen shot showing that for 802.1x and MAC address filter authentication at the same time there is no need to compare Radius Calling-Station-ID as Craig Hyps mentioned, Right ?</description>
      <pubDate>Tue, 18 Dec 2018 00:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765483#M497016</guid>
      <dc:creator>Jing Hong Li</dc:creator>
      <dc:date>2018-12-18T00:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765731#M497017</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320865"&gt;@Jing Hong Li&lt;/a&gt;&amp;nbsp;- which Craig Hyps reference are you referring to? &amp;nbsp;There was a similar posting on this Community Forum this week where someone asked how to do 802.1X but in combination with a MAC address lookup in an Endpoint Identity Group. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have &lt;A href="https://community.cisco.com/t5/wireless-security-and-network/ise-2-1-802-1x-and-mac-filtering/m-p/3764970#M55921" target="_self"&gt;a read here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 11:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3765731#M497017</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-12-18T11:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766304#M497018</link>
      <description>&lt;P&gt;I reference below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/802-1x-and-mac-address-authentication-simultaneously/m-p/3557008/highlight/false#" target="_self"&gt;https://community.cisco.com/t5/identity-services-engine-ise/802-1x-and-mac-address-authentication-simultaneously/m-p/3557008/highlight/false#&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766304#M497018</guid>
      <dc:creator>Jing Hong Li</dc:creator>
      <dc:date>2018-12-19T00:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766311#M497019</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P class="1545179782547"&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/77628" target="_blank"&gt;Craig Hyps&lt;/A&gt;&amp;nbsp;wrote&amp;nbsp;&lt;/P&gt;
&lt;SPAN&gt;... you can also validate the Calling-Station-Id (MAC address of LAN user) to an allowed list such as Endpoint Identity Group with specific permissions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is how it is done. The Calling-Station-Id (MAC address) is assigned to an endpoint ID group and we use this endpoint ID group name in the authorization policy condition.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766311#M497019</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-19T00:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766396#M497020</link>
      <description>&lt;P&gt;Great!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks hslai，and I will have a test!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 05:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3766396#M497020</guid>
      <dc:creator>Jing Hong Li</dc:creator>
      <dc:date>2018-12-19T05:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3767605#M497021</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320865"&gt;@Jing Hong Li&lt;/a&gt; / &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was unable to find a way to search the Calling-Station-Id in an Endpoint Identity Group DURING an 802.1X authentication.&amp;nbsp; In the radius packets there is always the Calling-Station-ID - BUT - because this is an 802.1X authentication, the User-Name field is used in all of the lookups.&lt;/P&gt;
&lt;P&gt;The solution (as far as I can see) is to perform a MAB auth, and then an 802.1X auth.&amp;nbsp; The Cisco WLC supports that.&amp;nbsp; If the MAB auth fails, then the WLC won't even attempt the 802.1X auth.&amp;nbsp; This means less work for ISE.&lt;/P&gt;
&lt;P&gt;The link I sent in a previous comment shows how this is done.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 22:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3767605#M497021</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-12-20T22:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: [ISE 2.3+] 802.1X AND MAC address Authentication simultaneously?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3811386#M497022</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532" target="_self"&gt;Arne Bier&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;no need to search&amp;nbsp;&lt;SPAN&gt;Calling-Station-Id, just compare Identity Group name, it works fine.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 02:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-802-1x-and-mac-address-authentication-simultaneously/m-p/3811386#M497022</guid>
      <dc:creator>Jing Hong Li</dc:creator>
      <dc:date>2019-02-28T02:46:42Z</dc:date>
    </item>
  </channel>
</rss>

