<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Hi Fnu,can we apply this in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698875#M55422</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Fnu,&lt;/P&gt;&lt;P&gt;can we apply this situation using microsoft NAP and AD but without creating this bulk of accounts (mac address as a username and password) ??&lt;/P&gt;&lt;P&gt;It's really strange that something like that is not available on cisco as a leader for the switching market !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 May 2015 07:08:18 GMT</pubDate>
    <dc:creator>sherif safwat</dc:creator>
    <dc:date>2015-05-26T07:08:18Z</dc:date>
    <item>
      <title>mac authentication bypass</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698871#M55416</link>
      <description>&lt;P&gt;we have dot1x and MAB features implemented in a Juniper infrastructure where we can bypass non dot1x devices using local database in the switches themselves.&lt;/P&gt;&lt;P&gt;now we will migrate to cisco and need to deploy the same mab scenario locally on the switches without the need for radius for mab authentication.&lt;/P&gt;&lt;P&gt;how can this be done ?&lt;/P&gt;&lt;P&gt;Note : Juniper command as below&lt;/P&gt;&lt;P&gt;set protocol dot1x authenticator static xx:xx:xx:xx:xx:xx&lt;/P&gt;&lt;P&gt;where the xx:xx:xx:xx:xx:xx is the mac required to&amp;nbsp;bypass&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698871#M55416</guid>
      <dc:creator>sherif safwat</dc:creator>
      <dc:date>2019-03-11T05:45:12Z</dc:date>
    </item>
    <item>
      <title>Hi Sherif,You will need the</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698872#M55419</link>
      <description>&lt;P&gt;Hi Sherif,&lt;/P&gt;&lt;P&gt;You will need the RADIUS server and mac address list created on it for MAB to work as a fall back method or standalone MAB.&lt;/P&gt;&lt;P&gt;More details can be found at:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-663759.html&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_aaa/configuration/15-2mt/sec-config-mab.html&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2015 19:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698872#M55419</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-05-25T19:58:47Z</dc:date>
    </item>
    <item>
      <title>Hi FNU,Actually we use</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698873#M55420</link>
      <description>&lt;P&gt;Hi FNU,&lt;/P&gt;&lt;P&gt;Actually we use Microsoft NAP for authentication with active directory,and it's not logical to create more than 500 account in active directory with our devices mac-addresses as a username and a password to be authenticated!!&lt;/P&gt;&lt;P&gt;Juniper is smart on this as we can easily match of the OUI part of the mac addresses locally on the switch and keeping the NAP only for dot1x authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope there will be a similar method for that on cisco&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2015 20:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698873#M55420</guid>
      <dc:creator>sherif safwat</dc:creator>
      <dc:date>2015-05-25T20:18:46Z</dc:date>
    </item>
    <item>
      <title>Hi Sherif,I don't see such an</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698874#M55421</link>
      <description>&lt;P&gt;Hi Sherif,&lt;/P&gt;&lt;P&gt;I don't see such an option available. You would need Radius server or LDAP or AD integrated with switch/router for MAB &amp;nbsp;to work. I don't see an option to define local MAC-ADDRESS list on switch/router itself.&lt;/P&gt;&lt;P&gt;May be some one has ideas for an&amp;nbsp;easy way to import/create the Mac-address DB on AD.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2015 20:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698874#M55421</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-05-25T20:36:02Z</dc:date>
    </item>
    <item>
      <title> Hi Fnu,can we apply this</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698875#M55422</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Fnu,&lt;/P&gt;&lt;P&gt;can we apply this situation using microsoft NAP and AD but without creating this bulk of accounts (mac address as a username and password) ??&lt;/P&gt;&lt;P&gt;It's really strange that something like that is not available on cisco as a leader for the switching market !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 07:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698875#M55422</guid>
      <dc:creator>sherif safwat</dc:creator>
      <dc:date>2015-05-26T07:08:18Z</dc:date>
    </item>
    <item>
      <title>it's done , noway to do it</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698876#M55423</link>
      <description>&lt;P&gt;it's done , noway to do it from Cisco switch itself .&lt;/P&gt;&lt;P&gt;can be done from Microsoft NAP to accept these account without authentication and provide Vlan directly&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 15:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass/m-p/2698876#M55423</guid>
      <dc:creator>sherif safwat</dc:creator>
      <dc:date>2015-05-27T15:05:58Z</dc:date>
    </item>
  </channel>
</rss>

