<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4281366#M565085</link>
    <description>&lt;P&gt;thanks a lot,&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command is&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication timer inactivity {seconds | server}&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 13:52:00 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2021-01-28T13:52:00Z</dc:date>
    <item>
      <title>MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273372#M564807</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we are using 802.1x to authenticate our Clients.&lt;/P&gt;&lt;P&gt;As a fallback and for foreign devices we are using MAB.&lt;/P&gt;&lt;P&gt;Now we often met the issue, that also MAB is not working.&lt;/P&gt;&lt;P&gt;The authentication session does not start at all and there is no MAC Address visible.&lt;/P&gt;&lt;P&gt;As soon as we disable the authentication, the device can be connected succesfully, MAC is visible etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We met this issue with different Devices (e.g. Raspberry Pi, Printer) and on different Plattforms (e.g. 4506E, C9300).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anbody else facing such issues and may can provide a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and est regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 16:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273372#M564807</guid>
      <dc:creator>Stefan E.</dc:creator>
      <dc:date>2021-01-15T16:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273378#M564808</link>
      <description>&lt;P&gt;Please provide further information so the forum can better assist.&amp;nbsp; Information including switch config (interface/mab/dot1x/aaa configs).&amp;nbsp; Have you ran any debugs to further tshoot that you can share? Can you share any detail radius live logs from mab failures?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 17:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273378#M564808</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-01-15T17:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273507#M564809</link>
      <description>&lt;P&gt;Depend on,&lt;/P&gt;&lt;P&gt;priority and order,&lt;/P&gt;&lt;P&gt;share config if you can&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 20:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273507#M564809</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-15T20:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273544#M564811</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;of course i can share some more details:&lt;/P&gt;&lt;P&gt;Here the interface config:&lt;/P&gt;&lt;PRE&gt;interface GigabitEthernet3/37
 description [...]
 switchport access vlan 116
 switchport mode access
 switchport voice vlan 70
 authentication event fail action next-method
 authentication event server dead action authorize vlan 116
 authentication event server dead action authorize voice
 authentication event server alive action reinitialize 
 authentication host-mode multi-auth
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 authentication violation restrict
 mab
 dot1x pae authenticator
 dot1x timeout tx-period 2
 dot1x max-req 4
 spanning-tree portfast
 ip dhcp snooping limit rate 50
end&lt;/PRE&gt;&lt;P&gt;In general, the authentication is working, as you can see here (other Ports on the same switch working fine with MAB and 802.1x):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Switch#sh authentication sessions interface 

Interface    MAC Address    Method  Domain  Status Fg Session ID
Gi2/37       e4e7.--------  dot1x   DATA    Auth      8D82[....]F4
Gi3/38       48ba.--------  mab     DATA    Auth      8D82[....]B4
Gi3/38       dca6.--------  mab     DATA    Auth      8D82[....]8C
Gi3/11       f430.--------  dot1x   DATA    Auth      8D82[....]64
Gi3/9        80e8.--------  dot1x   DATA    Auth      8D82[....]48
Gi3/8        c434.--------  dot1x   DATA    Auth      8D82[....]60
Gi3/38       309c.--------  mab     DATA    Auth      8D82[....]E4
Gi3/38       0080.--------  mab     DATA    Auth      8D82[....]A8
Gi2/29       901b.--------  mab     DATA    Auth      8D82[....]4C
Gi2/11       5838.--------  mab     DATA    Auth      8D82[....]D8
Gi3/14       0008.--------  dot1x   DATA    Auth      8D82[....]04
Gi3/13       1062.--------  dot1x   DATA    Auth      8D82[....]18

Session count = 12

Key to Session Events Blocked Status Flags:

  A - Applying Policy (multi-line status for details)
  D - Awaiting Deletion
  F - Final Removal in progress
  I - Awaiting IIF ID allocation
  N - Waiting for AAA to come up
  P - Pushed Session
  R - Removing User Profile (multi-line status for details)
  U - Applying User Profile (multi-line status for details)
  X - Unknown Blocker&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if i enable authentication of the port shown at the beginning of this post, nothing happens:&lt;/P&gt;&lt;PRE&gt;Switch#sh mac address-table interface Gi3/37
No entries present.

Switch#sh authentication sessions interface Gi3/37
No sessions match supplied criteria.

Runnable methods list:
  Handle  Priority  Name
    17       5      dot1x
    18       10     mab
    20       15     webauth&lt;/PRE&gt;&lt;P&gt;Same situation after waiting some minutes, some shut and no shuts and reload of the connected device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as i remove the authentication:&lt;/P&gt;&lt;PRE&gt;Switch#sh mac address-table interface GigabitEthernet3/37
Unicast Entries
 vlan     mac address     type        protocols               port
---------+---------------+--------+---------------------+-------------------------
 116      dca6.----------   dynamic ip                    GigabitEthernet3/37        &lt;/PRE&gt;&lt;P&gt;It seems there is not received packet when authentication is enabled, and therefore the authentication will not start.&lt;/P&gt;&lt;P&gt;So i can't provide any logging from Cisco ISE.&lt;/P&gt;&lt;P&gt;But it makes no sense, because without authentication everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas or more informations needed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 21:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4273544#M564811</guid>
      <dc:creator>Stefan E.</dc:creator>
      <dc:date>2021-01-15T21:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4279928#M565022</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/93611"&gt;@Stefan E.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen some devices being very "quiet" when they connect to the network, especially older printers using external print servers. This means that the device will not send any packets out so no dot1x will be triggered. I had similar issues and the device would not send any packets for more than 5 minutes.&lt;/P&gt;&lt;P&gt;What might help you is put the following command under the specific interface and test to ping the specific device "authentication control-direction in" and try to ping the device from another node. Also try to shut and no shut the interface after you apply authentication commands.&lt;/P&gt;&lt;P&gt;If you have the ability to perform a packet capture via a SPAN port while you have applied the authentication commands and have it running as to see any packets send to from the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 17:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4279928#M565022</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2021-01-26T17:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280042#M565027</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 03:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280042#M565027</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-28T03:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280044#M565028</link>
      <description>&lt;P&gt;I Now deep investigate this issue just give me some time.&lt;BR /&gt;OK friend &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 19:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280044#M565028</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-27T19:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280104#M565029</link>
      <description>&lt;P&gt;Hi Panos,&lt;/P&gt;&lt;P&gt;thanks for your feedback and your tipps.&lt;/P&gt;&lt;P&gt;Was not aware of the mentioned command, will definitly try it.&lt;/P&gt;&lt;P&gt;But it's confusing, as i see the mac address right after removing the authentication.&lt;/P&gt;&lt;P&gt;Doesn't that mean, that the device is sending packets?&lt;/P&gt;&lt;P&gt;And also we met this issue even after the reload of the device (e.g. a printer) without success. I'm assuming that there should be traffic during the boot process in any case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280104#M565029</guid>
      <dc:creator>Stefan E.</dc:creator>
      <dc:date>2021-01-26T21:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280107#M565030</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your feedback.&lt;/P&gt;&lt;P&gt;I can try this aswell, but if there would be any authentication starting, i should see it in the logging or with "sh authen session interface" command. But that's not the case. So why it should start the mab when he is not trying via 802.1x?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280107#M565030</guid>
      <dc:creator>Stefan E.</dc:creator>
      <dc:date>2021-01-26T21:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280471#M565061</link>
      <description>&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have tried reloading the device then, assuming that it has a static IP, either the device is not initiating out any packets or there's something wrong with the switch (bug?) or a probe that the switch sends causes the device to fall back?&lt;/P&gt;&lt;P&gt;I'm not sure if the switch will initiate any probes out of the port when it will only see the line going up without first receiving any packets from the endpoint.&lt;/P&gt;&lt;P&gt;A theory in why you see the mac address when you remove the authentication is that then the port has no restrictions and the device could receive packets and reply (e.g. an ARP request). This is why I proposed to use the control direction in, as to allow the device to receive packets and try to respond, allowing the switch to populate the MAC from the endpoint reply.&lt;/P&gt;&lt;P&gt;I would setup a packet capture for both scenarios and repeat the exact same steps in order to try to understand what's going on.&lt;/P&gt;&lt;P&gt;Then maybe try a different switch in terms platform and version.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 12:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280471#M565061</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2021-01-27T12:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280935#M565071</link>
      <description>&lt;P&gt;I figure out the issue here,&amp;nbsp;&lt;BR /&gt;auth timer reauth server.&lt;BR /&gt;Here what happened, " I take Printer as example"&lt;BR /&gt;1- SW send identity request, printer not response to this request since it not support 802.1x&lt;BR /&gt;2- SW start learn MAC address and first frame send from printer is the dhcp request,&lt;BR /&gt;3- SW send this mac to radius to auth and the radius reply with success BUT&lt;BR /&gt;also with reauth time.&lt;BR /&gt;4- SW start send receive from this port since the AuthC is success&lt;BR /&gt;5- Printer now get ip from dhcp&lt;BR /&gt;6- SW reauth time is end and SW start new 802.1x and remove mac from port&lt;BR /&gt;and it failed "as mention before printer not support 802.1x" it start MAB&lt;BR /&gt;BUT BUT here&lt;BR /&gt;SW start learn MAC but the printer not send dhcp because it already have ip and also it quite device i.e. it receive the order it not send frame&lt;BR /&gt;SW wait wait,&lt;BR /&gt;no mac learn on this port and hence nothing happened.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we can approve that this is issue here with&amp;nbsp;&lt;BR /&gt;with the port that not learn mac we will force the printer to reassign new IP from dhcp.&lt;BR /&gt;&lt;BR /&gt;please can you check this point.&lt;BR /&gt;Note:- please do that without the shutdown the printer, shutdown the printer make the SW &amp;nbsp;reauth automatically and we can not config that this is issue here.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;solution:-&lt;BR /&gt;there is inactivity timer we can config it under each interface that we connect quite device, this make SW in case of inactivity only re learn the mac and start new MAB process.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 21:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4280935#M565071</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-27T21:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4281135#M565075</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;- nice analysis - do you happen to have that command for the inactivity timer?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 06:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4281135#M565075</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-01-28T06:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4281366#M565085</link>
      <description>&lt;P&gt;thanks a lot,&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command is&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication timer inactivity {seconds | server}&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 13:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4281366#M565085</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-01-28T13:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4286376#M565285</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name lia-user-rank-Rising-star"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN class=""&gt;MHM Cisco World&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;wow. Thanks for your great analysis.&lt;/P&gt;&lt;P&gt;I'm not sure if this definitly will be the reson, but will keep in mind and check.&lt;/P&gt;&lt;P&gt;Till now we met this issue on different plattforms (C9300, 2960x C4506-E) and different types of devices (e.g. a Raspberry PI and a Audiocodes Phone). The "control-direction in" did not solve the issue.&lt;/P&gt;&lt;P&gt;Even when we had this configured, the Ping was not working and there was no MAC and no authentication visible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to the actual Corona Homeoffice Situation i can't do a test with SPAN Port and Paket capture at the moment.&lt;BR /&gt;Will try this, as soon the situation has changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your feedback.&lt;BR /&gt;I definitly appreciate all ideas on that topic.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 20:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4286376#M565285</guid>
      <dc:creator>Stefan E.</dc:creator>
      <dc:date>2021-02-04T20:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577141#M573619</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This is subject is very important to me because I am also having this issue.&lt;/P&gt;&lt;P&gt;Most of the endpoints authenticate correctly with mab (these endpoints include computers, printers, RTUs, etc).&lt;/P&gt;&lt;P&gt;But in some cases, when connecting some Wave Quality Measure and a Deep Sea Electronics Generator, the behaviour of the CE is exactly the same as described by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/93611"&gt;@Stefan E.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a real example of an interface config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/7&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority mab dot1x&lt;BR /&gt;&amp;nbsp;authentication port-control auto&amp;nbsp;&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout quiet-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast edge&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I have this configured, &lt;STRONG&gt;doesn't arrive any packets in the interface&lt;/STRONG&gt;. If I remove this configuration and do a simple &lt;STRONG&gt;access vlan&amp;nbsp;&lt;/STRONG&gt;config, communication starts working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't understand why this is happening and I have tried all the solutions proposed by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;, without success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 15:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577141#M573619</guid>
      <dc:creator>tcatanho</dc:creator>
      <dc:date>2022-03-23T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577464#M573629</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1307348"&gt;@tcatanho&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What IOS / IOS-XE are you using?&lt;/P&gt;
&lt;P&gt;I have been working with C9300 IOS-XE 17.6.2 recently and I have found a very nice config that works for me&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would say all the commands below make for a happy solution.&lt;/P&gt;
&lt;P&gt;If you have endpoints that don't send any Ethernet packets, then MAB will not be triggered. The end device needs to send *something* to cause MAB to start. And if you want the device to stay connected, then do not return a session timeout via ISE - the switch will apply a session timeout value of N/A - but the Accounting will be sent every 48 hours to keep ISE session DB and License DB happy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After applying the config to an interface, you sometimes have to "shut/no shut", or perform a "clear access-session int ..." to kick start the process. If the endpoint is still not creating a session (as seen in "show access-session int ..." then the client is the problem. In that case use static VLANs instead - and port security.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;aaa new-model
!
!
aaa group server radius ISE
 server name nac1
 server name nac2
 deadtime 5
 retransmit 2
 timeout 5
 load-balance method least-outstanding
!
aaa authentication dot1x default group ISE
aaa authorization network default group ISE
aaa accounting update newinfo periodic 2880
aaa accounting identity default start-stop group ISE
!
!
aaa session-id common
!
!
ip dhcp snooping vlan *** comma delimited list of VLANs to Snoop on *****
no ip dhcp snooping information option
ip dhcp snooping
!
!
!
epm logging
access-session attributes filter-list list FILTER_DS
 cdp
 lldp
 dhcp
access-session accounting attributes filter-spec include list FILTER_DS
device-tracking policy IPDT_POLICY
 security-level glean
 no protocol ndp
 no protocol udp
 tracking enable reachable-lifetime 10
!
service-template DEFAULT_LINKSEC_POLICY_MUST_SECURE
 linksec policy must-secure
service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE
 linksec policy should-secure
service-template DEFAULT_CRITICAL_VOICE_TEMPLATE
 voice vlan
service-template DEFAULT_CRITICAL_DATA_TEMPLATE
service-template CRITICAL_VOICE_VLAN
 description ** Apply voice vlan on AAA Fail **
 voice vlan
service-template CRITICAL_AUTH_VLAN
 description ** Apply data vlan on AAA Fail **
 vlan ***critical_VLAN****
service-template RESTRICTED_AUTH_VLAN
 description ** Apply RESTRICTED vlan on AAA Fail **
 vlan **** restricted_VLAN****
service-template IA-TIMER
 description ** Apply inactivity timer and ARP probe **
 inactivity-timer 60 probe
dot1x system-auth-control
!
class-map type control subscriber match-all AAA_SVR_DOWN_AUTHD_HOST
 match result-type aaa-timeout
 match authorization-status authorized
!
class-map type control subscriber match-all AAA_SVR_DOWN_UNAUTHD_HOST
 match result-type aaa-timeout
 match authorization-status unauthorized
!
class-map type control subscriber match-all DOT1X
 match method dot1x
!
class-map type control subscriber match-all DOT1X_FAILED
 match method dot1x
 match result-type method dot1x authoritative
!
class-map type control subscriber match-all DOT1X_MEDIUM_PRIO
 match authorizing-method-priority gt 20
!
class-map type control subscriber match-all DOT1X_NO_RESP
 match method dot1x
 match result-type method dot1x agent-not-found
!
class-map type control subscriber match-all DOT1X_TIMEOUT
 match method dot1x
 match result-type method dot1x method-timeout
!
class-map type control subscriber match-any IN_CRITICAL_AUTH
 match activated-service-template RESTRICTED_AUTH_VLAN
 match activated-service-template CRITICAL_VOICE_VLAN
!
class-map type control subscriber match-all MAB
 match method mab
!
class-map type control subscriber match-all MAB_FAILED
 match method mab
 match result-type method mab authoritative
!
class-map type control subscriber match-none NOT_IN_CRITICAL_AUTH
 match activated-service-template RESTRICTED_AUTH_VLAN
 match activated-service-template CRITICAL_VOICE_VLAN
!
!
policy-map type control subscriber IDENTITY-POLICY
 event session-started match-all
  10 class always do-until-failure
   10 authenticate using dot1x priority 10
   20 authenticate using mab priority 20
 event authentication-failure match-first
  10 class AAA_SVR_DOWN_UNAUTHD_HOST do-until-failure
   10 activate service-template RESTRICTED_AUTH_VLAN
   20 activate service-template CRITICAL_VOICE_VLAN
   30 authorize
   40 pause reauthentication
  20 class AAA_SVR_DOWN_AUTHD_HOST do-until-failure
   10 pause reauthentication
   20 authorize
  30 class DOT1X_NO_RESP do-until-failure
   10 terminate dot1x
   20 authenticate using mab priority 20
  40 class MAB_FAILED do-until-failure
   10 terminate mab
   20 authentication-restart 60
  50 class DOT1X_FAILED do-until-failure
   10 terminate dot1x
   20 activate service-template RESTRICTED_AUTH_VLAN
   30 authorize
  60 class always do-until-failure
   10 terminate dot1x
   20 terminate mab
   30 authentication-restart 60
 event agent-found match-all
  10 class always do-until-failure
   10 terminate mab
   20 authenticate using dot1x priority 10
 event aaa-available match-all
  10 class IN_CRITICAL_AUTH do-until-failure
   10 clear-session
  20 class NOT_IN_CRITICAL_AUTH do-until-failure
   10 resume reauthentication
 event authentication-success match-all
  10 class always do-until-failure
   10 activate service-template IA-TIMER
!
!
template 802.1X
 dot1x pae authenticator
 storm-control broadcast level 1.00
 storm-control multicast level 1.00
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport access vlan ****restricted_VLAN****
 switchport mode access
 switchport nonegotiate
 trust device cisco-phone
 mab
 access-session host-mode multi-domain
 access-session closed
 access-session port-control auto
 authentication periodic
 authentication timer reauthenticate server
 service-policy type control subscriber IDENTITY-POLICY
 description UserAccess 802.1X
 ip dhcp snooping limit rate 15
!

interface GigabitEthernet1/0/12
 description NAC Controlled Port
 switchport mode access
 switchport voice vlan ***voice_VLAN***
 device-tracking attach-policy IPDT_POLICY
 load-interval 30
 dot1x timeout tx-period 10
 no lldp transmit
 no lldp receive
 source template 802.1X
 spanning-tree portfast
!
ip radius source-interface ****vlan/interface****
radius-server attribute 6 on-for-login-auth
radius-server attribute 6 support-multiple
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
radius-server dead-criteria time 5 tries 2
radius-server deadtime 5
!
radius server nac1
 address ipv4 ***ISE1_IP*** auth-port 1812 acct-port 1813
 automate-tester username testuser idle-time 2
 key 0 ************
!
radius server nac2
 address ipv4 ***ISE2_IP*** auth-port 1812 acct-port 1813
 automate-tester username testuser idle-time 2
 key 0 *************
!

mac address-table notification change
no access-session mac-move deny
&lt;/PRE&gt;</description>
      <pubDate>Wed, 23 Mar 2022 22:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577464#M573629</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-03-23T22:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577468#M573631</link>
      <description>&lt;P&gt;I interest in this case,&amp;nbsp;&lt;BR /&gt;can you show&amp;nbsp;&lt;BR /&gt;show auth session in port ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 22:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577468#M573631</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-03-23T22:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577475#M573632</link>
      <description>&lt;P&gt;A Cisco phone&lt;/P&gt;
&lt;PRE&gt;s112#&lt;STRONG&gt;show access-session int gi 1/0/12 details&lt;/STRONG&gt;
            Interface:  GigabitEthernet1/0/12
               IIF-ID:  0x1EA91FCE
          MAC Address:  885a.92d9.d0f7
         IPv6 Address:  Unknown
         IPv4 Address:  10.49.44.30
            User-Name:  88-5A-92-D9-D0-F7
               Status:  Authorized
               Domain:  VOICE
       Oper host mode:  multi-domain
     Oper control dir:  both
      &lt;FONT color="#FF0000"&gt;Session timeout:  N/A&lt;/FONT&gt;
  Acct update timeout:  172800s (local), Remaining: 170391s
    Common Session ID:  420D020A00000635B8E2D488
      Acct Session ID:  0x00000605
               Handle:  0x3e00062b
       Current Policy:  IDENTITY-POLICY


Local Policies:
        Service Template: IA-TIMER (priority 150)
         Idle timeout: 60 sec

Server Policies:
           Vlan Group:  Name: Unified_Comms_VLAN_Group,  Vlan: 1208


Method status list:
       Method           State
        dot1x           Stopped
          mab           Authc Success
&lt;/PRE&gt;
&lt;P&gt;And a Windows laptop (using 802.1X supplicant)&lt;/P&gt;
&lt;PRE&gt;s112#&lt;STRONG&gt;show access-session int gi 1/0/6 details&lt;/STRONG&gt;
            Interface:  GigabitEthernet1/0/6
               IIF-ID:  0x1B45AC5B
          MAC Address:  3c97.0e1c.12f7
         IPv6 Address:  Unknown
         IPv4 Address:  10.48.0.10
            User-Name:  3C-97-0E-1C-12-F7
               Status:  Authorized
               Domain:  DATA
       Oper host mode:  multi-domain
     Oper control dir:  both
&lt;FONT color="#FF0000"&gt;      Session timeout:  65535s (server), Remaining: 63037s
       Timeout action:  Reauthenticate&lt;/FONT&gt;
  Acct update timeout:  172800s (local), Remaining: 170302s
    Common Session ID:  420D020A00000633B8E18E22
      Acct Session ID:  0x00000603
               Handle:  0xc2000629
       Current Policy:  IDENTITY-POLICY


Local Policies:
        Service Template: IA-TIMER (priority 150)
         Idle timeout: 60 sec

Server Policies:
      Session-Timeout: 65535 sec
           Vlan Group:  Vlan: 1100


Method status list:
       Method           State
        dot1x           Stopped
          mab           Authc Success
&lt;/PRE&gt;
&lt;P&gt;When I block all RADIUS traffic to ISE, then it fails the auth and I see this (as expected - emergency VLANs in place)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;s112#&lt;STRONG&gt;show access-session interface gig 1/0/12 details&lt;/STRONG&gt;
            Interface:  GigabitEthernet1/0/12
               IIF-ID:  0x19038741
          MAC Address:  885a.92d9.d0f7
         IPv6 Address:  Unknown
         IPv4 Address:  Unknown
            User-Name:  885a92d9d0f7
               Status:  Authorized
               Domain:  UNKNOWN
       Oper host mode:  multi-domain
     Oper control dir:  both
      Session timeout:  N/A
  Acct update timeout:  172800s (local), Remaining: 172778s
    Common Session ID:  420D020A00000631B8E01186
      Acct Session ID:  0x00000602
               Handle:  0xdd000627
       Current Policy:  IDENTITY-POLICY


&lt;FONT color="#FF0000"&gt;Local Policies:
        Service Template: CRITICAL_VOICE_VLAN (priority 150)
           Voice Vlan:  Vlan: 1208
        Service Template: RESTRICTED_AUTH_VLAN (priority 150)
           Vlan Group:  Vlan: 1001&lt;/FONT&gt;

Server Policies:


Method status list:
       Method           State
        dot1x           Stopped
          mab           &lt;FONT color="#FF0000"&gt;Authc Failed&lt;/FONT&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
s112#&lt;STRONG&gt;show access-session interface gig 1/0/6 detail&lt;/STRONG&gt;s
            Interface:  GigabitEthernet1/0/6
               IIF-ID:  0x1E348BE0
          MAC Address:  3c97.0e1c.12f7
         IPv6 Address:  Unknown
         IPv4 Address:  10.48.0.10
               Status:  Authorized
               Domain:  UNKNOWN
       Oper host mode:  multi-domain
     Oper control dir:  both
      Session timeout:  N/A
  Acct update timeout:  172800s (local), Remaining: 172759s
    Common Session ID:  420D020A00000632B8E0AFAB
      Acct Session ID:  0x00000601
               Handle:  0x9c000628
       Current Policy:  IDENTITY-POLICY


&lt;FONT color="#FF0000"&gt;Local Policies:
        Service Template: CRITICAL_VOICE_VLAN (priority 150)
           Voice Vlan:  Vlan: 1208
        Service Template: RESTRICTED_AUTH_VLAN (priority 150)
           Vlan Group:  Vlan: 1001&lt;/FONT&gt;

Server Policies:


Method status list:
       Method           State
        dot1x           Stopped
          mab           &lt;FONT color="#FF0000"&gt;Authc Failed

&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interestingly, if the laptop were connected to the back of the phone, then a disaster could happen if the phone were to be in the DATA VLAN for some reason (e.g. it failed ISE auth and landed in a DATA VLAN)... the port shut would then shut down in err-disabled. Why? Because that is the expected result of multi-domain mode - it only allows one MAC address in the DATA domain.&lt;/P&gt;
&lt;P&gt;There is no easy way around this. One way might be to enable &lt;STRONG&gt;multi-auth&lt;/STRONG&gt; mode, but then it's less secure. But only happens if the phone is in the DATA domain ... which normally should not be the case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 23:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577475#M573632</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-03-23T23:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577477#M573633</link>
      <description>&lt;P&gt;Thanks for sharing this info.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 23:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577477#M573633</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-03-23T23:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: MAB not working</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577686#M573640</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;First of all I want o thank you for your time and fast reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently working with Cisco CGR2010 with&amp;nbsp;&lt;STRONG&gt;GRWICDES Software (GRWICDES-IPSERVICESK9-M), Version 15.2(6)E1, RELEASE SOFTWARE (fc4).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;PRE&gt;If you have endpoints that don't send any Ethernet packets, then MAB will not be triggered.&lt;/PRE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The endpoint doesn't send any Ethernet packets after I configure the interface with MAB. If I remove this configuration, I start receiving packets and my mac-address table is updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;PRE&gt;&lt;SPAN&gt;After applying the config to an interface, you sometimes have to "shut/no shut", or perform a "clear access-session int ..."&lt;/SPAN&gt;
&lt;/PRE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I understand this, I have done it a few times with sucess, but in these specific cases where MAB is not working, this solution doesn't work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;wrote:&lt;PRE&gt;&lt;SPAN&gt;In that case use static VLANs instead - and port security.&amp;nbsp;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes! I have been talking with my team, and the solution will most likely be this. But it is not the same as using MAB and ISE...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tiago&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 09:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-not-working/m-p/4577686#M573640</guid>
      <dc:creator>tcatanho</dc:creator>
      <dc:date>2022-03-24T09:52:49Z</dc:date>
    </item>
  </channel>
</rss>

