<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB authentication instead 802.1x on pc in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589498#M573996</link>
    <description>&lt;P&gt;I see only MAC-Based so PC use MAC-Based.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but you can try &lt;STRONG&gt;enable 802.1x-based&lt;/STRONG&gt; also if SW support both Auth in same port.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 09 Apr 2022 11:16:29 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-04-09T11:16:29Z</dc:date>
    <item>
      <title>MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4588948#M573963</link>
      <description>&lt;P&gt;Goodmorning. we have the followinh problem. On some pc, in random moment, cisco ise authenticate pc using MAB instead 802.1x. So the user reboot the pc or remove &amp;amp; reinsert the ehternet cable and the pc can reauthenticate using user account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;into the ise log i see that the pc is find into AD but try to use MAB and than fail.&lt;/P&gt;&lt;P&gt;802.1x on pc is enabled with GPO. The ip phone (yealink) can authenticate successfully using mab&lt;/P&gt;&lt;P&gt;we have hp aruba 2930 switch.&lt;/P&gt;&lt;P&gt;here the config:&lt;/P&gt;&lt;P&gt;radius-server host 172.18.253.247 key "XXXXXXX"&lt;BR /&gt;radius-server host 172.18.253.247 dyn-authorization&lt;BR /&gt;aaa server-group radius "ISE" host xxx.xxx.xxx.xxx&lt;BR /&gt;aaa authentication num-attempts 10&lt;BR /&gt;aaa authentication telnet login radius local&lt;BR /&gt;aaa authentication telnet enable radius local&lt;BR /&gt;aaa authentication ssh login radius local&lt;BR /&gt;aaa authentication ssh enable radius local&lt;BR /&gt;aaa authentication port-access eap-radius server-group "ISE"&lt;BR /&gt;aaa authentication mac-based chap-radius server-group "ISE"&lt;BR /&gt;aaa port-access authenticator 1/1-1/8,1/10-1/19,1/21-1/46,2/10-2/24,2/26-2/32,2/34-2/44,2/46,3/1-3/47&lt;BR /&gt;aaa port-access authenticator x/y client-limit 3&lt;BR /&gt;aaa port-access authenticator active&lt;BR /&gt;aaa port-access mac-based 1/1-1/8,1/10-1/19,1/21-1/46,2/10-2/24,2/26-2/32,2/34-2/44,2/46,3/1-3/47&lt;BR /&gt;aaa port-access mac-based x/y addr-limit 3&lt;BR /&gt;aaa port-access mac-based x/y reauth-period 60&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cisco ise log and&amp;nbsp;cisco ise config is attached&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for helping!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 09:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4588948#M573963</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-08T09:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589098#M573975</link>
      <description>&lt;P&gt;can I see the config of one port ?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 13:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589098#M573975</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-08T13:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589110#M573977</link>
      <description>&lt;P&gt;for example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface 2/42&lt;BR /&gt;tagged vlan 66&lt;BR /&gt;untagged vlan 21&lt;BR /&gt;aaa port-access authenticator&lt;BR /&gt;aaa port-access authenticator client-limit 3&lt;BR /&gt;aaa port-access mac-based&lt;BR /&gt;aaa port-access mac-based addr-limit 3&lt;BR /&gt;aaa port-access mac-based reauth-period 60&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;vlan 66 is voice vlan for phone&lt;/P&gt;&lt;P&gt;vlan 21 is lan vlan for pc&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 13:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589110#M573977</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-08T13:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589498#M573996</link>
      <description>&lt;P&gt;I see only MAC-Based so PC use MAC-Based.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but you can try &lt;STRONG&gt;enable 802.1x-based&lt;/STRONG&gt; also if SW support both Auth in same port.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 11:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589498#M573996</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-09T11:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589923#M574030</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;this&amp;nbsp;&lt;STRONG&gt;aaa port-access authenticator&lt;/STRONG&gt; and this&amp;nbsp;&lt;STRONG&gt;aaa port-access authenticator client-limit 3&amp;nbsp;&lt;/STRONG&gt;are the command to enable 802.1x authentication user-based (&lt;A href="https://techhub.hpe.com/eginfolib/networking/docs/switches/WB/15-18/5998-8152_wb_2920_asg/content/ch13s05.html" target="_blank"&gt;https://techhub.hpe.com/eginfolib/networking/docs/switches/WB/15-18/5998-8152_wb_2920_asg/content/ch13s05.html&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c02642107" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c02642107&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 07:05:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4589923#M574030</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-11T07:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591052#M574115</link>
      <description>&lt;P&gt;Your ISE log was helpful to understand how and why it was falling back to MAB.&lt;/P&gt;
&lt;P&gt;Try turning OFF "Fallback to unauthorized network access" on your supplicant so it will only do 802.1X.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ethernet0 Properties - MAB Checkbox.png" style="width: 371px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/148723i4D16DBAA7B45E35D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Ethernet0 Properties - MAB Checkbox.png" alt="Ethernet0 Properties - MAB Checkbox.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 15:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591052#M574115</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-12T15:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591057#M574116</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp; but the client is first try 802.1x and then failed and try MAB.&amp;nbsp;&lt;BR /&gt;I think that he need&amp;nbsp;&lt;BR /&gt;reauth command to make client always reauth and if it not reauth the client will delete form ISE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 16:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591057#M574116</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-12T16:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591061#M574117</link>
      <description>&lt;P&gt;If 802.1X failed, why did it fail? You only showed the MAB authentication.&lt;/P&gt;
&lt;P&gt;The user may unplug and replug their cable to have the switch start 802.1X or they can login and logout and that will trigger 802.1X from the client side.&lt;/P&gt;
&lt;P&gt;I don't know what re-authentication command you are expecting them to use on their computer.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 16:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591061#M574117</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-12T16:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591299#M574125</link>
      <description>&lt;P&gt;Re auth command in switch not client.&lt;/P&gt;&lt;P&gt;this force sw to Start 802.1x again for this port.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 00:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591299#M574125</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-13T00:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591404#M574132</link>
      <description>&lt;P&gt;Hi, yesterday i have set tx period on switch&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa port-access authenticator 3/35 tx-period 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(&lt;SPAN&gt;Sets the period the port waits to retransmit the next EAPOL PDU during an authentication session. (Default: 30 seconds))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so, now retansmit every seconds.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;i try to remove the flag, thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;the re auth is already set, if you see the config there is reauth-period 60 for the mac-based, should i set it also for&amp;nbsp;aaa port-access authenticator?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks to everyone!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591404#M574132</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-13T06:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591415#M574133</link>
      <description>&lt;P&gt;here the config of gpo.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 07:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591415#M574133</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-13T07:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591448#M574135</link>
      <description>&lt;P&gt;Yes you need re auth for 802.1x&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 07:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4591448#M574135</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-13T07:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4593306#M574173</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;with reauth enable it was a disaster :D.&amp;nbsp;the PCs lost their network and never re-authenticated themselves&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;&amp;nbsp;i've try to remove the flag but the problem still persists&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 07:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4593306#M574173</guid>
      <dc:creator>m.rivoltella</dc:creator>
      <dc:date>2022-04-15T07:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication instead 802.1x on pc</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4593586#M574177</link>
      <description>&lt;P&gt;Does it do 802.1X if you remove&lt;/P&gt;
&lt;PRE&gt;aaa authentication mac-based chap-radius server-group "ISE"&lt;/PRE&gt;
&lt;P&gt;At this point it appears to be a problem with your HP switch configuration.&lt;/P&gt;
&lt;P&gt;Your endpoint supplicant looks OK.&lt;/P&gt;
&lt;P&gt;Try other endpoints to verify it is not this one endpoint, also.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 15:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-instead-802-1x-on-pc/m-p/4593586#M574177</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-15T15:31:24Z</dc:date>
    </item>
  </channel>
</rss>

