<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with authentication based on MAC address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896625#M583197</link>
    <description>&lt;P&gt;MAB is enabled on a port. Interface configuration is the same as on other switches and ports.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 10:10:02 GMT</pubDate>
    <dc:creator>lnw-team</dc:creator>
    <dc:date>2023-08-01T10:10:02Z</dc:date>
    <item>
      <title>Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896617#M583195</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am experiencing problems with device authentication based on MAC address in one of our locations. It concerns collaboration devices that cannot be authenticated via certificate. There's a security policy on our Cisco ISE deployment that grants access based on a profile. All devices whose MAC address starts with xxxx.xx should be placed in a separate VLAN. We've got four access switches on site and authentication works fine on three of them. There's no NAD (network access device) condition in a policy. We've got other devices attached to the faulty switch and they are able to authenticate successfully via certificate (EAP-TLS) or other authentication method. It was working fine before but now when dot1x authentication is enabled on a switch port, the switch does not see even MAC address on the interface. Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 09:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896617#M583195</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-08-01T09:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896622#M583196</link>
      <description>&lt;P&gt;With this description, I assume that the last change messed up with the MAB config on the switch. Can you show the Interface-config?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 09:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896622#M583196</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-08-01T09:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896625#M583197</link>
      <description>&lt;P&gt;MAB is enabled on a port. Interface configuration is the same as on other switches and ports.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 10:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896625#M583197</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-08-01T10:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896632#M583198</link>
      <description>&lt;P&gt;Does the switch initiate a MAB request? What do you see on the ISE?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 10:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896632#M583198</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-08-01T10:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896701#M583201</link>
      <description>&lt;P&gt;The point is that I do not see any log messages.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 11:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896701#M583201</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-08-01T11:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896958#M583202</link>
      <description>&lt;P&gt;So, not seeing a mac on the interface is odd.&lt;/P&gt;&lt;P&gt;So, a couple questions.&lt;/P&gt;&lt;P&gt;1 Are these powered, or PoE devices?&lt;/P&gt;&lt;P&gt;2 Do they work if the port is set as just an access port?&lt;/P&gt;&lt;P&gt;3 Do you have any similar commands on the ports?&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;4 What model switch are you using?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even if everything is failing, you should get a mac on the port so long as the device is talking.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 13:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4896958#M583202</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2023-08-01T13:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897009#M583207</link>
      <description>&lt;P data-source-line="248"&gt;You have provided no actual ISE policy or LiveLog errors so it is difficult to know what your specific issue is. See &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt; .&lt;/P&gt;
&lt;P&gt;Meanwhile, you should see if any of the scenarios here address your issue:&lt;/P&gt;
&lt;H3 id="mac-authentication-bypass-mab-with-ise-20230720" class="maps-to-line" style="margin-top: 0.6em; margin-bottom: 0.65em; unicode-bidi: plaintext; line-height: 1.5em; font-size: 1.1em; font-weight: bold; color: #32373f; font-family: Avenir, Arial, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" data-source-line="248"&gt;▷&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" style="background-color: transparent; color: #155bda;" title="https://youtu.be/IzUpgL-zPVE" href="https://youtu.be/IzUpgL-zPVE" data-from-md="" target="_blank"&gt;MAC Authentication Bypass (MAB) with ISE&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;2023/07/20&lt;/H3&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897009#M583207</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-08-01T14:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897490#M583220</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;1. These are not PoE devices. They have their own power supply.&lt;BR /&gt;2. They work when the port is set for access. No trunk is required.&lt;BR /&gt;3. I've got all those commands in interface configuration.&amp;nbsp;&lt;BR /&gt;4.&amp;nbsp;C3850&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 11:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897490#M583220</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-08-02T11:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentication based on MAC address</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897580#M583232</link>
      <description>&lt;P&gt;ok, so I'm going to summarize from the messages, correct le if i'm wrong.&lt;/P&gt;&lt;P&gt;you have 4 switches in this location, EAP-TLS works on all 4, but MAB is not working on 1. I know you said when you enable dot1x, but that should be running for EAP-TLS, so I'm guessing you meant when you enable mab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, pardon if some of this is basic, but I started at a helpdesk.&lt;/P&gt;&lt;P&gt;1) you have rebooted the non working switch?&lt;/P&gt;&lt;P&gt;2) Are all 4 on the same code version?&lt;/P&gt;&lt;P&gt;3) When you enable MAB, does EAP-TLS keep working for other devices?&lt;/P&gt;&lt;P&gt;If the above 3 are yes, then you may need to compare configs from the working and non-working. I would mainly look at the radius and AAA commands. The only other port command I see for MAB is&amp;nbsp;&lt;SPAN&gt;authentication port-control auto. i'm also assuming these work on the other 3 switches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The odd part is the no mac address. If the switch doesn't get one it will not start MAB. So why does this switch not get a mac.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-authentication-based-on-mac-address/m-p/4897580#M583232</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2023-08-02T13:26:44Z</dc:date>
    </item>
  </channel>
</rss>

