<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971570#M585532</link>
    <description>&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;gt;...I'm looking into how to allow MAB for endpoints which had successful 802.1x authentication.&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Inconsistent requirement , 802.1x supersedes MAB&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;gt;...s there a way to update some endpoint attribute based on a successful 802.1x authentication which then gets used whenever the client (for whatever reason) &lt;FONT color="#FF6600"&gt;goes through MAB?&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- The client doesn't go to anything&amp;nbsp; ; what the client does is determined by the NAC (ISE) infrastructure &lt;STRONG&gt;(only)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 10:53:32 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-12-05T10:53:32Z</dc:date>
    <item>
      <title>ISE Allow MAB for endpoints which had successful Dot1.x authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971540#M585530</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;
&lt;P&gt;I'm looking into how to allow MAB for endpoints which had successful 802.1x authentication.&lt;/P&gt;
&lt;P&gt;Is there a way to update some endpoint attribute based on a successful 802.1x authentication which then gets used whenever the client (for whatever reason) goes through MAB?&lt;/P&gt;
&lt;P&gt;On another NAC solution you can set the endpoint to known through after an authentication.&lt;/P&gt;
&lt;P&gt;How would I do that in ISE?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Jonatan&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 10:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971540#M585530</guid>
      <dc:creator>JonatanSitter</dc:creator>
      <dc:date>2023-12-05T10:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971570#M585532</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;gt;...I'm looking into how to allow MAB for endpoints which had successful 802.1x authentication.&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Inconsistent requirement , 802.1x supersedes MAB&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;gt;...s there a way to update some endpoint attribute based on a successful 802.1x authentication which then gets used whenever the client (for whatever reason) &lt;FONT color="#FF6600"&gt;goes through MAB?&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- The client doesn't go to anything&amp;nbsp; ; what the client does is determined by the NAC (ISE) infrastructure &lt;STRONG&gt;(only)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 10:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971570#M585532</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-05T10:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971594#M585533</link>
      <description>&lt;P&gt;Thanks for the helpful response.&lt;/P&gt;
&lt;P&gt;I know that 802.1x supersedes MAB. But as you might know, sometimes an endpoint fails to authenticate over 802.1x.&lt;BR /&gt;At that point the switch allows for MAB. I want ISE to authenticate/authorize an endpoint over MAB only if there has been a successful 802.1x authentication for example the day before.&lt;/P&gt;
&lt;P&gt;We should be able to set endpoint attributes in the authorization process. Not only send radius attributes to the switch but also add custom attributes to the endpoint database.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971594#M585533</guid>
      <dc:creator>JonatanSitter</dc:creator>
      <dc:date>2023-12-05T11:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971595#M585534</link>
      <description>&lt;P&gt;First config ISE as MAB and as 802.1x&lt;/P&gt;
&lt;P&gt;Then config your SW with&amp;nbsp;&lt;/P&gt;
&lt;P&gt;802.1x flexible auth&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where order and priority make big rule in make end point auth both or one of mab/802.1x&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971595#M585534</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-05T11:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971597#M585535</link>
      <description>&lt;P&gt;&lt;A href="https://www.google.com/url?sa=t&amp;amp;source=web&amp;amp;rct=j&amp;amp;opi=89978449&amp;amp;url=https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf&amp;amp;ved=2ahUKEwjJ9dHSl_iCAxXCVvEDHd3mBx4QFnoECBAQAQ&amp;amp;usg=AOvVaw3z5i9twAwNga4buBNcHYyk" target="_blank"&gt;https://www.google.com/url?sa=t&amp;amp;source=web&amp;amp;rct=j&amp;amp;opi=89978449&amp;amp;url=https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf&amp;amp;ved=2ahUKEwjJ9dHSl_iCAxXCVvEDHd3mBx4QFnoECBAQAQ&amp;amp;usg=AOvVaw3z5i9twAwNga4buBNcHYyk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971597#M585535</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-05T11:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971746#M585536</link>
      <description>&lt;P&gt;If 802.1x fails for whatever reason, do you&amp;nbsp;&lt;EM&gt;really&lt;/EM&gt; want to allow access?&amp;nbsp; What if the device is stolen?&amp;nbsp; The thief now has access to your network.&amp;nbsp; Just because another solution allows an insecure workaround it should&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; be the norm.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 14:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971746#M585536</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-12-05T14:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971752#M585537</link>
      <description>&lt;P&gt;What about PXE boot for example? In that case the PC/Laptop does not respond to 802.1x and needs to fall back to MAB. I want to only allow that if it has previously authenticated successfully and not just for any pxe device.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971752#M585537</guid>
      <dc:creator>JonatanSitter</dc:creator>
      <dc:date>2023-12-05T15:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971759#M585539</link>
      <description>&lt;P&gt;Move the endpoint MAC address to a PXE Endpoint Identity Group and reference that in your Authorization Policy&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971759#M585539</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-12-05T15:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971761#M585540</link>
      <description>&lt;P&gt;Can that be done automatically?&lt;BR /&gt;i.e. if authenticated successfully -&amp;gt; endpoint gets assigned a certain endpoint identity group which later can be referenced in MAB authz policy.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971761#M585540</guid>
      <dc:creator>JonatanSitter</dc:creator>
      <dc:date>2023-12-05T15:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971769#M585542</link>
      <description>&lt;P&gt;It can be, it depends on how you have your profiling and/or EIGs set up as to how you would determine which EIG the endpoints are assigned&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 15:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4971769#M585542</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-12-05T15:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Allow MAB for endpoints which had successful Dot1.x authentica</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4972316#M585553</link>
      <description>&lt;P&gt;Could you maybe give me some hints, what to look for?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 12:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-allow-mab-for-endpoints-which-had-successful-dot1-x/m-p/4972316#M585553</guid>
      <dc:creator>JonatanSitter</dc:creator>
      <dc:date>2023-12-06T12:13:14Z</dc:date>
    </item>
  </channel>
</rss>

