<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB authentication and ARP request in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042327#M588170</link>
    <description>&lt;P&gt;Hi everyone, in my network i have an issues with MAB authentication and some "quiet" endpoint, now explain the details.&lt;/P&gt;&lt;P&gt;The endpoint is poe and is configured with static IP, not support dot1x. When the device boot up not make any ethernet traffic except multiple ARP request. I have already read &lt;A href="https://community.cisco.com/t5/network-access-control/best-mab-practice-for-quiet-endpoints-with-static-ips/m-p/4552067#M572774" target="_blank" rel="noopener"&gt;this&lt;/A&gt; discussion but my problem is little different. The endpoint fail dot1x and MAB authentication not starting because the client not make any traffic.&amp;nbsp;Actually i use a workaround: configure the device with dhcp and add "&lt;EM&gt;authentication timer restart 5" &lt;/EM&gt;on the port configuration, but this isn't a clean solution because i want to use static IP on this device.&lt;/P&gt;&lt;P&gt;This is typical port configuration:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet1/0/1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport access vlan 998&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer restart 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;It's possible to trigger MAB authentication also with ARP request?&lt;/P&gt;&lt;P&gt;I think that the MAB authentication starting when mac-address table are populated. What are the rules that the switch use to populate the mac-address table, the arp request is insufficient?&lt;/P&gt;&lt;P&gt;Thanks to the community for replies!&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 10:45:49 GMT</pubDate>
    <dc:creator>SysAdminPilot</dc:creator>
    <dc:date>2024-03-18T10:45:49Z</dc:date>
    <item>
      <title>MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042327#M588170</link>
      <description>&lt;P&gt;Hi everyone, in my network i have an issues with MAB authentication and some "quiet" endpoint, now explain the details.&lt;/P&gt;&lt;P&gt;The endpoint is poe and is configured with static IP, not support dot1x. When the device boot up not make any ethernet traffic except multiple ARP request. I have already read &lt;A href="https://community.cisco.com/t5/network-access-control/best-mab-practice-for-quiet-endpoints-with-static-ips/m-p/4552067#M572774" target="_blank" rel="noopener"&gt;this&lt;/A&gt; discussion but my problem is little different. The endpoint fail dot1x and MAB authentication not starting because the client not make any traffic.&amp;nbsp;Actually i use a workaround: configure the device with dhcp and add "&lt;EM&gt;authentication timer restart 5" &lt;/EM&gt;on the port configuration, but this isn't a clean solution because i want to use static IP on this device.&lt;/P&gt;&lt;P&gt;This is typical port configuration:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet1/0/1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport access vlan 998&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer restart 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;It's possible to trigger MAB authentication also with ARP request?&lt;/P&gt;&lt;P&gt;I think that the MAB authentication starting when mac-address table are populated. What are the rules that the switch use to populate the mac-address table, the arp request is insufficient?&lt;/P&gt;&lt;P&gt;Thanks to the community for replies!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042327#M588170</guid>
      <dc:creator>SysAdminPilot</dc:creator>
      <dc:date>2024-03-18T10:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042340#M588171</link>
      <description>&lt;P&gt;Use DHCP with static IP-MAC or IP-ClientID&amp;nbsp;&lt;BR /&gt;this make endpoint&amp;nbsp; use DHCP and trigger MAB&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042340#M588171</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-18T10:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042345#M588172</link>
      <description>&lt;P&gt;I would like use static ip... I need to find alternative....&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042345#M588172</guid>
      <dc:creator>SysAdminPilot</dc:creator>
      <dc:date>2024-03-18T10:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042347#M588173</link>
      <description>&lt;P&gt;DHCP with static IP is same as you assing static IP to endpoint directly except with DHCP the endpoint send DHCP request and SW detect this request use MAC in this frame DHCP request for MAB&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042347#M588173</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-18T10:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042373#M588178</link>
      <description>&lt;P&gt;In production enviroment don't have dhcp server on this network&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 11:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042373#M588178</guid>
      <dc:creator>SysAdminPilot</dc:creator>
      <dc:date>2024-03-18T11:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042612#M588185</link>
      <description>&lt;P&gt;ISE cannot do anything without traffic and does not submit ARP requests.&lt;/P&gt;
&lt;P&gt;Use your switch as a DHCP server:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-13/configuration_guide/ip/b_1713_ip_9300_cg/configuring_dhcp.html#task_D69E2B3A83F24C35A1D87619D68E62FE" target="_self"&gt;IP Addressing Services Configuration Guide, Cisco IOS XE 17.13.x (Catalyst 9300 Switches)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can even reserve IP Addresses:&amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/switching/how-to-reserve-a-specific-mac-address-in-the-existing-cisco-dhcp/td-p/4046515" target="_self"&gt;&lt;SPAN&gt;how to reserve a specific MAC address in the existing Cisco DHCP server switch&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 13:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042612#M588185</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2024-03-18T13:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042620#M588187</link>
      <description>&lt;P&gt;Unfortunately DHCP server isn't solution for my network design. My device send continuous ARP request after power up on the network, because it isn't good for start MAB authentication?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 13:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042620#M588187</guid>
      <dc:creator>SysAdminPilot</dc:creator>
      <dc:date>2024-03-18T13:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication and ARP request</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042978#M588197</link>
      <description>&lt;P&gt;See the previous community thread &lt;A href="https://community.cisco.com/t5/network-access-control/wired-802-1x-mab-for-silent-endpoint/td-p/4403961" target="_self"&gt;Wired 802.1x: MAB for Silent Endpoint&lt;/A&gt; for possible solutions.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 18:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-and-arp-request/m-p/5042978#M588197</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-03-18T18:14:37Z</dc:date>
    </item>
  </channel>
</rss>

