<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain-joined computer and MAB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5145233#M590654</link>
    <description>&lt;P&gt;&lt;FONT size="2"&gt;authentication event no-response action authorize vlan 86 &amp;lt;&amp;lt;- remove this since the client always not response&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;debug mab &amp;lt;&amp;lt;- share this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2024 21:58:30 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-07-15T21:58:30Z</dc:date>
    <item>
      <title>Domain-joined computer and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5142580#M590514</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Structure,&amp;nbsp;&lt;/P&gt;&lt;P&gt;- domain network&lt;/P&gt;&lt;P&gt;- dynamic VLAN assignment (Microsoft NPS) but for some testing purpose in the example below is used static vlan assignment&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Catalyst access switches (C2960X C9200)&lt;/P&gt;&lt;P&gt;- "local domain joined" computers (dot1x authentication via certificate works)&lt;/P&gt;&lt;P&gt;- "foreign domain joined" computer (dot1x authentication as expected does not work)&lt;/P&gt;&lt;P&gt;Requirements:&lt;/P&gt;&lt;P&gt;As expected "local domain joined computers" are passing authentication.&lt;/P&gt;&lt;P&gt;We want to label "foreign domain joined computers" as trusted and allow them to pass authentication via MAB.&lt;/P&gt;&lt;P&gt;Problem is that I can't see in the log on the switch that "foreign domain joined computer" MAC authentication. It seems that computer even does not try MAB authentication. As I can find in some way it is expected behavior for domain joined computers and MAB should be "triggered" by switch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch configuration:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;switchport access vlan 50&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport mode access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport voice vlan 20&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication event fail action next-method&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication event server dead action reinitialize vlan 86&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication event no-response action authorize vlan 86&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication host-mode multi-auth&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication order dot1x mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication priority dot1x mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication port-control auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication timer reauthenticate 10800&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication timer restart 10800&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication violation replace&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dot1x timeout quiet-period 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dot1x timeout tx-period 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;storm-control broadcast level pps 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;storm-control action shutdown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;spanning-tree portfast edge&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ip dhcp snooping limit rate 50&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;But I can't see any try for MAB authentication:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;086160: Jul 10 09:11:10 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086161: Jul 10 09:11:11 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086162: Jul 10 09:11:14 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086163: Jul 10 09:11:15 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086164: Jul 10 09:11:18 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086165: Jul 10 09:11:19 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086166: Jul 10 09:11:34 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B2F43ECE18&lt;BR /&gt;086167: Jul 10 09:11:41 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086168: Jul 10 09:11:42 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086169: Jul 10 09:11:45 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086170: Jul 10 09:11:46 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086171: Jul 10 09:11:58 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B3F43F15F7&lt;BR /&gt;086172: Jul 10 09:12:13 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086173: Jul 10 09:12:14 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086174: Jul 10 09:12:16 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B4F43F9415&lt;BR /&gt;086175: Jul 10 09:12:17 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086176: Jul 10 09:12:18 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B4F43F9415&lt;BR /&gt;086177: Jul 10 09:12:18 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086178: Jul 10 09:12:27 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B4F43F9415&lt;BR /&gt;086179: Jul 10 09:14:18 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B4F43F9415&lt;BR /&gt;086180: Jul 10 09:18:31 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086182: Jul 10 09:18:32 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to down&lt;BR /&gt;086183: Jul 10 09:18:35 CEST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086184: Jul 10 09:18:36 CEST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/30, changed state to up&lt;BR /&gt;086185: Jul 10 09:18:41 CEST: %DOT1X-5-FAIL: Authentication failed for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B5F4455828&lt;BR /&gt;086186: Jul 10 09:18:42 CEST: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (c465.1609.1e2d) on Interface Gi1/0/30 AuditSessionID C0A8E51D000007B5F4455828&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Changing order to mab dot1x is not solution.&lt;/P&gt;&lt;P&gt;Any suggestion, how to force&amp;nbsp;"foreign domain joined computer" to try MAB after unsuccessful dot1x?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 07:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5142580#M590514</guid>
      <dc:creator>jcegar84</dc:creator>
      <dc:date>2024-07-10T07:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-joined computer and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5145230#M590652</link>
      <description>&lt;P&gt;Any supplicant (802.1X configured client network device) will send EAPOL Identify frames when it senses the link is up. Likewise, when the switch senses the link up, it sends EAPOL Start frames. Then the switch processes that and sends it to RADIUS server. If the 802.1X authentication fails, because you don't trust the foreign clients, and likewise, the clients can also abort the EAP conversation because they don't trust the EAP server cert, then you have authentication failure. How you treat that failure determines what happens next. if you return and Access-reject (which is the expected and obvious solution) then the switch processes that as a failed authentication and the endpoint is not authorized - in the case of Low Impact Mode, the pre-auth ACL remains in place and the port is protected, apart from the stuff your pre-auth ACL allows through. But MAB will not be triggered. Why? Because the 802.1X authentication failed and the client did not provide any other traffic on the network adapter. The endless loop begins ...&lt;/P&gt;
&lt;P&gt;The solution is to enable the option in Windows, to failback when 802.1X fails. This tells the supplicant to abort 802.1X and send regular traffic (e.g. DHCP request)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 21:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5145230#M590652</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-15T21:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-joined computer and MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5145233#M590654</link>
      <description>&lt;P&gt;&lt;FONT size="2"&gt;authentication event no-response action authorize vlan 86 &amp;lt;&amp;lt;- remove this since the client always not response&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;debug mab &amp;lt;&amp;lt;- share this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 21:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/domain-joined-computer-and-mab/m-p/5145233#M590654</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-15T21:58:30Z</dc:date>
    </item>
  </channel>
</rss>

