<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245363#M594107</link>
    <description>&lt;P&gt;What your very first screenshot tells me, is that you have built a bunch of Authentication Rules under a single Policy Set.&lt;/P&gt;
&lt;P&gt;You have not shown us your top-level Policy Set - and I think this is where the problem lies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should create a Separate Policy Set for each type of Policy - e.g. in the top-level ISE Policy Set, create stuff like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1736456613608.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237296i13C04E38F5B1BABA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1736456613608.png" alt="ArneBier_0-1736456613608.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to build logic for Wireless MAB, then click into the Wireless MAB Policy (click on the far right ' &amp;gt; ' icon, and then start building Authentication and Authorization logic.&lt;/P&gt;
&lt;P&gt;If you have a bunch of SSIDs, then you can also keep the Policy Set nice and tidy by creating one Policy per SSID at the top level. That would obviously also be the case for separating Guest Wireless (Wireless_MAB &amp;amp; Normalised SSID Contains 'GUEST') and 802.1X (Wireless_802.1X &amp;amp; Normalised SSID Contains 'Corp') -etc.&lt;/P&gt;
&lt;P&gt;The Smart Condition 'Wireless_MAB' assumes that your NAD has been tagged with the appropriate vendor (e.g. Cisco, HP etc.) since some NAD devices send different RADIUS attributes during MAB - ISE abstracts this with 'Wireless_MAB'.&amp;nbsp; &amp;nbsp;You can further abstract the SSID name with the Smart Condition 'Normalised RADIUS: SSID' instead of referring to Called-Station-ID (under the hood it uses Called-Station-ID, but the SSID condition is more descriptive to the human).&lt;/P&gt;
&lt;P&gt;I noticed that your Guest Redirection Rule 'UTC-Guest_GuestAccessPolicy' comes AFTER the 'UTC-Guest_RediretPolicy' - the logic is wrong - if your Rule is Wireless MAB &amp;amp; SSID UTC-Guest, then this will be true every time, and the rule that follows it won't ever be matched. You need to swap them around - the more specific Rules must always come before the less specific rules, when there is common logic.&amp;nbsp; And also 'UTC Guest Redirect' rule is the wrong description - swap the descriptions of the UTC Guest Rules.&lt;/P&gt;
&lt;P&gt;If wireless MAB is failing through to the default Policy, then it means that ISE is not matching all the conditions, and perhaps the NAD is not sending the attributes you expect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the NAD Cisco AireOS, 9800, Meraki ,or what?&lt;/P&gt;
&lt;P&gt;e.g. If I recall, Meraki uses PAP authentication, and not MAB. That requires a different set of Rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I think your main issue is that you have not split out your Policy Sets to make the logic clear/clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2025 21:03:48 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-01-09T21:03:48Z</dc:date>
    <item>
      <title>Unauthorized Endpoint Access Issue with Wireless MAB Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243662#M594011</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am facing an issue with Cisco ISE version 3.3. I created a policy for wireless MAB authentication to restrict access for certain endpoints, as shown in the attached image. However, unauthorized endpoints are still able to connect to the SSID by matching the default ‘Default_Authenticated_Access’ policy. Disabling this policy causes issues with access to other SSIDs. How can I resolve this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 19:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243662#M594011</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-05T19:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243670#M594012</link>
      <description>&lt;P&gt;Can I see policy set you use in ISE&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 19:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243670#M594012</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-05T19:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243680#M594013</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1829319"&gt;@tamer01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How are you matching the Mac address?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you disable the&amp;nbsp;&lt;SPAN&gt;Default_Authenticated_Access other SSID is impacted, maybe is better review your policies.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 20:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243680#M594013</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-01-05T20:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243690#M594014</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Here’s the authentication and authorization policies.&amp;nbsp;&lt;BR /&gt;as I said before the unauthorized mac hits in basic_authenticated_access policy as shown in live logs&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 20:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243690#M594014</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-05T20:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243691#M594015</link>
      <description>&lt;P&gt;After disabling&amp;nbsp;&lt;SPAN&gt;Default_Authenticated_Access, trying to associate and loading not gaining access for all ssids MAB or dot1x&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 20:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243691#M594015</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-05T20:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243702#M594016</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1829319"&gt;@tamer01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking the print over a smartphone. I can not see where you setup the wlan ID for Mab.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 21:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243702#M594016</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-01-05T21:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243707#M594017</link>
      <description>&lt;P&gt;called-id &amp;lt;&amp;lt;- how you config this in WLC and under policy set, I see only end with can you more elborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2025 21:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243707#M594017</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-05T21:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243801#M594020</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’m using condition called-station-Id ends with “ssid name”.&lt;/P&gt;
&lt;P&gt;FYI the unauthorized MACs assigned to policy’s SGT or authorization profile and it shouldn’t be happened.&lt;/P&gt;
&lt;P&gt;I mean that unauthorized devices assign the vlan and take ip address from vlan pool then hit in basic_ authenticated_access policy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don’t know if it’s related with authentication policy or not&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 07:19:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243801#M594020</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-06T07:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243825#M594021</link>
      <description>&lt;P&gt;can you add match called-id (with SSID) for guest policy ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 07:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243825#M594021</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-06T07:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243847#M594022</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Already added. Check highlights&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 08:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5243847#M594022</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-06T08:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245068#M594096</link>
      <description>&lt;P&gt;I will send you PM tomorrow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245068#M594096</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-09T08:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245363#M594107</link>
      <description>&lt;P&gt;What your very first screenshot tells me, is that you have built a bunch of Authentication Rules under a single Policy Set.&lt;/P&gt;
&lt;P&gt;You have not shown us your top-level Policy Set - and I think this is where the problem lies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should create a Separate Policy Set for each type of Policy - e.g. in the top-level ISE Policy Set, create stuff like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1736456613608.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237296i13C04E38F5B1BABA/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1736456613608.png" alt="ArneBier_0-1736456613608.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to build logic for Wireless MAB, then click into the Wireless MAB Policy (click on the far right ' &amp;gt; ' icon, and then start building Authentication and Authorization logic.&lt;/P&gt;
&lt;P&gt;If you have a bunch of SSIDs, then you can also keep the Policy Set nice and tidy by creating one Policy per SSID at the top level. That would obviously also be the case for separating Guest Wireless (Wireless_MAB &amp;amp; Normalised SSID Contains 'GUEST') and 802.1X (Wireless_802.1X &amp;amp; Normalised SSID Contains 'Corp') -etc.&lt;/P&gt;
&lt;P&gt;The Smart Condition 'Wireless_MAB' assumes that your NAD has been tagged with the appropriate vendor (e.g. Cisco, HP etc.) since some NAD devices send different RADIUS attributes during MAB - ISE abstracts this with 'Wireless_MAB'.&amp;nbsp; &amp;nbsp;You can further abstract the SSID name with the Smart Condition 'Normalised RADIUS: SSID' instead of referring to Called-Station-ID (under the hood it uses Called-Station-ID, but the SSID condition is more descriptive to the human).&lt;/P&gt;
&lt;P&gt;I noticed that your Guest Redirection Rule 'UTC-Guest_GuestAccessPolicy' comes AFTER the 'UTC-Guest_RediretPolicy' - the logic is wrong - if your Rule is Wireless MAB &amp;amp; SSID UTC-Guest, then this will be true every time, and the rule that follows it won't ever be matched. You need to swap them around - the more specific Rules must always come before the less specific rules, when there is common logic.&amp;nbsp; And also 'UTC Guest Redirect' rule is the wrong description - swap the descriptions of the UTC Guest Rules.&lt;/P&gt;
&lt;P&gt;If wireless MAB is failing through to the default Policy, then it means that ISE is not matching all the conditions, and perhaps the NAD is not sending the attributes you expect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the NAD Cisco AireOS, 9800, Meraki ,or what?&lt;/P&gt;
&lt;P&gt;e.g. If I recall, Meraki uses PAP authentication, and not MAB. That requires a different set of Rules.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I think your main issue is that you have not split out your Policy Sets to make the logic clear/clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 21:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245363#M594107</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-09T21:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245386#M594110</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;You are right.&lt;/P&gt;
&lt;P&gt;Regarding guest, it’s created by cisco catalyst center with this sequence.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 22:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245386#M594110</guid>
      <dc:creator>tamer01</dc:creator>
      <dc:date>2025-01-09T22:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245390#M594111</link>
      <description>&lt;P&gt;Are you getting hits on the UTC Guest_GuestAccessPolicy?&amp;nbsp; And does Guest work as expected?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1736463186137.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237297i8A91776541D924E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1736463186137.png" alt="ArneBier_0-1736463186137.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Unless I missed something, the second Rule should have no hits, because it makes no logical sense in that order, because ISE does not look ahead in the rules to see if there is a better match - it stops when the conditions satisfy the Boolean operator - in this case it's an AND, which means both conditions must be TRUE to make the AND operator succeed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 22:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245390#M594111</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-09T22:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized Endpoint Access Issue with Wireless MAB Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245429#M594115</link>
      <description>&lt;P&gt;so in end it solved or NOT ? can you confirm&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 00:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-endpoint-access-issue-with-wireless-mab/m-p/5245429#M594115</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-10T00:40:04Z</dc:date>
    </item>
  </channel>
</rss>

