<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch config for ports with dot1x and MAB at same time - auth ord in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249576#M594317</link>
    <description>&lt;P&gt;Make new post please&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 13:00:30 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-01-20T13:00:30Z</dc:date>
    <item>
      <title>Switch config for ports with dot1x and MAB at same time - auth order</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5086811#M589194</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I almost always see this command as best practice&amp;nbsp;&lt;STRONG&gt;authentication order dot1x mab&lt;/STRONG&gt; , but sometimes I see this as best practice&amp;nbsp;&lt;STRONG&gt;authentication order mab dot1x.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The priority is always this: &lt;STRONG&gt;authentication priority dot1x mab&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-when I have PC (dot1x) and IP Phone (MAB) on the same port what do you recommend?&lt;/P&gt;
&lt;P&gt;-Why would I use one orden over the other?&lt;/P&gt;
&lt;P&gt;-And what do you guys use normally in these situations? what is your real world experience?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 01:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5086811#M589194</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-05-02T01:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087151#M589201</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1487216"&gt;@babalao&lt;/a&gt;&amp;nbsp; I traditionally use the defaults, 802.1X first before MAB. This works well in scenarios where a PC is plugged in behind a Phone. Ensure the authentication timers settings are not excessive as this can cause DHCP to timeout on some MAB devices. &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This guide covers explains the different order/priority scenarios and the points to consider when changing the order/priority. &lt;A href="https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 07:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087151#M589201</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-02T07:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087196#M589202</link>
      <description>&lt;P&gt;Best practice i suggesting using as below - since if you use MAB that is not secure at all - if dot1x fails then use MAB for non supplicant supported devices.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The priority is always this:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;authentication priority dot1x mab&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 07:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087196#M589202</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-05-02T07:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087212#M589204</link>
      <description>&lt;P&gt;the different is&amp;nbsp;&lt;BR /&gt;order dot1x mab &amp;lt;&amp;lt;- this not common in cisco doc. and the steps are&amp;nbsp;&lt;BR /&gt;SW will try dot1x if failed then it try MAB, it is old fallback MAB auth&lt;BR /&gt;&lt;BR /&gt;order mab dot1x &amp;lt;&amp;lt;- this list in flexAut cisco feature and it is New and the steps are&amp;nbsp;&lt;BR /&gt;SW will detect any MAC and send to raduis and check auth with MAC, here the MAC must not list in radius, if this auth is failed then the SW start dot1x&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;why cisco use order auth order mab dot1x ?&lt;/P&gt;
&lt;P&gt;because there is some device like printer request DHCP in first frame to SW if SW use first dot1x then try auth with MAB&amp;nbsp; there is chance that this SW will not get IP.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 07:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5087212#M589204</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-02T07:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5248597#M594274</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking forward to expert advice here.&lt;/P&gt;&lt;P&gt;Currently we've configured switch ports for MAB based authentication. And we're planning to move to dot1x.&lt;/P&gt;&lt;P&gt;As part of testing whenever we're changing the "authentication order" and "authentication priority" to dot1x from MAB (current setup) and generating a new authentication session the switchport goes into drop state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When doing sh mac addresses int gi0/x&lt;/P&gt;&lt;P&gt;We can see Mac address and port status as "drop".&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 12:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5248597#M594274</guid>
      <dc:creator>Shivesh Mishra</dc:creator>
      <dc:date>2025-01-17T12:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5248962#M594288</link>
      <description>&lt;P&gt;Could you please try to shutdown the port, change the configs, and then unshut it?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 14:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5248962#M594288</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-18T14:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249570#M594316</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for the suggestions.&lt;/P&gt;&lt;P&gt;Tried it but still the same problem. Port goes into drop state.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 12:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249570#M594316</guid>
      <dc:creator>Shivesh Mishra</dc:creator>
      <dc:date>2025-01-20T12:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249576#M594317</link>
      <description>&lt;P&gt;Make new post please&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 13:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249576#M594317</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-20T13:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249718#M594324</link>
      <description>&lt;P&gt;You're welcome. What device type are you trying to authenticate/authorize via dot1x? a PC or a phone? also, could you please share your sanitized configs from the RADIUS server and the switch port for review?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 18:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5249718#M594324</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-20T18:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5250977#M594405</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We're trying to authenticate windows PCs via dot1x. Supplicant is already configured on system end.&lt;/P&gt;&lt;P&gt;Below is the port configuration :&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/19&lt;/P&gt;&lt;P&gt;switchport access vlan xxx&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan zzz&lt;/P&gt;&lt;P&gt;switchport port-security maximum 2&lt;/P&gt;&lt;P&gt;authentication event server dead action authorize vlan xxx&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt;authentication host-mode multi-host&lt;/P&gt;&lt;P&gt;authentication order mab&lt;/P&gt;&lt;P&gt;authentication priority mab&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate 43200&lt;/P&gt;&lt;P&gt;authentication timer inactivity 3600&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt;dotlx pae authenticator&lt;/P&gt;&lt;P&gt;dotlx timeout server-timeout 30&lt;/P&gt;&lt;P&gt;dotlx timeout tx-period 10&lt;/P&gt;&lt;P&gt;dotlx max-req 3&lt;/P&gt;&lt;P&gt;dotlx max-reauth-req 10&lt;/P&gt;&lt;P&gt;spanning-tree portfast edge&lt;/P&gt;&lt;P&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;On Radius Server we've kept a simple straight config for testing purpose only as below -&lt;/P&gt;&lt;P&gt;EAP-Type : TLS (Accept)&lt;/P&gt;&lt;P&gt;Supplicant is configured accordingly on the system end.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 13:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5250977#M594405</guid>
      <dc:creator>Shivesh Mishra</dc:creator>
      <dc:date>2025-01-22T13:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5251078#M594414</link>
      <description>&lt;P&gt;Could you please try to remove the command "&lt;SPAN&gt;switchport port-security maximum 2&lt;/SPAN&gt;" and also replace the "authentication host-mode multi-host" with "&lt;SPAN&gt;authentication host-mode multi-auth"?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5251078#M594414</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-22T16:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5251563#M594435</link>
      <description>&lt;P&gt;Hello Aref,&lt;/P&gt;&lt;P&gt;Tried above suggestion, but still the same problem. Switchport goes into dropped state.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 12:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5251563#M594435</guid>
      <dc:creator>Shivesh Mishra</dc:creator>
      <dc:date>2025-01-23T12:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Switch config for ports with dot1x and MAB at same time - auth ord</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5252567#M594482</link>
      <description>&lt;P&gt;Hello Shivesh. Not really sure, I would think maybe the switch software is hitting some bugs, I don't know. I would try to look into the switch software release notes, and upgrade it to the latest recommended release.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 12:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-config-for-ports-with-dot1x-and-mab-at-same-time-auth/m-p/5252567#M594482</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-25T12:45:46Z</dc:date>
    </item>
  </channel>
</rss>

