<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with MAB authentication on IOL switch with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335475#M598392</link>
    <description>&lt;P&gt;i used pnetlab - IOL have some versions have&amp;nbsp; Limitations&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i tried below version as per my notes it works for me&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SW4#show version&lt;BR /&gt;Cisco IOS Software, Linux Software (I86BI_LINUXL2-ADVENTERPRISEK9-M), Version 15.2(CML_NIGHTLY_20190423)FLO_DSGS7, EARLY DEPLOYMENT DEVELOPMENT BUILD, synced to V152_6_0_81_E&lt;/P&gt;
&lt;P&gt;interface eth 0/1&amp;nbsp;&lt;BR /&gt;switchport host&lt;BR /&gt;authentication open&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab&lt;BR /&gt;authentication priority mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;SW4#show authentication sessions interface ethernet 0/1 details&lt;BR /&gt;Interface: Ethernet0/1&lt;BR /&gt;MAC Address: 50d6.9f00.9dff&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 5.2.35.2&lt;BR /&gt;User-Name: 50-D6-9F-00-9D-FF&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 225s&lt;BR /&gt;Common Session ID: 960107220000000E00282A68&lt;BR /&gt;Acct Session ID: 0x00000001&lt;BR /&gt;Handle: 0x6D000003&lt;BR /&gt;Current Policy: POLICY_Et0/1&lt;/P&gt;
&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: xxxxxxxxxxxxxx (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: 305&lt;BR /&gt;ACS ACL: xxxxxxxxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;
&lt;P&gt;mab Authc Success&lt;/P&gt;</description>
    <pubDate>Thu, 02 Oct 2025 15:24:07 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2025-10-02T15:24:07Z</dc:date>
    <item>
      <title>Problem with MAB authentication on IOL switch with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335348#M598373</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to configure MAB authentication using Cisco ISE and a switch, but I'm running into an issue:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;When I do &lt;STRONG&gt;not&lt;/STRONG&gt; configure MAB on the switch, the MAC address of the client shows up normally in the MAC address table.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When I enable the MAB configuration, the switch does &lt;STRONG&gt;not&lt;/STRONG&gt; receive any MAC address from the client (it shows 0000.0000.0000), even though the MAB process is running.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Additional info:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;mab config&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anfeldendani1996_0-1759399383233.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252906i0C8741856CDF7010/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anfeldendani1996_0-1759399383233.png" alt="anfeldendani1996_0-1759399383233.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;results :&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anfeldendani1996_1-1759399403109.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/252907i2B9BB5BBAA638514/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anfeldendani1996_1-1759399403109.png" alt="anfeldendani1996_1-1759399403109.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Switch version:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Cisco IOS Software, Solaris Software (I86BI_LINUXL2-ADVENTERPRISEK9-M), Experimental Version &lt;SPAN class=""&gt;15.1&lt;/SPAN&gt;(&lt;SPAN class=""&gt;20140814&lt;/SPAN&gt;:&lt;SPAN class=""&gt;053243&lt;/SPAN&gt;) &lt;SPAN class=""&gt;[mmen 112]&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When using &lt;STRONG&gt;802.1X&lt;/STRONG&gt;, authentication works correctly.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It seems like MAB is not learning or passing the client MAC address properly&lt;/P&gt;&lt;P&gt;Has anyone faced this issue before? Is it a known limitation/bug of this IOL image?&lt;BR /&gt;Any workaround&amp;nbsp; to test MAB in a lab environment?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 10:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335348#M598373</guid>
      <dc:creator>anfeldendani1996</dc:creator>
      <dc:date>2025-10-02T10:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MAB authentication on IOL switch with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335374#M598375</link>
      <description>&lt;P&gt;have you tried vIOSL2 ? or Cat9K image.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 11:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335374#M598375</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-10-02T11:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MAB authentication on IOL switch with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335465#M598390</link>
      <description>&lt;P&gt;hello ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for the suggesting ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'im using pnetlab , and i don't have access to the CLI , so i can't upload images&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 15:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335465#M598390</guid>
      <dc:creator>anfeldendani1996</dc:creator>
      <dc:date>2025-10-02T15:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MAB authentication on IOL switch with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335475#M598392</link>
      <description>&lt;P&gt;i used pnetlab - IOL have some versions have&amp;nbsp; Limitations&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i tried below version as per my notes it works for me&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SW4#show version&lt;BR /&gt;Cisco IOS Software, Linux Software (I86BI_LINUXL2-ADVENTERPRISEK9-M), Version 15.2(CML_NIGHTLY_20190423)FLO_DSGS7, EARLY DEPLOYMENT DEVELOPMENT BUILD, synced to V152_6_0_81_E&lt;/P&gt;
&lt;P&gt;interface eth 0/1&amp;nbsp;&lt;BR /&gt;switchport host&lt;BR /&gt;authentication open&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab&lt;BR /&gt;authentication priority mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;SW4#show authentication sessions interface ethernet 0/1 details&lt;BR /&gt;Interface: Ethernet0/1&lt;BR /&gt;MAC Address: 50d6.9f00.9dff&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 5.2.35.2&lt;BR /&gt;User-Name: 50-D6-9F-00-9D-FF&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 225s&lt;BR /&gt;Common Session ID: 960107220000000E00282A68&lt;BR /&gt;Acct Session ID: 0x00000001&lt;BR /&gt;Handle: 0x6D000003&lt;BR /&gt;Current Policy: POLICY_Et0/1&lt;/P&gt;
&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: xxxxxxxxxxxxxx (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecure&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: 305&lt;BR /&gt;ACS ACL: xxxxxxxxxxxxxxxxx&lt;/P&gt;
&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;
&lt;P&gt;mab Authc Success&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 15:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-mab-authentication-on-iol-switch-with-ise/m-p/5335475#M598392</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-10-02T15:24:07Z</dc:date>
    </item>
  </channel>
</rss>

