<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x Open Access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368159#M599736</link>
    <description>&lt;P&gt;I've configured a switch port for Open Access as per the&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;but when authentication fails (as expected) the port does not pass traffic for the data vlan. I have a phone connected to the port with MAB authentication and a PC connected through the phone. The PC does not have 802.1x configured yet hence why I want it to fail open.&lt;/P&gt;&lt;P&gt;Is there something obvious I'm missing? My configuration is below:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;interface GigabitEthernet1/0/17&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport access vlan 11&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport mode access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport voice vlan 51&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;device-tracking attach-policy IPDT_POLICY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication periodic&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication timer reauthenticate server&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;access-session port-control auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;spanning-tree portfast&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;service-policy type control subscriber PORT-AUTH-POLICY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;end&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;show authentication sessions&lt;BR /&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/17 c81f.eaf3.d63c mab VOICE Auth 0B00020A000025832DB071FA&lt;BR /&gt;Gi1/0/17 f4a8.0d09.7575 N/A UNKNOWN Unauth 0B00020A000025822DB053F0&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Feb 2026 12:57:14 GMT</pubDate>
    <dc:creator>memgtdg1</dc:creator>
    <dc:date>2026-02-06T12:57:14Z</dc:date>
    <item>
      <title>802.1x Open Access</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368159#M599736</link>
      <description>&lt;P&gt;I've configured a switch port for Open Access as per the&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;but when authentication fails (as expected) the port does not pass traffic for the data vlan. I have a phone connected to the port with MAB authentication and a PC connected through the phone. The PC does not have 802.1x configured yet hence why I want it to fail open.&lt;/P&gt;&lt;P&gt;Is there something obvious I'm missing? My configuration is below:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;interface GigabitEthernet1/0/17&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport access vlan 11&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport mode access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;switchport voice vlan 51&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;device-tracking attach-policy IPDT_POLICY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication periodic&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;authentication timer reauthenticate server&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;access-session port-control auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;spanning-tree portfast&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;service-policy type control subscriber PORT-AUTH-POLICY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;end&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;show authentication sessions&lt;BR /&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/17 c81f.eaf3.d63c mab VOICE Auth 0B00020A000025832DB071FA&lt;BR /&gt;Gi1/0/17 f4a8.0d09.7575 N/A UNKNOWN Unauth 0B00020A000025822DB053F0&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368159#M599736</guid>
      <dc:creator>memgtdg1</dc:creator>
      <dc:date>2026-02-06T12:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Open Access</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368194#M599740</link>
      <description>&lt;P&gt;how about adding some more config on the port and test.&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN class="undefined" aria-owns="action-menu-parent-container"&gt;authentication open
 access-session host-mode multi-domain
 authentication event fail action next-method&lt;/SPAN&gt;&lt;/CODE&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 14:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368194#M599740</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-06T14:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Open Access</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368206#M599741</link>
      <description>&lt;P&gt;Hi, thanks for your reply. I should have mentioned that I am using&amp;nbsp;IBNS 2.0. I believe authentication open and access-session host-mode multi-domain are the defaults as they don't show in config when I enter those commands.&lt;/P&gt;&lt;P&gt;I am also using a policy map that covers the methods:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;policy-map type control subscriber PORT-AUTH-POLICY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;event session-started match-all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 authenticate using dot1x aaa authc-list AAA_RADIUS authz-list AAA_RADIUS priority 10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;event authentication-failure match-first&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;5 class DOT1X_FAILED do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 terminate dot1x&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 authenticate using mab aaa authc-list AAA_RADIUS authz-list AAA_RADIUS priority 20&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 class DOT1X_NO_RESP do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 terminate dot1x&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 authenticate using mab aaa authc-list AAA_RADIUS authz-list AAA_RADIUS priority 20&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 class MAB_FAILED do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 terminate mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 authentication-restart 60&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;40 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 terminate dot1x&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 terminate mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;30 authentication-restart 60&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;event agent-found match-all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 terminate mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;20 authenticate using dot1x priority 10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;event inactivity-timeout match-all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 clear-session&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;event authentication-success match-all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;10 activate service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 14:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368206#M599741</guid>
      <dc:creator>memgtdg1</dc:creator>
      <dc:date>2026-02-06T14:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Open Access</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368207#M599742</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1924927"&gt;@memgtdg1&lt;/a&gt;&amp;nbsp;To support both VOICE (which is the MAC the switch sees first) and DATA (which is the MAC the switch sees second), you need to run in multi-domain mode, configure at port level&amp;nbsp;&lt;STRONG&gt;access-session host-mode multi-domain&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;If you're planning to use IBNS 2.0, it's recommended to use templates for any MAB/DOT1x/authentication related configurations; a good, simple and concise guide you can get here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.wiresandwi.fi/blog/solid-config-cisco-ibns-2-0-concurrent-802-1x-mab-switch-configuration-ios-xe" target="_blank"&gt;https://www.wiresandwi.fi/blog/solid-config-cisco-ibns-2-0-concurrent-802-1x-mab-switch-configuration-ios-xe&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 14:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368207#M599742</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-02-06T14:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Open Access</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368209#M599743</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1924927"&gt;@memgtdg1&lt;/a&gt;&amp;nbsp;In IBNS 2.0, open access is enabled by default, no need to activate it via&amp;nbsp;&lt;STRONG&gt;authentication&lt;/STRONG&gt; open;&amp;nbsp;also, while using IBNS 2.0, stop using&amp;nbsp;&lt;STRONG&gt;authentication&amp;nbsp;&lt;/STRONG&gt;commands, instead use&amp;nbsp;&lt;STRONG&gt;access-session&amp;nbsp;&lt;/STRONG&gt;commands, to avoid running into let's say unexpected behaviour.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Not sure what the default host-mode is, regardless, what you configure should show up in the configuration. Also, ensure that while working in open mode, at least initially, one ISE you don't push any authorisations, just Access-Accept.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I also suggest going through this presentation, aside to the already provided document:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2025/pdf/BRKCRT-3002.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2025/pdf/BRKCRT-3002.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 15:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-open-access/m-p/5368209#M599743</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-02-06T15:05:59Z</dc:date>
    </item>
  </channel>
</rss>

