<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Doubts about Dot1x with failover method MAB in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034374#M3083</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I configured the port of the test switch to use Dot1x as the first authentication, and as a fallback in case the dot1x failed, to use the Mab type authentication.&lt;/P&gt;&lt;P&gt;Everything seems to work correctly. But I have a question:&lt;/P&gt;&lt;P&gt;If I connected a New PC that is not present in the ISE Mab database, should the PC not be able to access the network?&lt;/P&gt;&lt;P&gt;Bye,&lt;/P&gt;&lt;P&gt;JF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 14:13:22 GMT</pubDate>
    <dc:creator>ifabrizio</dc:creator>
    <dc:date>2024-03-05T14:13:22Z</dc:date>
    <item>
      <title>Doubts about Dot1x with failover method MAB</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034374#M3083</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I configured the port of the test switch to use Dot1x as the first authentication, and as a fallback in case the dot1x failed, to use the Mab type authentication.&lt;/P&gt;&lt;P&gt;Everything seems to work correctly. But I have a question:&lt;/P&gt;&lt;P&gt;If I connected a New PC that is not present in the ISE Mab database, should the PC not be able to access the network?&lt;/P&gt;&lt;P&gt;Bye,&lt;/P&gt;&lt;P&gt;JF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 14:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034374#M3083</guid>
      <dc:creator>ifabrizio</dc:creator>
      <dc:date>2024-03-05T14:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Doubts about Dot1x with failover method MAB</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034375#M3084</link>
      <description>&lt;P&gt;Follows the port switch config:&lt;/P&gt;&lt;P&gt;switchport access vlan 71&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree guard root&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 14:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034375#M3084</guid>
      <dc:creator>ifabrizio</dc:creator>
      <dc:date>2024-03-05T14:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Doubts about Dot1x with failover method MAB</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034376#M3085</link>
      <description>&lt;P&gt;according to condition in Authentication policy, if you select if the endpoint unknown the action continue for authz if not then the user will failed to access&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 14:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/doubts-about-dot1x-with-failover-method-mab/m-p/5034376#M3085</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-05T14:18:16Z</dc:date>
    </item>
  </channel>
</rss>

