<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSID with Dot1X and MAB in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855213#M257145</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;Any options if i can have one SSID on Cisco 5520 WLC which supports dot1X as well as MAB?&lt;/P&gt;
&lt;P&gt;Actually we have issues in some devices where certificate can not be pushed and we want to connect same devices on same SSID throgh MAB.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2023 12:45:59 GMT</pubDate>
    <dc:creator>Noovi</dc:creator>
    <dc:date>2023-06-15T12:45:59Z</dc:date>
    <item>
      <title>SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855213#M257145</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;Any options if i can have one SSID on Cisco 5520 WLC which supports dot1X as well as MAB?&lt;/P&gt;
&lt;P&gt;Actually we have issues in some devices where certificate can not be pushed and we want to connect same devices on same SSID throgh MAB.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 12:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855213#M257145</guid>
      <dc:creator>Noovi</dc:creator>
      <dc:date>2023-06-15T12:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855234#M257146</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;This is the option you can have with one SSID. Considering 9800 WLC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_multiple_authc_for_a_client.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_multiple_authc_for_a_client.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table" border="1" width="100%"&gt;
&lt;TBODY class="tbody"&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Layer 2&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Layer 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Supported&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB + PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;-&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;&lt;STRONG&gt;MAB + 802.1X&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;-&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB Failure&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;802.1X&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;802.1X&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;-&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;iPSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;-&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;iPSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;iPSK + MAB&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;Yes&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;iPSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;No&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB Failure + PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;LWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;No&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;MAB Failure + PSK&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;CWA&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="entry"&gt;
&lt;P class="p"&gt;No&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 15 Jun 2023 13:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855234#M257146</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-15T13:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855243#M257148</link>
      <description>&lt;P&gt;As I know mab + 802.1X both is l2 auth' but mab here is not use for auth it used for wlc to bulid connection database for this user.&lt;/P&gt;
&lt;P&gt;Mab auth only without any other l2 auth need you add mac address to wlc or use extended server for mac.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 13:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855243#M257148</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-15T13:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855994#M257165</link>
      <description>&lt;P&gt;I think&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/81762"&gt;@Noovi&lt;/a&gt;&amp;nbsp;is asking if it's possible to replace dot1X with MAB due to the failed to push certificates on devices. I think you ar using EAP-TLS to perform computer authentication so that's why you want to filter them when connecting.&lt;/P&gt;
&lt;P&gt;My recommendation is that you keep using dot1X, but instead of using certificate validation (EAP-TLS) on the RADIUS policies you use user credentials only (PEAP). Then if you want to add this "extra" layer of security to limit the connection to those specific devices using MAB you can do it.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 06:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4855994#M257165</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2023-06-16T06:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4856034#M257174</link>
      <description>&lt;P&gt;Short answer is No, you can enable both mac filtering and 802.1X on same SSID but means WLC need the mac address in its database for endpoint to perform 802.1X, its more of an AND option than OR option.&lt;/P&gt;
&lt;P&gt;one option might be to have 2 separate SSID with same name and use mac filtering for one and 802.1X for another one, and when you are configuring your policy and wireless profile you can push correct profile to relevant devices or advertise the one with mac filtering in areas where you have devices not supporting cert .. you get the idea, it not the most traditional way, but its just an option if your device location and environment permits. Best it to have 2 seperate SSIDs or what JPavonM recommended.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 07:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4856034#M257174</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-06-16T07:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSID with Dot1X and MAB</title>
      <link>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4857125#M257233</link>
      <description>&lt;P&gt;Doing just this but needing to use 2 SSIDs&lt;/P&gt;
&lt;P&gt;- iPSK for devices that dont support 802.1x (EAP-TLS/ PEAP)&amp;nbsp;&lt;BR /&gt;- 802.1x for devices that do support it&lt;/P&gt;
&lt;P&gt;Have default PSK to use in an onbaording workflow where they just get internet access to reach the MDM to provision the certificate, and iPSK policy for devices that dont support it to get correct VLAN assignment&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 23:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssid-with-dot1x-and-mab/m-p/4857125#M257233</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2023-06-18T23:21:03Z</dc:date>
    </item>
  </channel>
</rss>

