<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wireless 802.1x with MAB as fallback and FreeRadius in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3802559#M28438</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;with more and more IoT devices&amp;nbsp;entering the market we need to design our wireless infrastructure&lt;/P&gt;
&lt;P&gt;to accomodate IoT devices which support 802.1x but also devices which do not support 802.1x.&lt;/P&gt;
&lt;P&gt;As the best practice is not to exceed the number of 4 SSIDs the ideal solution would look like one SSID only with 802.1x enabled and MAC filtering for MAB (MAC Authentication Bypass) for IoT devices not supporting 802.1x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Cisco Switching world this is no problem at all but does anyone have experience how this can be handled in the Cisco Wireless world (with 8540 WLCs and release 8.5) ?&lt;/P&gt;
&lt;P&gt;I know there is the new feature Identity PSK but this would also require a separate SSID for non-802.1x devices but how can both devices types be covered by 1 SSID ?&lt;/P&gt;
&lt;P&gt;In other discussions it's stated that it should be possible (though not officially supported) with Cisco ISE as radius server but has anyone managed to implement 1 SSID with 802.1x and MAB for non-802.1x devices using FreeRadius as backend ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and best regards,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 16:51:49 GMT</pubDate>
    <dc:creator>ciscoprolin</dc:creator>
    <dc:date>2021-07-05T16:51:49Z</dc:date>
    <item>
      <title>Wireless 802.1x with MAB as fallback and FreeRadius</title>
      <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3802559#M28438</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;with more and more IoT devices&amp;nbsp;entering the market we need to design our wireless infrastructure&lt;/P&gt;
&lt;P&gt;to accomodate IoT devices which support 802.1x but also devices which do not support 802.1x.&lt;/P&gt;
&lt;P&gt;As the best practice is not to exceed the number of 4 SSIDs the ideal solution would look like one SSID only with 802.1x enabled and MAC filtering for MAB (MAC Authentication Bypass) for IoT devices not supporting 802.1x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Cisco Switching world this is no problem at all but does anyone have experience how this can be handled in the Cisco Wireless world (with 8540 WLCs and release 8.5) ?&lt;/P&gt;
&lt;P&gt;I know there is the new feature Identity PSK but this would also require a separate SSID for non-802.1x devices but how can both devices types be covered by 1 SSID ?&lt;/P&gt;
&lt;P&gt;In other discussions it's stated that it should be possible (though not officially supported) with Cisco ISE as radius server but has anyone managed to implement 1 SSID with 802.1x and MAB for non-802.1x devices using FreeRadius as backend ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and best regards,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3802559#M28438</guid>
      <dc:creator>ciscoprolin</dc:creator>
      <dc:date>2021-07-05T16:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 802.1x with MAB as fallback and FreeRadius</title>
      <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3802594#M28439</link>
      <description>Hi,&lt;BR /&gt;you can do few checks, even i am not tried yes i can suggest below.&lt;BR /&gt;&lt;BR /&gt;1 - enable MAC filtering for SSID and add MAC to whitelist in controller (not radius)&lt;BR /&gt;2 - select 802.1x for next step.&lt;BR /&gt;&lt;BR /&gt;but i dont think you can use radius server for both 1x and MAB</description>
      <pubDate>Fri, 15 Feb 2019 09:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3802594#M28439</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2019-02-15T09:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 802.1x with MAB as fallback and FreeRadius</title>
      <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3804022#M28440</link>
      <description>Not using Freeradius for this, but I also think it's possible on ISE.&lt;BR /&gt;You'd need to do a chained policy, which first checks the MAC and if that one fails, do 802.1x. I'm not sure if FreeRadius is capable of this.&lt;BR /&gt;Another variant (if your FreeRadius is just a proxy for an Active Directory) might be this:&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/MS/Access_Control/Configuring_Microsoft_NPS_for_MAC-Based_RADIUS_-_MS_Switches" target="_blank"&gt;https://documentation.meraki.com/MS/Access_Control/Configuring_Microsoft_NPS_for_MAC-Based_RADIUS_-_MS_Switches&lt;/A&gt;</description>
      <pubDate>Mon, 18 Feb 2019 12:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3804022#M28440</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-02-18T12:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 802.1x with MAB as fallback and FreeRadius</title>
      <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3804173#M28441</link>
      <description>&lt;P&gt;Thanks for your appreciated reply. We are able to use FreeRadius in connection with the Identity PSK Feature offered by Cisco WLCs since release 8.5.&lt;/P&gt;
&lt;P&gt;With the I-PSK we need to sacrifice a separate SSID (apart from 802.1x) that's why we're considering MAB for Wireless as an alternative to I-PSK.&lt;/P&gt;
&lt;P&gt;With Cisco switches MAB is absolutely no problem but with the Cisco WLC we're not sure. Found another article in which it was stated it does not work with the WLC:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/policy-and-access/wlc-mab-with-802-1x-authentication/m-p/3747331" target="_blank"&gt;https://community.cisco.com/t5/policy-and-access/wlc-mab-with-802-1x-authentication/m-p/3747331&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;We'll try to test it.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 15:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3804173#M28441</guid>
      <dc:creator>ciscoprolin</dc:creator>
      <dc:date>2019-02-18T15:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 802.1x with MAB as fallback and FreeRadius</title>
      <link>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3805041#M28442</link>
      <description>Yeah, wireless 802.1x and wired 802.1x are sadly not exactly the same thing. I hope it will work for you.</description>
      <pubDate>Tue, 19 Feb 2019 16:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-802-1x-with-mab-as-fallback-and-freeradius/m-p/3805041#M28442</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-02-19T16:07:20Z</dc:date>
    </item>
  </channel>
</rss>

