<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAC Blocking During Cisco ISE Authentication Phase in Secure Access Discussions</title>
    <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5554170#M204</link>
    <description>&lt;P&gt;Glad to hear it's working as expected. Tbh, I don't think there is a way to reference a list or an identity group in this case. However, one thing you could potentially explore would be to go through ISE endpoint groups and make sure none of the MACs that should be blocked are there, and then make sure that the option "If user not found" are set to drop as it shows on "2.png" screenshot on your authentication rule that would have "Permit" action configured.&lt;/P&gt;
&lt;P&gt;In other words in ISE you can deal with MAB authentications in two ways, one way would be to say if a MAC doesn't already exist in ISE I want to block it from passing the authentication, and that's where you configure the "If user not found" option to drop. The other way which we usually use for guest traffic would be to say pass authentication of any MAC even if the MAC doesn't exist in ISE and that's where you set the option "If user not found" to be allow/pass. With this option ISE endpoint database will keep adding any MAC that would be seen by ISE for a first time.&lt;/P&gt;
&lt;P&gt;Think about a guest portal that you configure where you want any guest to be allowed to go through the portal registration (or even a hotspot) and then connect to the network. In that case you would have two options, option one would be to get the MAC addresses of all guests ahead of time and that is a nightmare and it's not even practical or option two would be to allow any MAC to pass authentication and then restric accesses with the authorization rules. Option one here would need the option "If user not found" to be set to drop and option two would need the option "If user not found" to be set to allow.&lt;/P&gt;
&lt;P&gt;Also, as a side note, passing authentication doesn't mean getting access to the network as you could see on your environment. You can see many customers deployments allow MAC addresses authentications but then restrict or deny them access to the network by the authorization rules.&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2026 09:40:37 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2026-05-21T09:40:37Z</dc:date>
    <item>
      <title>MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553843#M193</link>
      <description>&lt;P&gt;Hello. I have a MAC address that I need to block. I added this MAC address to the Blacklist group (Administration - Identity Management - Groups - Endpoint Identity Groups - Blacklist). I created a rule in the Authorization Policy section that blocks access if there's a match on the blacklist. This works correctly during authorization.&lt;/P&gt;&lt;P&gt;The problem is that I need to block the device during authentication, but I can't create such a rule in the Authentication Policy section; there's no Blacklist in Authentication Conditions.&lt;/P&gt;&lt;P&gt;How can I block a MAC address during authentication on Cisco ISE?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 04:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553843#M193</guid>
      <dc:creator>schikannikov</dc:creator>
      <dc:date>2026-05-20T04:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553844#M194</link>
      <description>&lt;P&gt;i guess the Blacklist/Endpoint Identity Group is typically evaluated during the Authorization phase, not during Authentication. That is why you cannot directly use the Blacklist group as a condition in the Authentication Policy.&lt;/P&gt;&lt;P&gt;if you want to block the mac before it even hits ISE then you need to local it locally on the switch.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 05:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553844#M194</guid>
      <dc:creator>Singhaam</dc:creator>
      <dc:date>2026-05-20T05:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553848#M195</link>
      <description>&lt;P&gt;you can create a&amp;nbsp;Authorization Policy - Global Exceptions&amp;nbsp;so the mac is blocked globally in ISE&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Singhaam_0-1779254445862.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/282458iE2683089D25091E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Singhaam_0-1779254445862.png" alt="Singhaam_0-1779254445862.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 05:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553848#M195</guid>
      <dc:creator>Singhaam</dc:creator>
      <dc:date>2026-05-20T05:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553882#M196</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide below details to understand in the better way&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authentication Method: Are you using:&lt;UL&gt;&lt;LI&gt;MAB (MAC Authentication Bypass)?&lt;/LI&gt;&lt;LI&gt;802.1X authentication?&lt;/LI&gt;&lt;LI&gt;Both?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Deployment Type: Is this for:&lt;UL&gt;&lt;LI&gt;Wired network access?&lt;/LI&gt;&lt;LI&gt;Wireless network access?&lt;/LI&gt;&lt;LI&gt;Both?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Desired Outcome: When a blacklisted MAC address attempts to authenticate, do you want to:&lt;UL&gt;&lt;LI&gt;Completely reject/drop the authentication request?&lt;/LI&gt;&lt;LI&gt;Authenticate but assign to a quarantine/restricted VLAN?&lt;/LI&gt;&lt;LI&gt;Redirect to a portal page?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;ISE Version: What version of Cisco ISE are you running?&lt;/LI&gt;&lt;LI&gt;Current Behavior: When the blacklisted MAC currently gets pass authentication, what authorization result does it receive?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 06:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553882#M196</guid>
      <dc:creator>ashish.kushwaha</dc:creator>
      <dc:date>2026-05-20T06:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553883#M197</link>
      <description>&lt;H3&gt;What I Understand So Far:&lt;/H3&gt;&lt;P&gt;Your Core Issue: You can block MAC addresses during the Authorization phase using Endpoint Identity Groups (Blacklist), but there's no direct Blacklist condition available in Authentication Policy rules, so you cannot block devices before they even authenticate.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 06:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553883#M197</guid>
      <dc:creator>ashish.kushwaha</dc:creator>
      <dc:date>2026-05-20T06:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553885#M198</link>
      <description>&lt;P&gt;1. Microsoft Active Directory is used for authentication.&lt;BR /&gt;2. I need to disable MAC addresses for the wireless network.&lt;BR /&gt;3. Desired result: completely reject the device's connection attempt.&lt;BR /&gt;4. ISE version 2.2.0.470.&lt;BR /&gt;5. The MAC address, while blacklisted, attempts to authenticate but is unable to complete due to an incorrect password.&lt;BR /&gt;I need to prevent the password prompt from appearing.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 07:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553885#M198</guid>
      <dc:creator>schikannikov</dc:creator>
      <dc:date>2026-05-20T07:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553888#M199</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 07:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553888#M199</guid>
      <dc:creator>schikannikov</dc:creator>
      <dc:date>2026-05-20T07:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553893#M200</link>
      <description>&lt;P&gt;Cisco ISE processes network access in two sequential phases:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Authentication Phase: Verifies the identity of the user/device&lt;/LI&gt;&lt;LI&gt;Authorization Phase: Determines what access the authenticated identity should receive&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The core issue: The Endpoint Identity Group Blacklist feature only works in Authorization Policies, not in Authentication Policies. When using 802.1X with Active Directory authentication for wireless networks:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISE first attempts to authenticate the user credentials&lt;/LI&gt;&lt;LI&gt;The device gets a password prompt during 802.1X negotiation&lt;/LI&gt;&lt;LI&gt;Only AFTER successful authentication does ISE check the Authorization Policy&lt;/LI&gt;&lt;LI&gt;By this time, the user has already seen and potentially interacted with the login screen&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is a design characteristic of how 802.1X works - it's credential-based authentication, so the authentication phase expects user input before the device identity can be fully evaluated.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So for this you can explore with the other method.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Configure the wireless SSID to attempt MAC Authentication Bypass (MAB) first, followed by 802.1X. This allows ISE to check the device's MAC address during authentication (before credentials are requested) and block blacklisted devices immediately.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Architecture Flow&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Device connects → WLC attempts MAB authentication first → ISE checks MAC address&lt;BR /&gt;↓&lt;BR /&gt;If MAC is blacklisted → Reject immediately (no password prompt)&lt;BR /&gt;↓&lt;BR /&gt;If MAC is not blacklisted → Fall back to 802.1X → AD authentication → Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 07:44:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553893#M200</guid>
      <dc:creator>ashish.kushwaha</dc:creator>
      <dc:date>2026-05-20T07:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553894#M201</link>
      <description>&lt;P&gt;Can you please tell me where this is configured?&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 07:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553894#M201</guid>
      <dc:creator>schikannikov</dc:creator>
      <dc:date>2026-05-20T07:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553899#M202</link>
      <description>&lt;P&gt;Please try this and see if it works.&lt;/P&gt;
&lt;P&gt;- Go to your interested authentication policy&lt;BR /&gt;- A&lt;SPAN&gt;dd an authentication rule above the MAB common one&lt;BR /&gt;- Add the compound condition "Wired_MAB" or "Wireless_MAB" or both&lt;BR /&gt;- Add a new condition and select "Radius" from the list&lt;BR /&gt;- Add "Calling-Station-ID" condition&lt;BR /&gt;- Add the MAC address that you want to block&lt;BR /&gt;- Set the action of that rule to "Deny"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 08:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5553899#M202</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-20T08:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5554098#M203</link>
      <description>&lt;P&gt;This does what I need! I did as you said (I attached screenshots to the message), and the device started getting blocked. My question is: is there a way to use a list of devices instead of just one MAC address?&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 04:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5554098#M203</guid>
      <dc:creator>schikannikov</dc:creator>
      <dc:date>2026-05-21T04:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Blocking During Cisco ISE Authentication Phase</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5554170#M204</link>
      <description>&lt;P&gt;Glad to hear it's working as expected. Tbh, I don't think there is a way to reference a list or an identity group in this case. However, one thing you could potentially explore would be to go through ISE endpoint groups and make sure none of the MACs that should be blocked are there, and then make sure that the option "If user not found" are set to drop as it shows on "2.png" screenshot on your authentication rule that would have "Permit" action configured.&lt;/P&gt;
&lt;P&gt;In other words in ISE you can deal with MAB authentications in two ways, one way would be to say if a MAC doesn't already exist in ISE I want to block it from passing the authentication, and that's where you configure the "If user not found" option to drop. The other way which we usually use for guest traffic would be to say pass authentication of any MAC even if the MAC doesn't exist in ISE and that's where you set the option "If user not found" to be allow/pass. With this option ISE endpoint database will keep adding any MAC that would be seen by ISE for a first time.&lt;/P&gt;
&lt;P&gt;Think about a guest portal that you configure where you want any guest to be allowed to go through the portal registration (or even a hotspot) and then connect to the network. In that case you would have two options, option one would be to get the MAC addresses of all guests ahead of time and that is a nightmare and it's not even practical or option two would be to allow any MAC to pass authentication and then restric accesses with the authorization rules. Option one here would need the option "If user not found" to be set to drop and option two would need the option "If user not found" to be set to allow.&lt;/P&gt;
&lt;P&gt;Also, as a side note, passing authentication doesn't mean getting access to the network as you could see on your environment. You can see many customers deployments allow MAC addresses authentications but then restrict or deny them access to the network by the authorization rules.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 09:40:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/mac-blocking-during-cisco-ise-authentication-phase/m-p/5554170#M204</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-21T09:40:37Z</dc:date>
    </item>
  </channel>
</rss>

