cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
823
Views
10
Helpful
3
Replies

Default MAB authentication

aspry
Level 1
Level 1

Hello,

 

I note from logs that our  WIFI users are authenticating via the Default MAB rule in the default policy set and then authenticating via a 802.1x rule created within a policy set I have created, which is further up in the policy sets.

If I disable the default MAB authentication rule within the default policy set the user then fails authentication in the 802.1x rule.

 

It appears that the user first uses MAB then 802.1x.

 

Is there a way around this, I only want users to authenticate in the Policy Set that I created and not use the default Policy Set.

 

Thanks

Andy

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

If you are using Cisco WLC, you might have the WLAN configured for MAC Authentication Failover to 802.1X.

You might want to take a look at this guide -- Configure 802.1x Authentication with PEAP, ISE 2.1 and WLC 8.3 

View solution in original post

3 Replies 3

varma10
Level 1
Level 1

Try changing the order in authentication policy and give it a try.

 

ISE tried policies in sequential order. Also, for authentication failing via dot1x a quick view on the policy might give an idea.

JohnNewman7082
Level 1
Level 1

Please share your auth rules to be sure your 802.1x rule does not have any coorelation with MAB.

 

Really though, wifi should only be doing MAB or dot1x, not both.  If you want to use dot1x, please ensure MAC filtering is disabled on the wlan.

hslai
Cisco Employee
Cisco Employee

If you are using Cisco WLC, you might have the WLAN configured for MAC Authentication Failover to 802.1X.

You might want to take a look at this guide -- Configure 802.1x Authentication with PEAP, ISE 2.1 and WLC 8.3