12-07-2018 11:50 AM
Hello, has anyone ever done any tests around False Positive Rates and False Negative Rates with regard to 802.1x performance (particularly as it pertains the the metrics below)? Or any existing test cases or test methods you can share? Also, if you have guidance for validating FNR/FPR from a posture perspective? Any help would be greatly appreciated!
The Acceptable Quality Limit in the RFS from DHS:
<=.1% FPR of blocked connections; <=1% FNR of unblocked connections within a 30 day period as demonstrated in level 1, level 3 and/or OT&E test events.
Solved! Go to Solution.
12-10-2018 09:31 AM
12-09-2018 01:59 PM
Can you please explain FNR and FPR in more detail? I don't quite follow what this has to do with 802.1X in particular.
12-10-2018 08:46 AM
Sure - basically, with ISE:
1. What percentage of 802.1X sessions that should have been authenticated successfully, were falsely blocked? (Type 1)
2. And, what percentage of total allowed sessions, should have actually been blocked? (Type 2)
Decision |
H0 True |
HO False |
Accept Device |
Good, The device is authorized and is allowed |
Type 2 Error - The unauthorized device is allowed on the network |
Reject Device |
Type 1 Error - The authorized device is blocked |
Good, the device is not authorized and is not allowed |
12-10-2018 09:31 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide