02-13-2020 09:48 PM - edited 02-21-2020 11:13 AM
I'm testing my wireless authentication.
You have set policies for MAB and 1X.
Rule1 = MAB
Rule2 = 1X
Like the ACL, i know that policies are applied from top to bottom.
Wireless authentication performs 1X authentication after MAB authentication in order.
This is as I wish.
However, if you change the rule order, only 1X authentication is performed.
Why not perform the MAB certification of Rule1 when the order is changed?
Rule2 = 1X
Rule1 = MAB
Is 1X authentication a higher priority than MAB?
Why not perform the MAB certification of Rule1 when the order is changed?
Solved! Go to Solution.
02-13-2020 10:04 PM
02-18-2020 09:37 PM
You can't authenticate an endpoint with MAB on an 802.1x secured Wireless SSID. If the SSID is configured for 802.1x, the endpoint must authenticate using an 802.1x authentication method (PEAP, EAP-TLS, etc).
Unlike Wired switches, there is no concept of falling back to a MAB authentication if 802.1x fails for Wireless.
You can only authenticate an endpoint with MAB when using an Open or PSK (requires WLC 8.3 code or newer) SSID.
Cheers,
Greg
02-13-2020 10:04 PM
02-17-2020 12:04 AM
02-17-2020 07:34 AM
02-18-2020 09:04 PM
The current MAB rule is Permit if the client's MAC exists in the endpoint group.
But I would like to know why 1X authentication is Rule 1 and MAB authentication is Rule2 and does not go through MAB authentication.
Is there a problem?
02-18-2020 09:37 PM
You can't authenticate an endpoint with MAB on an 802.1x secured Wireless SSID. If the SSID is configured for 802.1x, the endpoint must authenticate using an 802.1x authentication method (PEAP, EAP-TLS, etc).
Unlike Wired switches, there is no concept of falling back to a MAB authentication if 802.1x fails for Wireless.
You can only authenticate an endpoint with MAB when using an Open or PSK (requires WLC 8.3 code or newer) SSID.
Cheers,
Greg
02-21-2020 02:35 PM
Rule 1 has the condition on Wireless MAB so only authentications matching that will report hits. The same goes for Rule 2 on Wireless 802.1X.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide