09-20-2018 02:28 AM - edited 09-20-2018 02:31 AM
Hello,
I have a switch port configured to authenticate with order first MAB and then dot1X. The priority has been setup in the opposite way, first dot1X then MAB. I would like to re-authenticate devices (phones in this case) but it seems when I run "clear dot1x int ..." or "clear authentication sessions int ..." the switch is not sending the EAP-Request/Identity and MAB occurs after running them.
Is there any command to force the switch to use dot1X send the EAP-Request/Identity to the endpoint? Unfortunately, I cannot change the switch port configuration and shut/no shut is not allowed either.
Thanks and regards,
Víctor.
Solved! Go to Solution.
09-20-2018 05:39 AM
I believe that is the downside of doing mab first, which is something I never do. When you do MAB first you are forcing the connecting device to initiate Dot1x which some devices like Macs are only responders. In addition, as you are seeing you may have issues during reauthentication.
09-20-2018 05:39 AM
I believe that is the downside of doing mab first, which is something I never do. When you do MAB first you are forcing the connecting device to initiate Dot1x which some devices like Macs are only responders. In addition, as you are seeing you may have issues during reauthentication.
09-20-2018 12:04 PM - edited 09-20-2018 12:20 PM
You can force reauthentcation using 802.1X by adding Cisco VSA:termination-action-modifier=1 to the authorization profile along with the reauthentication parameters even when the ordering dictates MAB first. Please see '802.1X and MAB ordering section' of the following document for more information:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide