cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5063
Views
15
Helpful
7
Replies
Frequent Contributor

Authentication open vs authentication order mab | dot1x

Hello Freinds

 

is okay inder the interface connected to Dot1xPC and MAB PC to use authentication open , instead of

 

authentication order mab for MAB PC

 

&

 

authentication order dot1x for Dot1xPC

 

thanks

7 REPLIES 7
Participant

Re: Authentication open vs authentication order mab | dot1x

Both dot1x and MAB are methods of authentication for a port, whereas authentication open provides no authentication for a port, it allows all traffic through if a host is authenticated successfully or not.  

 

It is used when setting up dot1x configurations in monitor mode. You could have both dot1x/MAB authentication and authentication open to log authentication details but allow a user access even if they fail authentication.  

 

The authentication order commands only specify which method of authentication to try first between mab, dot1x and webauth. If you are looking at a dot1x setup the authentication order commands don't provide authentication, it would be the mab and dot1x pae authenticator interface commands.

 

Participant

Re: Authentication open vs authentication order mab | dot1x

Hi,

 

Please take into account that authentication open is useful only if the authentication/authorization fails.

There is a common misconception that if you have authentication open your hosts can't be affected by any ISE policy change.

Still, even if you have authentication open but ISE sends a dACL with deny any or places you to a specific (blackhole) VLAN that authorization will apply.

Same applies if your last rule (before deny) is guest portal.  Everyone will be trapped in the guest portal authorization rule, and the authentication open command would be useless.

 

Authentication open is great only if your hosts that are not authenticated match a deny rule. (in this case in the authorization policy)

 

Thanks,

Octavian

Participant

Re: Authentication open vs authentication order mab | dot1x

This is very true. Indeed a big misconception that no Cisco doc clarifies anywhere.
Highlighted
Beginner

Re: Authentication open vs authentication order mab | dot1x

Hi, 

 

1)Under monitor mode, If there is no dACL(no deny), will there be still blocking of MAB or 802.1x devices? considering authorization policy doesn't goes through (due to missing the device MAC address in Identity group)

IF there is a blocking, who and how it works?

 

2)Furthermore, how to ensure there is no blocking when runnning monitor mode?

 

3)I also heard tht there could be no blocking even during "closed mode". How possible is this?

Enthusiast

Re: Authentication open vs authentication order mab | dot1x

Hi Ibrahim,
those options are not opposite, they are complementary.
However, it is importante to notice that with authentication open you should use an ACL at interfaces to controll what can and what cant be accessed.
Look for ISE low impact mode.

Frequent Contributor

Re: Authentication open vs authentication order mab | dot1x

Hello freinds

 

thanks for explaning

 

 

so the below is for better operation

so in the port conncted to mab pc  , the authentication order is mab

 

while port connected to dot1xpc , authentication order must be  dot1x

 

thanks all

Enthusiast

Re: Authentication open vs authentication order mab | dot1x

Not necessary. You can configure all of the interfaces as:

authentication order mab dot1x
authentication priority dot1x mab