cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2642
Views
0
Helpful
5
Replies

MAB Authentication operation and its interaction with Authorization

bbriggs
Level 1
Level 1

We are using a default Wired_MAB configuration.

As I understand it a device tries to authenticate and as part of this the identity store i.e. the local internal identity store is queried.

If this is a new device it isn't in the Identity Store, however our new device seems to get added.

Is it the case that authentication proceeds after MAB with ISE continuing to Authorization Rules, if a device passes profiling it is added to the Identity Store and having been added, at THAT point authentication can now be successful?

It has always seemed odd to me that there does not seem to be a failure condition within Authentication for MAB devices, however if a device fails to profile i.e. Authorize, it also fails authentication.

Can someone clarify this?

Thanks

2 Accepted Solutions

Accepted Solutions

Gagandeep Singh
Cisco Employee
Cisco Employee

Hi,

In MAB, authentication use Internal Endpoint where If user not found "CONTINUE"

It will move to authorization policy. MAC address gets added in ISE database as per profiled Endpoint.

Even if it doesn't match any profiling policy, it will become part of Unknown endpoint.

As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.

Regards

Gagan

PS: rate helpful posts!!!!!

View solution in original post

Gagandeep Singh
Cisco Employee
Cisco Employee

Please rate as correct if it helps!!!!

Also let me know if you have any concerns on this thread...

Regards

Gagan

View solution in original post

5 Replies 5

Gagandeep Singh
Cisco Employee
Cisco Employee

Hi,

In MAB, authentication use Internal Endpoint where If user not found "CONTINUE"

It will move to authorization policy. MAC address gets added in ISE database as per profiled Endpoint.

Even if it doesn't match any profiling policy, it will become part of Unknown endpoint.

As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.

Regards

Gagan

PS: rate helpful posts!!!!!

Gagandeep Singh
Cisco Employee
Cisco Employee

Please rate as correct if it helps!!!!

Also let me know if you have any concerns on this thread...

Regards

Gagan

bbriggs
Level 1
Level 1

Thanks for that. That's a great help.

Your Welcome!!!!!

Hi, appreciate this is now an old thread but wondering if you can help me, i have the exact same query as above.  I don't want the MAC address to be auto-populated into the inventory in the case where the device is unknown it should remain unknown and rejected.  Any idea's how i can resolve this?

thanks