02-20-2017 11:45 AM - edited 03-11-2019 12:28 AM
We are using a default Wired_MAB configuration.
As I understand it a device tries to authenticate and as part of this the identity store i.e. the local internal identity store is queried.
If this is a new device it isn't in the Identity Store, however our new device seems to get added.
Is it the case that authentication proceeds after MAB with ISE continuing to Authorization Rules, if a device passes profiling it is added to the Identity Store and having been added, at THAT point authentication can now be successful?
It has always seemed odd to me that there does not seem to be a failure condition within Authentication for MAB devices, however if a device fails to profile i.e. Authorize, it also fails authentication.
Can someone clarify this?
Thanks
Solved! Go to Solution.
02-20-2017 01:00 PM
Hi,
In MAB, authentication use Internal Endpoint where If user not found "CONTINUE"
It will move to authorization policy. MAC address gets added in ISE database as per profiled Endpoint.
Even if it doesn't match any profiling policy, it will become part of Unknown endpoint.
As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.
Regards
Gagan
PS: rate helpful posts!!!!!
02-20-2017 01:23 PM
Please rate as correct if it helps!!!!
Also let me know if you have any concerns on this thread...
Regards
Gagan
02-20-2017 01:00 PM
Hi,
In MAB, authentication use Internal Endpoint where If user not found "CONTINUE"
It will move to authorization policy. MAC address gets added in ISE database as per profiled Endpoint.
Even if it doesn't match any profiling policy, it will become part of Unknown endpoint.
As per second query, it fails authentication because RADIUS has one packet for authentication and authorization. So even it passes authentication and failed in authorization, you will get failed authentication report.
Regards
Gagan
PS: rate helpful posts!!!!!
02-20-2017 01:23 PM
Please rate as correct if it helps!!!!
Also let me know if you have any concerns on this thread...
Regards
Gagan
02-22-2017 09:56 AM
Thanks for that. That's a great help.
02-22-2017 10:49 AM
Your Welcome!!!!!
07-16-2020 07:15 AM
Hi, appreciate this is now an old thread but wondering if you can help me, i have the exact same query as above. I don't want the MAC address to be auto-populated into the inventory in the case where the device is unknown it should remain unknown and rejected. Any idea's how i can resolve this?
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide