cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4747
Views
1
Helpful
3
Replies

802.1x preauth ACL

Isaiah
Level 2
Level 2

Is it possible to configure a pre-authentication ACL for interfaces configured with wired 802.1x authentication? I would like to have selective network access allowed in the state prior to successful authentication, and then overridden by a dACL granting full access if/when authentication passes.

1 Accepted Solution

Accepted Solutions

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

No. You can just change the VLAN.

View solution in original post

3 Replies 3

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

No. You can just change the VLAN.

Okay. Is any traffic at all (DHCP / DNS / PXE / etc.) allowed to pass on the switchport prior to authentication? Or is an unauthenticated endpoint completely isolated?

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Completely isolated unless you configure a guest VLAN and authentication does not occur.