MAC Authentication Bypass (MAB) Configuration on Cisco IOS XE and ISE
MAB authenticates printers, cameras, and legacy gear that cannot run a supplicant by using their MAC as the RADIUS username. Here is the Cisco IOS XE and ISE config.
Port-based network access control, the standard for authenticating users and devices onto wired and wireless networks. Articles tagged 802.1X cover supplicant and authenticator behavior, RADIUS, EAP methods, Cisco ISE, dynamic VLANs, dACLs, host modes, and phased deployment.
MAB authenticates printers, cameras, and legacy gear that cannot run a supplicant by using their MAC as the RADIUS username. Here is the Cisco IOS XE and ISE config.
EAP-TLS replaces 802.1X passwords with mutual certificate auth. Here is the PKI prep, ISE policy, and IOS XE config you need for a production certificate-based rollout.
PEAP-MSCHAPv2 protects the credential exchange inside a TLS tunnel against an ISE server certificate. Here is the full Cisco ISE and IOS XE config for AD users.
The ISE side of 802.1X: network devices, identity sources, authentication and authorization policies, and the Policy Set that ties it all together for a Catalyst 9300.
A complete 802.1X switchport config on IOS XE 17.9: AAA, RADIUS servers, dot1x system-auth-control, interface policy-map, and the voice VLAN gotchas to avoid.
The 802.1X authentication flow, step by step, from EAPOL-Start through RADIUS Access-Accept and port authorization. Three conversations, one timeline, no magic.
Cisco ISE is more than a RADIUS server. It is the policy decision point for 802.1X, layering device type, posture, and context on top of pass/fail authentication.
RADIUS CoA lets ISE push policy updates to the switch mid-session, no re-auth required. Here is the IOS XE and ISE config, plus the posture remediation use case.
Web authentication adds a captive portal as an 802.1X fallback for guests, contractors, and unmanaged endpoints. Here is the Cisco IOS XE and ISE config.
Multi-domain authentication lets an IP phone and a PC share one 802.1X port with separate voice and data VLANs. Here is the Cisco IOS XE config and verification.
dACLs move ACL definitions off the switch and into ISE, delivered per session via RADIUS. Here is how the download mechanism works and how to configure both sides.
Guest VLAN, Auth-Fail VLAN, and Critical VLAN cover the three 802.1X failure paths: no supplicant, wrong credentials, and RADIUS down. Here is when and how to use each.