Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

802.1X authentication modes

Want to summarize with AI?

Log in

Describes the EAP and MAB authentication modes that Cisco ACI uses to authenticate endpoints and control network access.


Cisco ACI 802.1X supports Extensible Authentication Protocol (EAP) as the primary authentication mode and MAC Authentication Bypass (MAB) as the fallback authentication mode.

Authentication mode behavior

Each authentication mode uses a different method to verify an endpoint.

Table 1. 802.1X authentication modes

Mode

Behavior

EAP

The authenticator sends an EAP-Request/Identity frame to request the supplicant's identity. The supplicant returns an EAP-Response/Identity frame.

MAB

If EAP authentication is unavailable, MAB provides fallback port-based access control using the endpoint's MAC address.