Describes the EAP and MAB authentication modes that Cisco ACI uses to authenticate endpoints and control network access.
Cisco ACI 802.1X supports Extensible Authentication Protocol (EAP) as the primary authentication mode and MAC Authentication Bypass (MAB) as the fallback authentication mode.
Authentication mode behavior
Each authentication mode uses a different method to verify an endpoint.
|
Mode |
Behavior |
|---|---|
|
EAP |
The authenticator sends an |
|
MAB |
If EAP authentication is unavailable, MAB provides fallback port-based access control using the endpoint's MAC address. |