System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

802.1X authentication with MAC Authentication Bypass fallback

Want to summarize with AI?

Log in

Explains how MAB provides fallback authentication for clients that cannot complete 802.1X while preserving 802.1X as the preferred authentication method.


802.1X authentication with MAC Authentication Bypass (MAB) fallback is a combined access-control mode that

  • uses 802.1X as the primary authentication method

  • uses MAB when the client does not complete 802.1X authentication, and

  • terminates MAB authorization when 802.1X authentication succeeds.

This mode supports networks that contain both 802.1X-capable and non-802.1X-capable devices.

Table 1. Table 3: Feature History Table

Feature Name

Release Information

Feature Description

MAC Authentication Bypass fallback method for 802.1X authentication

Release 25.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100]); Modular Systems (8800 [LC ASIC: Q200, P100]) (select variants only*)

You can use MAC Authentication Bypass (MAB) as a fallback method to enhance network security and flexibility when routers do not support the 802.1X protocol. By default, 802.1X authentication is set as the primary authentication method. In multi-authentication mode, a router supports up to 20 MAB clients simultaneously, in networks with a mix of 802.1X-capable and non-802.1X-capable devices.

The feature introduces these changes:

CLI:

  • show dot1x port authentication

*This feature is supported on:

  • 8212-48FH-M

  • 88-LC0-36FH-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM


How 802.1X authentication falls back to MAC Authentication Bypass

MAB fallback supports networks with both 802.1X-capable and non-802.1X-capable devices.

Summary

The router can prioritize 802.1X authentication by using these methods:

  • EAPOL detection: The router monitors for EAPOL packets and gives a successful 802.1X session precedence over MAB authorization.

  • Change of Authorization (CoA): The AAA server sends a RADIUS CoA request to enforce 802.1X authentication.

Workflow

These stages describe fallback authentication:

  1. During initial authentication, the router waits for EAPOL packets for three intervals of 10 seconds each.

  2. During reauthentication, the router waits for EAPOL packets for three intervals of 30 seconds each.

  3. If no EAPOL packets are detected, the client does not support 802.1X, or the remote server reports an 802.1X failure, the router attempts MAB.

  4. If the RADIUS server times out during 802.1X authentication and the dot1x profile explicitly sets server dead action auth-fail , the router falls back to MAB.

  5. If 802.1X authentication succeeds, the router terminates MAB authorization and gives control to the 802.1X session.

Result

The router authenticates each client with 802.1X when possible and uses MAB when the configured fallback conditions occur.


802.1X and MAC Authentication Bypass failure behavior

Use this reference to understand authentication failure handling during MAB fallback.

802.1X authentication can fail when:

  • No EAPOL is received because the client does not support 802.1X or does not respond to the EAPOL request.

  • The RADIUS server sends an Access-Reject message.

  • The RADIUS server is unreachable while the default server dead action auth-fail command is applied.

MAB authentication can fail when:

  • The RADIUS server sends an Access-Reject message.

  • The RADIUS server is unreachable while the default server dead action auth-fail command is applied.

This table lists how the router responds to failed authentication.

Table 2. Authentication failure behavior

Failure condition

Router behavior

802.1X does not receive EAPOL

The router proceeds with MAB when fallback is configured.

802.1X authentication fails

The router proceeds with MAB when fallback is configured.

All authentication methods fail

After 60 seconds, the router deletes the client and associated programming.


Configure 802.1X authentication with MAB fallback

Configure 802.1X and MAB authentication methods and verify the result of each attempted method.

802.1X is the primary method. MAB is used when the client does not complete 802.1X authentication.

Before you begin

Configure the RADIUS server and the default dot1x authentication method.

Procedure

  1. Configure a dot1x profile with 802.1X and MAB.

    Example:

    Router# configure
    Router(config)# dot1x profile sample-auth-mab
    Router(config-dot1x-auth-mab)# pae authenticator
    Router(config-dot1x-auth-mab)# mab
    Router(config-dot1x-auth-mab)# authenticator timer reauth-time 60
    Router(config-dot1x-auth-mab)# authenticator server dead action auth-fail
    Router(config-dot1x-auth-mab)# commit
  2. Verify the dot1x profile.

    Example:

    Router# show run dot1x profile sample-auth-mab
    dot1x profile sample-auth-mab
    mab
    pae authenticator
    authenticator
    timer reauth-time 60
    server dead action auth-retry
  3. Attach the profile to the interface.

    Example:

    Router# configure
    Router(config)# interface GigabitEthernet 0/1/0/0
    Router(config-if)# dot1x profile sample-auth-mab
    Router(config-if)# commit

    Run the show run interface GigabitEthernet 0/1/0/0 command to verify that the port control is configured on the interface.

  4. Verify MAB authorization after 802.1X receives no EAPOL.

    Example:

    Router# show dot1x port authentication
    Interface Client Method Status
    GigabitEthernet 0/1/0/0 ac4a.6730.0620 mab Authorized
    Router# show dot1x port authentication detail
    Port Authentication Info for GigabitEthernet 0/1/0/0
    ---------------------------------------------------------------
    Interface Handle : 0x80001c0
    Interface State : Up
    Port Status : Authorized (1/1)
    Profile : sample-test-auth-mab
    Method List : dot1x, mab
    Client :
    MAC Address : ac4a.6730.0620
    Status : Authorized
    Programming Status : Add Success
    Unauthorized Timer : 60s, timer off
    Method:
    dot1x : Failed (No EAPoL received)
    mab : Success
  5. Verify 802.1X authorization when the client completes 802.1X.

    Example:

    Router# show dot1x port authentication
    NODE: node0_2_CPU0
    =====================================================================
    Interface Client Method Status
    =====================================================================
    GigabitEthernet 0/1/0/0 ac4a.6730.0620 dot1x Authorized
    
    Router# show dot1x port authentication detail
    Port Authentication Info for GigabitEthernet 0/1/0/0
    ---------------------------------------------------------------
    Interface Handle : 0x80001c0
    Interface State : Up
    Port Status : Authorized (1/1)
    Profile : sample-test-auth-mab
    Method List : dot1x, mab
    Client :
    MAC Address : ac4a.6730.0620
    Status : Authorized
    Programming Status : Add Success
    Unauthorized Timer : 60s, timer off
    Method:
    dot1x : Success
    mab : Not Run

The output identifies whether MAB or 802.1X authorized the client.