Explains how MAB provides fallback authentication for clients that cannot complete 802.1X while preserving 802.1X as the preferred authentication method.
802.1X authentication with MAC Authentication Bypass (MAB) fallback is a combined access-control mode that
-
uses 802.1X as the primary authentication method
-
uses MAB when the client does not complete 802.1X authentication, and
-
terminates MAB authorization when 802.1X authentication succeeds.
This mode supports networks that contain both 802.1X-capable and non-802.1X-capable devices.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
MAC Authentication Bypass fallback method for 802.1X authentication |
Release 25.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100]); Modular Systems (8800 [LC ASIC: Q200, P100]) (select variants only*) You can use MAC Authentication Bypass (MAB) as a fallback method to enhance network security and flexibility when routers do not support the 802.1X protocol. By default, 802.1X authentication is set as the primary authentication method. In multi-authentication mode, a router supports up to 20 MAB clients simultaneously, in networks with a mix of 802.1X-capable and non-802.1X-capable devices. The feature introduces these changes: CLI:
*This feature is supported on:
|