Introduces RLAN authentication fallback, explaining how client authentication dynamically switches between 802.1X and MAB on OEAP RLAN ports, details prerequisites and operational behavior, and highlights feature availability in Cisco IOS XE Cupertino 17.8.1 and later.
An RLAN authentication fallback is a WLAN authentication mechanism that
-
enables client authentication to switch between 802.1X and MAC authentication bypass (MAB) when the initial method fails
-
supports dynamic fallback from 802.1X to MAB and vice versa according to client status and registration, and
-
requires that both 802.1X and MAB are enabled for fallback support.
Feature history
| Feature name |
Release information |
Feature description |
|---|---|---|
| RLAN authentication fallback |
Cisco IOS XE 17.8.x |
RLAN authentication fallback alternates client authentication between 802.1X and MAC authentication bypass (MAB) when the initial method fails. It dynamically switches based on client status and registration, requiring both 802.1X and MAB to be enabled. From Cisco IOS XE Cupertino 17.8.1, Remote LAN (RLAN) ports on OfficeExtend Access Points (OEAPs) support authentication fallback. |
How RLAN authentication fallback works
From Cisco IOS XE Cupertino 17.8.1, Remote LAN (RLAN) ports on OfficeExtend Access Points (OEAPs) support authentication fallback. If a client using IEEE 802.1X fails to authenticate, the system attempts MAC authentication bypass (MAB). Conversely, if the client's MAC address is not registered for MAC authentication bypass, the system falls back to IEEE 802.1X. Enable both methods to ensure successful authentication.
By default, the RLAN fallback mechanism is disabled. You must explicitly enable this mechanism. When both 802.1X and MAB are enabled, the device must succeed in both authentication methods for successful authentication.