Page 1 of 1

MAC authentication fallback

Posted: 27 Dec 2012 17:27
by suprys
Hi,

recently, I have stuck with 802.1x on 6850 (software 6.4.4.551.R01). Namely, I would like to perform MAC-auth fall back if device fails 802.1x (supplicant is activated).
I see some action after supplicant fails, like vlan guest, captive-portal, block.... but I need MAC-auth after 802.1x fail.

Is it possible ?


Regards,
Paul

Re: MAC authentication fallback

Posted: 04 Jan 2013 06:39
by silvio
I guess you meen mac-auth with external radius server? About your wish I'm now not sure (I'm not in my office without any access to switch...).
But there should be an other option with release 6.4.4 for mac-auth before checking if supplicant or not: supplicant bypass
In network guide you find a good declaration of it (look for supplicant bypass or 802.1x bypass).

regards
Silvio

Re: MAC authentication fallback

Posted: 02 Feb 2013 13:02
by suprys
Thanks Silvio for replay, right mac-auth with external radius server.
Supplicant bypass enforce to use mac-auth first. I want dot1x first then mac-auth.. but I found it's not possible due the iron policy rules...

regards,
Pawel