MAC Authentication Bypass
MAC authentication bypass or MAC Auth Bypass is an 802.1X feature to control policies for NAC agentless hosts. MAC authentication bypass is configured on a per-port basis and currently is supported only on the Catalyst 6500 running CatOS. When this feature is enabled, the switch makes a RADIUS request to the Cisco Secure ACS server with the MAC address of the client machine that is attempting to connect to the network. If Cisco Secure ACS finds the MAC address of the client machine in its internal database, it sends an access-accept to the switch, and the host is allowed onto the network. This MAC authentication happens after NAC-L2-802.1X. It bypasses the default NAC-L2-802.1X security policy of denying access for all devices that cannot complete an EAP authentication.
TIP You can use the MAC address OUI to wildcard and allow devices with MAC addresses within the same OUI range to access the network. This avoids an administrator having to enter each individual MAC address for devices such as printers or terminals that don't have an 802.1X supplicant and need to be allowed access to the network.
The Cisco Catalyst 6500 configuration for MAC authentication bypass consists of only a few commands. It must be enabled globally and then applied to a port. To enable MAC authentication bypass globally, use the set mac-auth-bypass enable command:
Console> (enable) set mac-auth-bypass enable
Then apply it to an specific port, as follows:
Console> (enable) set port mac-auth-bypass 2/3 enable
This enables MAC authentication bypass on port 2/3.
TIP Refer to Chapter 8 for the configuration of Cisco Secure ACS for MAC authentication bypass.
Continue reading here: Architectural Overview of NAC on Layer 3 Devices
Was this article helpful?