From the course: Cisco CCNP SCOR Security (350-701) Cert Prep: 3 Endpoint Protection and Secure Access

Unlock this course with a free trial

Join today to access over 22,500 courses taught by industry experts.

MAB

MAB

- [Instructor] In addition to 802.1X that we looked at in our previous lesson, we also need to examine MAB Mac address bypass. Not all devices on our network will support 802.1X authentication. In some cases we may have something like a network printer that wouldn't support 802.1X authentication. So rather than disabling 802.1X we can still secure our switch ports using MAB. When we use MAB, the switch is going to drop all of the frames except for the first frame from which it can learn the Mac address. Once the switch has learned the Mac address it's going to contact the radius server in this case Cisco ISE, to see if the Mac address should be permitted. So while this does offer some protection in instances where we can't use 802.1X authentication, it's not the best overall option. Obviously Mac addresses can be easily spoofed. So this is something we would use in conjunction with 802.1X. In any event this is fairly simple to implement using Cisco ISE as our authentication server…

Contents