Cisco WAP200 Administration Guide - Page 41

MAC disabled and 802.1x enabled, mandatory 802.1x authentication option disabled

Page 41 highlights

Chapter 2 How it works Chapter 2 MAC + 802.1x Not Mandatory MAC + 802.1x Mandatory Failure - No Failure Success Yes Failure Failure No Success Failure No Success - Yes Success Success Yes Failure - No Failure Success Yes Failure Failure No Success Failure No Success - No Success Success Yes Example A MAC and 802.1x enabled, mandatory 802.1x authentication option disabled Wireless clients are automatically authenticated by their MAC address. • If MAC authentication succeeds, the client gains access. Next the client station can initiate an 802.1x session, causing 802.1x authentication to take place. The result of this authentication then takes precedence over the MAC authentication result. • If MAC authentication fails, the client does not gain access but can still initiate an 802.1x session, causing 802.1x authentication to take place. If the result of this authentication is successful, then the client gains access. Example B MAC and 802.1x enabled, mandatory 802.1x authentication option enabled Wireless clients are automatically authenticated by their MAC address. If MAC authentication succeeds they do not gain access until 802.1x authentication is successful. Example C MAC disabled and 802.1x enabled, mandatory 802.1x authentication option disabled Wireless clients automatically gain access to the network with no authentication required. If the client starts an 802.1x session, authentication to take place. If the result of this authentication is failure, then the client looses access to the network. Example D MAC disabled and 802.1x enabled, mandatory 802.1x authentication option enabled Wireless clients only gain access to the network after successfully starting being authenticated via an 802.1x session. 41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82

Chapter 2
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - How it works - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Chapter 2
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 41 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Example A
MAC and 802.1x enabled, mandatory 802.1x authentication option disabled
Wireless clients are automatically authenticated by their MAC address.
If MAC authentication succeeds,
the client gains access. Next the client station can
initiate an 802.1x session, causing 802.1x authentication to take place. The result of
this authentication then takes precedence over the MAC authentication result.
If MAC authentication fails,
the client does not gain access but can still initiate an
802.1x session, causing 802.1x authentication to take place. If the result of this
authentication is successful, then the client gains access.
Example B
MAC and 802.1x enabled, mandatory 802.1x authentication option enabled
Wireless clients are automatically authenticated by their MAC address. If MAC
authentication succeeds they do not gain access until 802.1x authentication is
successful.
Example C
MAC disabled and 802.1x enabled, mandatory 802.1x authentication option disabled
Wireless clients automatically gain access to the network with no authentication
required. If the client starts an 802.1x session, authentication to take place. If the result
of this authentication is failure, then the client looses access to the network.
Example D
MAC disabled and 802.1x enabled, mandatory 802.1x authentication option enabled
Wireless clients only gain access to the network after successfully starting being
authenticated via an 802.1x session.
MAC + 802.1x Not Mandatory
Failure
-
No
Failure
Success
Yes
Failure
Failure
No
Success
Failure
No
Success
-
Yes
Success
Success
Yes
MAC + 802.1x Mandatory
Failure
-
No
Failure
Success
Yes
Failure
Failure
No
Success
Failure
No
Success
-
No
Success
Success
Yes