41-17
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 41 Configuring MAC Authentication Bypass
Configuring Agentless Hosts for NAC Auditing with MAB
Interaction of Agentless Host Audit with Security Features
This section describes the behavior of NAC audit with other security features:
•
802.1X—When ACS audits a 802.1X-authenticated port, it checks for the MAB configuration. ACS
audits the port only if MAB is enabled, otherwise it considers the port to be part of a guest VLAN.
•
MAB—Regardless of how MAB is triggered, audit runs unless MAB fails.
•
Layer 3 features—Not affected by MAB-enabled agentless host audit.
•
Critical-Auth—Because there is no RADIUS server, no interaction is possible and the old posture
(if any) is maintained.
•
PVLAN—No effect.