Administrator Guide

Table Of Contents
Security Commands 978
User Guidelines
Authentication of a user via MAB will not occur until the “dot1x time-out
guest-vlan-period” timer expires.
When using MAB, configure the user name attributes with the supplicant
MAC address using the mab request format command.
Command History
Updated syntax in version 6.5 firmware.
Example
The following example sets MAC Authentication Bypass on interface
gigabitethernet 1/0/2:
console(config-if-Gi1/0/2)#dot1x port-control mac-based
console(config-if-Gi1/0/2)#mab
default mab
Use the default mab command to configure the switch to transmit EAP or
CHAP or PAP credentials to the RADIUS server for MAB-authenticated
devices connected to the interface. Use the no form of the command to set
the protocol to the default.
Syntax
default mab [eap|chap|pap]
no default mab
eap—Use EAP Message Digest 5 authentication.
chap—Use Challenge Handshake Authentication Protocol.
pap—Use Password Authentication Protocol.
Default Configuration
The default protocol is EAP-MD5.
Command Mode
Interface Configuration (Ethernet) mode