T Techclick ← All lessons
Forescout · eyeSight / eyeControl · Lesson 13 of 13

RADIUS plugin: 802.1X or MAB — prove Accept or Reject

Priya cannot join corp Wi-Fi. Someone restarted the Switch Plugin. Admission is a RADIUS answer. Read 802.1X Last Authentication State — User, Computer, or MAC Based — RADIUS-Accepted or RADIUS-Rejected. Then pick one owner vs Virtual Firewall.

Updated 2026-08-18·18 min read·L2 primary·Quiz at end

After this page you can

The ticket

Priya: “Internet is down.” Switch Plugin is green. Inventory exists. 802.1X Last Authentication State - User Credentials = RADIUS-Rejected. 802.1X Authentication Type = PEAP. Restarting fs-app1 will not mint a password. This is an admission ticket.

Quick interview answer

The RADIUS Plugin exposes 802.1X properties for policy and Host Details. Official: 802.1X Last Authentication State - User Credentials, … Computer Credentials, … MAC Based (MAB) — each is RADIUS-Accepted or RADIUS-Rejected. 802.1X RADIUS Authentication State is the last Accept/Reject. 802.1X Authentication Type is EAP-TLS, EAP-TTLS, MAB, PEAP, or PEAP-EAP-TLS. Accept is not a VLAN. One port, one enforcement owner: ISE/Forescout RADIUS for users; Forescout Virtual FW/plugin for agentless — not both wild. Source: RADIUS properties for use in policy conditions.

Hero · Accept or Reject
802.1X Last Authentication State RADIUS-Accepted or RADIUS-Rejected
Rejected + a healthy Switch Plugin is credentials/EAP, not “NAC down.”
Lab data · dummy only

Enterprise Manager fs-em 10.10.10.30 · Appliance fs-app1 10.10.10.31 · span/mirror on sw-access-01 · same LAN 10.20.30.0/24 · Priya 10.20.30.80 · printer 10.20.30.60 · OT PLC 10.50.1.10. Not a live customer.

Three authentication states

PropertyMeans
802.1X Last Authentication State - User CredentialsLast user 802.1X — RADIUS-Accepted or RADIUS-Rejected
… Computer CredentialsMachine account / computer EAP
… MAC BasedMAB using the MAC as identity
802.1X Authentication TypePEAP, EAP-TLS, EAP-TTLS, MAB, PEAP-EAP-TLS
Same switch, two identities
Priya laptop802.1X user PEAP / EAP-TLSISE or Forescout RADIUS — one Printer 10.20.30.60MAB · MAC Based stateor Forescout control — one Do notVirtual FW + 802.1X flapon the same port

Lesson 6 decision still stands. This lesson is the RADIUS proof field on that decision.

https://fs-em.techclick-lab.in
Training mock · not live
Asset InventoryPolicyChannelsTools
Asset Inventory → 10.20.30.80 → Host Details

802.1X properties

RADIUS-Rejected
PEAP
Reject
— (not MAB)
RADIUS properties for use in policy conditions. Training mock — exact Host Details layout varies by Console train.

Who owns the port

Windows domain laptop → 802.1X (ISE or Forescout RADIUS as the written RADIUS server — pick one). Printer / camera that will never supplicant → MAB or Forescout switch plugin / Virtual FW — pick one. PLC → neither PEAP nor MAB in this class design (lesson 9). If ISE already does CoA on that interface, Forescout inspects and may eyeExtend; it does not also Virtual-FW.

How you prove admission

  1. Side A — NAD

    Switch: 802.1X then MAB order on user ports. Printer ports: MAB or none, matching the owner spreadsheet from lesson 6.

  2. Side B — Host Details

    Quote Last Authentication State (which of the three) + Authentication Type + RADIUS Authentication State. If Rejected, read RADIUS Log Details / Last Rejected Authentication Time when present. Do not Assign to VLAN yet.

  3. Side C — one owner

    If RADIUS-Accepted and the VLAN is still wrong, that is authorization (policy / dACL / plugin) — lesson 5/7 — not “restart RADIUS.” If Rejected, fix identity/EAP/cert/MAR. If empty 802.1X properties, the RADIUS plugin never saw the exchange — SPAN/NAD config, not HPS.

dummy switch proof · not a live customer
show authentication sessions interface Gi1/0/10
# Method: dot1x     Status: Authz Failed
# Next: quote Forescout 802.1X Last Authentication State - User Credentials
#        = RADIUS-Rejected  and  Authentication Type = PEAP

Four RADIUS failures

1 · Restart Switch Plugin because PEAP rejected

2 · MAB and 802.1X both succeeding then Virtual FW remapping VLAN

3 · PEAP on a PLC

4 · Empty 802.1X properties treated as “Forescout is down”

Empty means the plugin did not see RADIUS. Check NAD pointing at the right RADIUS IP, and that the Appliance actually handles that exchange on your design.

How to prove it

Close the ticket only when

1) Quoted User vs Computer vs MAC Based state. 2) Quoted Authentication Type. 3) Accept or Reject matches the NAD session. 4) Written port owner. 5) Priya is not also Virtual-FW’d.

Traps

WrongRight
RADIUS-Accepted = VLAN 30Accepted = identity. VLAN is authorization
MAC Based state for Priya’s PEAPUser Credentials for user EAP; MAC Based is MAB
MAB = 802.1X with a certMAB uses the MAC as identity

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

Priya PEAP fails. First proof field?

Correct: d. Ticket + official User Credentials property.
Q2

MAB is recorded on which property?

Correct: a. Official MAC Based = last MAB attempt.
Q3

RADIUS-Accepted means…

Correct: b. Traps — Accept is identity, not the VLAN.
Q4

802.1X Authentication Type values include…

Correct: c. RADIUS properties for use in policy conditions.
Q5

User laptop port already owned by ISE 802.1X. Forescout should…

Correct: a. Lesson 6/8 one owner.
Q6

Printer with no supplicant. Reasonable admission?

Correct: d. Choose — MAB or Forescout control, not both plus PEAP.

Forescout class series: Three products · First day · Discovery · Classification · Policy · Enforcement · Switch plugin · eyeExtend · OT / IoT · vs ISE + interview · HPS posture · eyeSegment matrix · RADIUS 802.1X MAB

Sources

Related: Forescout evidence desk · session factory · Cisco ISE series.