# RADIUS plugin: 802.1X or MAB — prove Accept or Reject

Source: https://ai.techclick.in/blog_forescout_radius_8021x_mab
Markdown: https://ai.techclick.in/blog_forescout_radius_8021x_mab.md
Publisher: Techclick Infosec Pvt Ltd

RADIUS plugin: 802.1X Last Authentication State User/Computer/MAC. PEAP vs MAB vs Virtual FW. Dummy Priya vs printer.

## The ticket

 Priya: “Internet is down.” Switch Plugin is green. Inventory exists.  802.1X Last Authentication State - User Credentials  =  RADIUS-Rejected .  802.1X Authentication Type  = PEAP. Restarting fs-app1 will not mint a password. This is an admission ticket.

  Quick interview answer

 The  RADIUS Plugin  exposes 802.1X properties for policy and Host Details. Official:  802.1X Last Authentication State - User Credentials ,  … Computer Credentials ,  … MAC Based  (MAB) — each is RADIUS-Accepted or RADIUS-Rejected.  802.1X RADIUS Authentication State  is the last Accept/Reject.  802.1X Authentication Type  is EAP-TLS, EAP-TTLS, MAB, PEAP, or PEAP-EAP-TLS. Accept is not a VLAN. One port, one enforcement owner: ISE/Forescout RADIUS for users; Forescout Virtual FW/plugin for agentless — not both wild. Source: RADIUS properties for use in policy conditions.

  Hero · Accept or Reject

 Rejected + a healthy Switch Plugin is credentials/EAP, not “NAC down.”
  Lab data · dummy only
 Enterprise Manager  fs-em   10.10.10.30  · Appliance  fs-app1   10.10.10.31  · span/mirror on  sw-access-01  · same LAN  10.20.30.0/24  · Priya  10.20.30.80  · printer  10.20.30.60  · OT PLC  10.50.1.10 . Not a live customer.

## Three authentication states

   Property  Means

   802.1X Last Authentication State - User Credentials   Last user 802.1X — RADIUS-Accepted or RADIUS-Rejected
   … Computer Credentials   Machine account / computer EAP
   … MAC Based   MAB using the MAC as identity
   802.1X Authentication Type   PEAP, EAP-TLS, EAP-TTLS, MAB, PEAP-EAP-TLS

  Same switch, two identities

 802.1X vs MAB vs Virtual FW

- Priya laptop 802.1X user PEAP / EAP-TLS ISE or Forescout RADIUS — one Printer 10.20.30.60 MAB · MAC Based state or Forescout control — one Do not Virtual FW + 802.1X flap on the same port Lesson 6 decision still stands. This lesson is the RADIUS proof field on that decision. https://fs-em.techclick-lab.in Training mock · not live Forescout Console Asset Inventory Policy Channels Tools Asset Inventory → 10.20.30.80 → Host Details ### 802.1X properties 802.1X Last Authentication State - User RADIUS-Rejected 802.1X Authentication Type PEAP 802.1X RADIUS Authentication State Reject 802.1X Last Authentication State - MAC Based — (not MAB) Cancel Save RADIUS properties for use in policy conditions. Training mock — exact Host Details layout varies by Console train. ## Who owns the port Windows domain laptop → 802.1X (ISE or Forescout RADIUS as the written RADIUS server — pick one). Printer / camera that will never supplicant → MAB or Forescout switch plugin / Virtual FW — pick one. PLC → neither PEAP nor MAB in this class design (lesson 9). If ISE already does CoA on that interface, Forescout inspects and may eyeExtend; it does not also Virtual-FW. ## How you prove admission #### Side A — NAD Switch: 802.1X then MAB order on user ports. Printer ports: MAB or none, matching the owner spreadsheet from lesson 6.

- #### Side B — Host Details Quote Last Authentication State (which of the three) + Authentication Type + RADIUS Authentication State. If Rejected, read RADIUS Log Details / Last Rejected Authentication Time when present. Do not Assign to VLAN yet.

- #### Side C — one owner If RADIUS-Accepted and the VLAN is still wrong, that is authorization (policy / dACL / plugin) — lesson 5/7 — not “restart RADIUS.” If Rejected, fix identity/EAP/cert/MAR. If empty 802.1X properties, the RADIUS plugin never saw the exchange — SPAN/NAD config, not HPS.

  dummy switch proof · not a live customer  show authentication sessions interface Gi1/0/10
# Method: dot1x     Status: Authz Failed
# Next: quote Forescout 802.1X Last Authentication State - User Credentials
#        = RADIUS-Rejected  and  Authentication Type = PEAP

## Four RADIUS failures

### 1 · Restart Switch Plugin because PEAP rejected

### 2 · MAB and 802.1X both succeeding then Virtual FW remapping VLAN

### 3 · PEAP on a PLC

### 4 · Empty 802.1X properties treated as “Forescout is down”

 Empty means the plugin did not see RADIUS. Check NAD pointing at the right RADIUS IP, and that the Appliance actually handles that exchange on your design.

## How to prove it

  Close the ticket only when

 1) Quoted User vs Computer vs MAC Based state. 2) Quoted Authentication Type. 3) Accept or Reject matches the NAD session. 4) Written port owner. 5) Priya is not also Virtual-FW’d.

## Traps

   Wrong  Right

  RADIUS-Accepted = VLAN 30  Accepted = identity. VLAN is authorization
  MAC Based state for Priya’s PEAP  User Credentials for user EAP; MAC Based is MAB
  MAB = 802.1X with a cert  MAB uses the MAC as identity

## Knowledge check

   Judgment items. One best answer. Reasons send you back to the matching section.

       Q1
       Priya PEAP fails. First proof field?

           Delete EM
           NMAP the PLC
           Disable SPAN
           802.1X Last Authentication State - User Credentials = RADIUS-Rejected (plus Authentication Type)

       Correct:  d . Ticket + official User Credentials property.

       Q2
       MAB is recorded on which property?

           802.1X Last Authentication State - MAC Based
           Windows Manageable Domain
           eyeSegment Internet zone
           NTP stratum

       Correct:  a . Official MAC Based = last MAB attempt.

       Q3
       RADIUS-Accepted means…

           The VLAN is guaranteed 30
           The RADIUS server authenticated that attempt — VLAN/dACL is a later authorization
           Virtual FW is required
           HPS is down

       Correct:  b . Traps — Accept is identity, not the VLAN.

       Q4
       802.1X Authentication Type values include…

           OSPF and EIGRP
           Only WMI
           PEAP, EAP-TLS, EAP-TTLS, MAB, PEAP-EAP-TLS
           Only SMTP

       Correct:  c . RADIUS properties for use in policy conditions.

       Q5
       User laptop port already owned by ISE 802.1X. Forescout should…

           Inspect / eyeExtend — not also Virtual FW that port
           Always add Virtual FW
           Force PEAP on the PLC
           Disable the RADIUS plugin so ISE works

       Correct:  a . Lesson 6/8 one owner.

       Q6
       Printer with no supplicant. Reasonable admission?

           PEAP-MSCHAPv2 as Priya
           Campus Virtual FW plus ISE CoA plus MAB
           802.1X user credentials only
           MAB (MAC Based) or Forescout control — one of them

       Correct:  d . Choose — MAB or Forescout control, not both plus PEAP.

       Check answers
       Reset

  Forescout class series:   Three products  ·  First day  ·  Discovery  ·  Classification  ·  Policy  ·  Enforcement  ·  Switch plugin  ·  eyeExtend  ·  OT / IoT  ·  vs ISE + interview  ·  HPS posture  ·  eyeSegment matrix  ·  RADIUS 802.1X MAB

## Sources

- RADIUS properties for use in policy conditions — Last Authentication State User/Computer/MAC, Authentication Type, RADIUS Authentication State.
- This series lesson 6 (Virtual FW vs 802.1X), lesson 7 (switch plugin), lesson 11 (do not confuse HPS with RADIUS).
- Forescout evidence desk — same 802.1X proof fields on a night-shift ticket.

 Related:  Forescout evidence desk  ·  session factory  ·  Cisco ISE series .

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
