What does MAC authentication bypass prove about a device whose address an attacker can read off the chassis, and what does the allow-list entry cost?
answer
- a label is not a secret
- no challenge anywhere in the exchange
- inventory and logging, not authentication
- the accept is what limits the spoof
- every device becomes a permanent exception
basics
~20 sMAC authentication bypass proves only that a frame carrying an allow-listed address reached the port. The address is a printed label, not a secret. Its value is inventory and logging, and each entry is a permanent exception someone must own.
solid answer
~50 sMAB is the fallback for devices that cannot run a supplicant — a camera, a badge reader, an infusion pump. The port tries 802.1X first; when the identity requests go unanswered and the timeout expires, the switch takes the source address of the first frame and asks the policy server whether that address is permitted. Nothing is challenged, so nothing is proved: the address is stamped on the chassis, visible to anyone on the segment, and settable in software on any laptop. So MAB is an inventory control with an audit trail, not an authentication mechanism — its real value is that unknown addresses are still refused and known ones are logged. The price is that every bypassed device becomes a permanent allow-list entry with an owner, a review, and a landing place, and the only thing limiting a spoof is how tightly that entry is authorised.
code
text · 8 linesAccess-Request (MAC authentication bypass)
User-Name = 001b44113ab7
User-Password = 001b44113ab7 <- the address, again
Calling-Station-Id = 00-1B-44-11-3A-B7
Service-Type = Call-Check <- an address check, not a login
NAS-Port-Id = ward-3-sw1:port14
...
(no EAP-Message attribute: nothing was ever challenged)go deeper
Be ready to say plainly that MAB admits a device on an address that is printed on its chassis and settable in software, so it verifies presentation, not identity. Know that 802.1X is tried first and bypass is the fallback.
Explain the exchange: retries and timeout, then an Access-Request built from the source address with no challenge in it, then an accept carrying an authorisation profile. Contrast it with a credential-based method where possession is actually proved.
Show where you put the effort given the check cannot be strengthened — a tight per-session authorisation on the accept, entries bounded to the ports and locations that make sense, and a list that carries owners and review dates rather than growing forever.
Own the framing that MAB is an exception process, not a control. Argue for admission requirements at procurement so the exception register stops growing, and be clear about who accepts the residual risk for devices that will never carry a credential.
## The problem MAB exists to solve 802.1X asks a port's occupant to prove an identity. A laptop can: it runs a supplicant, speaks EAPOL, and presents a certificate or a password. A ceiling camera, a badge reader, an infusion pump or an imaging console under a vendor support contract cannot — there is no supplicant, no place to load a credential, and often a contract that forbids you touching the device at all. If the port refuses everything that cannot answer, the ward goes dark. MAC authentication bypass is the fallback that keeps those devices on the network. ## What actually happens on the wire 1. The port comes up and issues EAP identity requests. Nothing answers. 2. After the configured number of retries and the timeout, the switch gives up on 802.1X. 3. The switch takes the source address of the first frame the device sends and builds a RADIUS Access-Request from it — conventionally with the address as both user name and password, the same address in Calling-Station-Id, and Service-Type set to Call-Check to mark it as an address check rather than a user login. 4. The policy server looks the address up in its bypass rule set and returns an accept with an authorisation profile (a VLAN assignment, a per-session ACL, or both), or a reject. There is no challenge anywhere in that exchange. Compare it with EAP-TLS, where the endpoint must produce a signature only the holder of a private key could produce. MAB has no equivalent step, and it never can — the whole premise is a device that cannot compute anything on your behalf. ## Why the address is not a credential A MAC address is 48 bits, of which the first 24 are the IEEE-assigned vendor prefix. It is: - **printed on the device**, usually on a label on the chassis or the box it came in; - **broadcast constantly** as the source address of every frame, so anyone with a port on the same segment learns it without touching the device; - **software-settable** on essentially every network interface made in the last two decades. So an attacker standing in the same room as the camera has three easy routes to the identity — read the label, watch the wire, or note it off an asset sticker — and one command to present it. Unplug the camera, plug in a laptop with that address, and the port's bypass check is satisfied. ## The direction of the claim What a MAB accept proves: *a frame bearing an address on the allow-list arrived on this port at this time.* What it does not prove: that the device is the one you enrolled, that it is healthy, that it is the make you think it is, or that it is still in the ceiling. Candidates who describe MAB as authenticating the device have the direction wrong, and that error is what makes them treat the accept as a security decision rather than a logged exception. ## What you actually get out of it MAB is not useless. Two things survive: - **Default deny still holds for the unknown.** An address that is not on the list is refused, so an attacker with an unmodified laptop gets nothing from a lobby socket. Making them do the extra step of copying an address is worth something. - **You get a record.** Every accept and reject is logged with the address, the port and the time, so an inventory exists that did not exist before, and a device appearing on a port it has never used before is visible. ## The price, which is the part interviewers probe Every device admitted this way turns into a line in a bypass list. That line needs an owner, a device record, a review date, and — the part that decides how much the spoof is worth — a tight authorisation on the accept. A bypass entry that lands the device in a broad segment hands an attacker who copies one label the same reach the real device has. A bypass entry that lands on a per-session ACL permitting exactly the archive the camera writes to, and nothing else, makes the spoof cost the attacker a camera's worth of access. That is the honest summary to give in an interview: **MAB does not authenticate; it narrows.** The security is not in the check, it is in what the accept is allowed to do, and in the discipline that keeps the list from growing into a permanent, unowned exception register.
- If MAB proves nothing, why bother with it instead of just opening the port?Because default deny still applies to everything not on the list, and because you get a record. An attacker with an unmodified laptop is refused, and has to first learn and present a permitted address. Every accept and reject is logged with address, port and time, which gives you an inventory and makes a device appearing on a strange port visible. An open port gives you neither.
- Why does the switch try 802.1X before falling back to the address check?So that any device which can prove a real credential is never quietly downgraded to a claim anyone can copy. The bypass path is only entered after the identity requests go unanswered and the timeout expires. If you invert that order to speed up onboarding, a device with a perfectly good certificate gets admitted on its address instead, and you have silently made the weak path the normal one.
- Where should the security effort go once you accept that MAB is unavoidable?Into the authorisation attached to the accept, and into the list's hygiene. A bypass entry that lands on a per-session ACL permitting only the one destination the device needs makes a copied address nearly worthless. A bypass entry that lands in a broad segment makes it worth as much as the device itself. Then: an owner per entry, a device record, and a review date.
A visitor badge with a name printed on it and no photograph. The desk can confirm the name is on today's list, which is worth something — but anyone who reads the badge over your shoulder can say the same name.
saying these in an interview costs you the question
- Calls MAB authentication and treats the accept as proof of identity
- Believes MAC addresses are burned in and cannot be changed
- Assumes an attacker needs physical access to the device to learn its address
- Puts the security in the check rather than in what the accept authorises
- Treats the bypass list as a config file rather than an exception register with owners