skip to content

NAC & 802.1X

You will learn how 802.1X authenticates devices at the port using EAP methods over RADIUS, how MAB handles agentless devices, and how NAC platforms assign VLANs and check endpoint posture dynamically. Interviewers probe the supplicant–authenticator–server flow because it ties authentication, switching, and policy together.

on this pageshow

explore

questions

page 1 of 2

What does MAC authentication bypass prove about a device whose address an attacker can read off the chassis, and what does the allow-list entry cost?

level: juniorimportance: must knowfreq 62%

answer

  1. a label is not a secret
  2. no challenge anywhere in the exchange
  3. inventory and logging, not authentication
  4. the accept is what limits the spoof
  5. every device becomes a permanent exception

basics

~20 s

MAC authentication bypass proves only that a frame carrying an allow-listed address reached the port. The address is a printed label, not a secret. Its value is inventory and logging, and each entry is a permanent exception someone must own.

solid answer

~50 s

MAB is the fallback for devices that cannot run a supplicant — a camera, a badge reader, an infusion pump. The port tries 802.1X first; when the identity requests go unanswered and the timeout expires, the switch takes the source address of the first frame and asks the policy server whether that address is permitted. Nothing is challenged, so nothing is proved: the address is stamped on the chassis, visible to anyone on the segment, and settable in software on any laptop. So MAB is an inventory control with an audit trail, not an authentication mechanism — its real value is that unknown addresses are still refused and known ones are logged. The price is that every bypassed device becomes a permanent allow-list entry with an owner, a review, and a landing place, and the only thing limiting a spoof is how tightly that entry is authorised.

code

text · 8 lines
text
Access-Request (MAC authentication bypass)
  User-Name          = 001b44113ab7
  User-Password      = 001b44113ab7      <- the address, again
  Calling-Station-Id = 00-1B-44-11-3A-B7
  Service-Type       = Call-Check         <- an address check, not a login
  NAS-Port-Id        = ward-3-sw1:port14
  ...
  (no EAP-Message attribute: nothing was ever challenged)

go deeper

for a junior

Be ready to say plainly that MAB admits a device on an address that is printed on its chassis and settable in software, so it verifies presentation, not identity. Know that 802.1X is tried first and bypass is the fallback.

for a middle

Explain the exchange: retries and timeout, then an Access-Request built from the source address with no challenge in it, then an accept carrying an authorisation profile. Contrast it with a credential-based method where possession is actually proved.

for a senior

Show where you put the effort given the check cannot be strengthened — a tight per-session authorisation on the accept, entries bounded to the ports and locations that make sense, and a list that carries owners and review dates rather than growing forever.

for a principal

Own the framing that MAB is an exception process, not a control. Argue for admission requirements at procurement so the exception register stops growing, and be clear about who accepts the residual risk for devices that will never carry a credential.

## The problem MAB exists to solve 802.1X asks a port's occupant to prove an identity. A laptop can: it runs a supplicant, speaks EAPOL, and presents a certificate or a password. A ceiling camera, a badge reader, an infusion pump or an imaging console under a vendor support contract cannot — there is no supplicant, no place to load a credential, and often a contract that forbids you touching the device at all. If the port refuses everything that cannot answer, the ward goes dark. MAC authentication bypass is the fallback that keeps those devices on the network. ## What actually happens on the wire 1. The port comes up and issues EAP identity requests. Nothing answers. 2. After the configured number of retries and the timeout, the switch gives up on 802.1X. 3. The switch takes the source address of the first frame the device sends and builds a RADIUS Access-Request from it — conventionally with the address as both user name and password, the same address in Calling-Station-Id, and Service-Type set to Call-Check to mark it as an address check rather than a user login. 4. The policy server looks the address up in its bypass rule set and returns an accept with an authorisation profile (a VLAN assignment, a per-session ACL, or both), or a reject. There is no challenge anywhere in that exchange. Compare it with EAP-TLS, where the endpoint must produce a signature only the holder of a private key could produce. MAB has no equivalent step, and it never can — the whole premise is a device that cannot compute anything on your behalf. ## Why the address is not a credential A MAC address is 48 bits, of which the first 24 are the IEEE-assigned vendor prefix. It is: - **printed on the device**, usually on a label on the chassis or the box it came in; - **broadcast constantly** as the source address of every frame, so anyone with a port on the same segment learns it without touching the device; - **software-settable** on essentially every network interface made in the last two decades. So an attacker standing in the same room as the camera has three easy routes to the identity — read the label, watch the wire, or note it off an asset sticker — and one command to present it. Unplug the camera, plug in a laptop with that address, and the port's bypass check is satisfied. ## The direction of the claim What a MAB accept proves: *a frame bearing an address on the allow-list arrived on this port at this time.* What it does not prove: that the device is the one you enrolled, that it is healthy, that it is the make you think it is, or that it is still in the ceiling. Candidates who describe MAB as authenticating the device have the direction wrong, and that error is what makes them treat the accept as a security decision rather than a logged exception. ## What you actually get out of it MAB is not useless. Two things survive: - **Default deny still holds for the unknown.** An address that is not on the list is refused, so an attacker with an unmodified laptop gets nothing from a lobby socket. Making them do the extra step of copying an address is worth something. - **You get a record.** Every accept and reject is logged with the address, the port and the time, so an inventory exists that did not exist before, and a device appearing on a port it has never used before is visible. ## The price, which is the part interviewers probe Every device admitted this way turns into a line in a bypass list. That line needs an owner, a device record, a review date, and — the part that decides how much the spoof is worth — a tight authorisation on the accept. A bypass entry that lands the device in a broad segment hands an attacker who copies one label the same reach the real device has. A bypass entry that lands on a per-session ACL permitting exactly the archive the camera writes to, and nothing else, makes the spoof cost the attacker a camera's worth of access. That is the honest summary to give in an interview: **MAB does not authenticate; it narrows.** The security is not in the check, it is in what the accept is allowed to do, and in the discipline that keeps the list from growing into a permanent, unowned exception register.

  • If MAB proves nothing, why bother with it instead of just opening the port?
    Because default deny still applies to everything not on the list, and because you get a record. An attacker with an unmodified laptop is refused, and has to first learn and present a permitted address. Every accept and reject is logged with address, port and time, which gives you an inventory and makes a device appearing on a strange port visible. An open port gives you neither.
  • Why does the switch try 802.1X before falling back to the address check?
    So that any device which can prove a real credential is never quietly downgraded to a claim anyone can copy. The bypass path is only entered after the identity requests go unanswered and the timeout expires. If you invert that order to speed up onboarding, a device with a perfectly good certificate gets admitted on its address instead, and you have silently made the weak path the normal one.
  • Where should the security effort go once you accept that MAB is unavoidable?
    Into the authorisation attached to the accept, and into the list's hygiene. A bypass entry that lands on a per-session ACL permitting only the one destination the device needs makes a copied address nearly worthless. A bypass entry that lands in a broad segment makes it worth as much as the device itself. Then: an owner per entry, a device record, and a review date.

A visitor badge with a name printed on it and no photograph. The desk can confirm the name is on today's list, which is worth something — but anyone who reads the badge over your shoulder can say the same name.

saying these in an interview costs you the question

  • Calls MAB authentication and treats the accept as proof of identity
  • Believes MAC addresses are burned in and cannot be changed
  • Assumes an attacker needs physical access to the device to learn its address
  • Puts the security in the check rather than in what the accept authorises
  • Treats the bypass list as a config file rather than an exception register with owners

context

open as a page

Why does 802.1X with PEAP-MSCHAPv2 still admit an attacker holding a password pulled from a stolen laptop image, and what does EAP-TLS cost instead?

level: juniorimportance: must knowfreq 72%

basics

~20 s

PEAP-MSCHAPv2 authenticates a password, and a password travels: whoever holds it authenticates from any laptop. So 802.1X admits a credential, not a device. EAP-TLS binds admission to a per-device key, but every device must be enrolled first.

open as a page

On an 802.1X Wi-Fi SSID, what does server-certificate validation in the client actually stop?

level: juniorimportance: must knowfreq 60%

basics

~20 s

It stops an attacker's radio that beacons your SSID from becoming the server your device authenticates to. Without it the supplicant builds its EAP tunnel to whoever answered and sends the credential exchange inside it.

open as a page

An attacker patches a laptop into an 802.1X access port: what passes before authentication, and what does that cost you?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Only EAPOL. The port's uncontrolled channel carries 802.1X frames; DHCP, ARP and everything else are dropped until authentication authorizes the controlled channel. Anything with no supplicant - imaging, headless kit - therefore sees a dead socket.

open as a page

A visitor left alone in a meeting room plugs into the live wall socket — what does that port hand them, and what does shutting unused ports cost?

level: juniorimportance: must knowfreq 62%

basics

~20 s

A socket that never got admission control hands a stranger a DHCP lease and layer-2 adjacency to everything in that room's VLAN. Shutting unused ports removes that, at the cost of a ticket every time a room is re-cabled.

open as a page

In DHCP snooping, which port do you trust, and does a wrong choice free a rogue or starve the rack?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Trust is a direction, not a device: the switch accepts DHCP server replies only from trusted ports, normally the link toward the real server. Mark the wrong port and either a rogue keeps offering leases or the segment gets none.

open as a page

Why does an unreachable 802.1X authentication server lock every device out of an unstaffed site, and who benefits if you configure it not to?

level: juniorimportance: must knowfreq 62%

basics

~20 s

A switch opens a port only when the authentication server returns an accept. Silence is not an accept, so an unreachable server denies everyone. Admitting on silence instead gives a port to anyone who can cause silence.

open as a page

Which destinations must a NAC quarantine segment reach, and what does each hand an intruder?

level: juniorimportance: must knowfreq 61%

basics

~20 s

A quarantined device can only be fixed if the segment still reaches patching, name resolution, identity and a time source. Every one of those is also an open path for an intruder sitting on the device that failed the check.

open as a page

An IP phone with a PC daisy-chained behind it breaks single-host 802.1X: which host mode, and what does it cost?

level: middleimportance: must knowfreq 56%

basics

~20 s

Multi-domain: the phone authenticates into the voice domain and the PC into the data domain, two sessions on one port. It costs single-host's guarantee that exactly one device is ever authorized there, and multi-host would cost far more.

open as a page

A MAC bypass rule permits any address in the camera vendor's OUI range: what can an attacker do with it, and what scoping have you lost?

level: middleimportance: should knowfreq 41%

basics

~20 s

It makes spoofing trivial: an attacker sets any address beginning with that vendor prefix and needs no real camera at all. It also collapses per-device scoping, because one rule can only carry one authorisation for everything it matches.

open as a page

In 802.1X EAP-TLS, what does a machine-store certificate admit that a user-store one an attacker can export does not, and what does it cost to deploy?

level: middleimportance: should knowfreq 55%

basics

~20 s

A machine-store certificate authenticates the device: the port sees a computer identity, and the key can be non-exportable. A user-store certificate follows the person, so an exportable copy admits an attacker's laptop. Machine enrolment needs a management channel first.

open as a page

In a tunnelled EAP exchange, what does an anonymous outer identity hide, and from whom?

level: middleimportance: should knowfreq 45%

basics

~20 s

It hides the real username from anyone listening to the air, because the outer identity is sent in clear before the TLS tunnel exists. It hides nothing from a rogue access point that terminated the tunnel itself.

open as a page

Port-security with a two-MAC limit is on the lobby socket — how does a visitor still get on, and what does the violation mode cost?

level: middleimportance: should knowfreq 55%

basics

~20 s

A MAC address is a claim the endpoint makes, not an identity: the visitor clones the room phone's address and stays inside the limit. Shutdown mode then lets anyone take the port offline; silent-drop modes leave no record.

open as a page

Why wait a full DHCP lease period before ARP validation drops, while a gateway claim still succeeds?

level: middleimportance: should knowfreq 55%

basics

~20 s

The binding table starts empty and learns only from DHCP exchanges the switch observes. Hosts already holding leases stay absent until they renew, at half the lease. Drop before then and their ARP is discarded: no gateway resolution.

open as a page

An 802.1X port loses its RADIUS servers: what decides how long it waits, and what happens to devices the fallback admitted?

level: middleimportance: should knowfreq 48%

basics

~20 s

The wait is the per-server retransmit count times the timeout, repeated across every configured server, so the port sits dark for that whole window before any fallback applies. Ports the fallback admitted keep that access until something forces re-authentication, and often nothing does.

open as a page

Why does re-checking NAC posture during a session cost you, and what does never re-checking hand an intruder?

level: middleimportance: should knowfreq 46%

basics

~20 s

A health check run at admission proves only that the device satisfied policy at that instant. Re-checking costs mid-session churn and support load; never re-checking leaves an authorization granted months ago standing over a device an intruder took last week.

open as a page

You inherit a 4,000-entry MAC bypass list where any entry is spoofable from a ward socket: how do you shrink it without downing a device?

level: seniorimportance: should knowfreq 47%

basics

~20 s

Narrow before you delete. Tighten the authorisation on every entry first, run the removal decision in log-only mode against real traffic, attribute each surviving entry to an owner and a device record, and retire the rest through agreed change windows.

open as a page

802.1X enforcement is eight weeks away and the asset register lists 4,200 endpoints — why is that the wrong number to plan enrolment against, and what does the leftover exception list hand an attacker?

level: seniorimportance: should knowfreq 45%

basics

~20 s

The register lists what someone recorded, not what is on the wire. Plan against devices observed authenticating while 802.1X runs without blocking. Whatever you never found becomes a standing exception, a permanent unauthenticated way in.

open as a page

Your 802.1X SSID admits handsets you do not manage — how do you assure their certificate settings?

level: seniorimportance: should knowfreq 38%

basics

~20 s

You cannot read a client-side setting, so measure it: with authorisation, announce a decoy of your own SSID with an untrusted certificate and count the devices that proceed. Then provision profiles where you can, and state the coverage you lack.

open as a page

A switch spliced between the wall socket and an authenticated phone: why does the port stay authorized, and what stops it?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Because the session ends on link-down and the spliced switch keeps the wall port's link up. Reauthentication only re-tests whoever answers EAPOL, not a silent rider. Only per-frame protection such as MACsec on the access link actually stops it.

open as a page

Your floor plan and your port database disagree about which socket feeds the visitor lounge — how do you get ground truth, and what does it cost?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Neither record is evidence; both are typed by teams that do not talk. The switch proves a port is active, never which wall plate it feeds — so ground truth means an escorted, room-by-room cable trace that decays as the building changes.

open as a page

What does a rogue IPv6 Router Advertisement win on an IPv4-only protected segment, and what does filtering it risk?

level: seniorimportance: should knowfreq 45%

basics

~20 s

It becomes a default router for every dual-stacked host, without touching one IPv4 binding. Filtering it needs a separate control with its own permitted ports; designate the wrong ones and the real router's advertisements are dropped too.

open as a page

Your EAP server certificate expired at 03:00 and every 802.1X site is dark: why won't dead-server fallback trigger, and what break-glass path won't also admit an intruder?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Because the server answered. Supplicants that validate the expired certificate abort the exchange and the server returns a reject, so the switch sees an authentication failure, not an unreachable server, and the unreachable-server fallback never applies.

open as a page

When is a per-session ACL worth its cost over a shared NAC quarantine VLAN an intruder can join?

level: seniorimportance: should knowfreq 37%

basics

~20 s

A per-session filter restricts one port without moving the device, so nothing re-addresses and failed hosts never sit together. It costs finite switch hardware entries; a shared quarantine VLAN is cheaper but pools every failed device in one broadcast domain.

open as a page

One 802.1X port template must ship to closets on two switch vendors after an acquisition: what do you pin, and who pays?

level: principalimportance: should knowfreq 29%

basics

~20 s

Pin behaviour, not syntax: host mode per port class, timers, session lifetime and failure posture, stated identically on both platforms rather than inherited from either vendor's defaults. The bill is inventory work and any hardware refresh.

open as a page

You run 802.1X for a dozen client tenants whose endpoints you cannot image, and nine have no enrolment pipeline — which credential can you actually ship each one, and what does the weaker one let an attacker do?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

You can only ship the credential a tenant's device management can deliver. With a pipeline, enrol machine certificates. Without one, a password method is what ships, and it admits any device holding that password — not just the tenant's.

open as a page

A laptop in the car park beacons your corporate SSID — what does hunting and containing it cost?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Detection costs airtime or hardware: serving radios must leave the channel to scan, or you buy sensors per site. Containment costs more, since it can disrupt a neighbouring tenant, may be unlawful, and never fixes the client setting.

open as a page

How does a remediated contractor laptop leave NAC quarantine without a link bounce, and what does the deadline override hand an intruder?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Something must re-evaluate the device so the policy server can push a change-of-authorization swapping the restricted authorization for the production one. Where no such signal exists, the exit becomes a human override, and that exception outlives the deadline that justified it.

open as a page

Who signs for a MAC bypass list of spoofable hospital devices when the team that owns them refuses the risk and the vendor forbids changes?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Translate each entry into a sentence the device owner can accept or refuse, tie renewal to the inventory cycle they already run, and escalate anything unsigned as a time-boxed accepted risk to an owner above both teams — never delete unilaterally.

open as a page

You propose every socket in a visitor-reachable room defaults to a zone a stranger's laptop cannot use — who signs it, and who refuses?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

It needs one accountable owner for the physical-to-logical map, since facilities, physical security and the network team each hold a piece and none can sign alone. Refusal comes from room bookings and from whoever funds the re-patch and the permanent exception queue.

open as a page

showing 1–30 of 32