skip to content

Admitting a Device

Who the port asks, what a device can prove, how long that proof holds, and what happens when it can prove nothing. Interviewers probe it because admission is where authentication and policy meet.

on this pageshow

explore

questions

20

What does MAC authentication bypass prove about a device whose address an attacker can read off the chassis, and what does the allow-list entry cost?

level: juniorimportance: must knowfreq 62%

answer

  1. a label is not a secret
  2. no challenge anywhere in the exchange
  3. inventory and logging, not authentication
  4. the accept is what limits the spoof
  5. every device becomes a permanent exception

basics

~20 s

MAC authentication bypass proves only that a frame carrying an allow-listed address reached the port. The address is a printed label, not a secret. Its value is inventory and logging, and each entry is a permanent exception someone must own.

solid answer

~50 s

MAB is the fallback for devices that cannot run a supplicant — a camera, a badge reader, an infusion pump. The port tries 802.1X first; when the identity requests go unanswered and the timeout expires, the switch takes the source address of the first frame and asks the policy server whether that address is permitted. Nothing is challenged, so nothing is proved: the address is stamped on the chassis, visible to anyone on the segment, and settable in software on any laptop. So MAB is an inventory control with an audit trail, not an authentication mechanism — its real value is that unknown addresses are still refused and known ones are logged. The price is that every bypassed device becomes a permanent allow-list entry with an owner, a review, and a landing place, and the only thing limiting a spoof is how tightly that entry is authorised.

code

text · 8 lines
text
Access-Request (MAC authentication bypass)
  User-Name          = 001b44113ab7
  User-Password      = 001b44113ab7      <- the address, again
  Calling-Station-Id = 00-1B-44-11-3A-B7
  Service-Type       = Call-Check         <- an address check, not a login
  NAS-Port-Id        = ward-3-sw1:port14
  ...
  (no EAP-Message attribute: nothing was ever challenged)

go deeper

for a junior

Be ready to say plainly that MAB admits a device on an address that is printed on its chassis and settable in software, so it verifies presentation, not identity. Know that 802.1X is tried first and bypass is the fallback.

for a middle

Explain the exchange: retries and timeout, then an Access-Request built from the source address with no challenge in it, then an accept carrying an authorisation profile. Contrast it with a credential-based method where possession is actually proved.

for a senior

Show where you put the effort given the check cannot be strengthened — a tight per-session authorisation on the accept, entries bounded to the ports and locations that make sense, and a list that carries owners and review dates rather than growing forever.

for a principal

Own the framing that MAB is an exception process, not a control. Argue for admission requirements at procurement so the exception register stops growing, and be clear about who accepts the residual risk for devices that will never carry a credential.

## The problem MAB exists to solve 802.1X asks a port's occupant to prove an identity. A laptop can: it runs a supplicant, speaks EAPOL, and presents a certificate or a password. A ceiling camera, a badge reader, an infusion pump or an imaging console under a vendor support contract cannot — there is no supplicant, no place to load a credential, and often a contract that forbids you touching the device at all. If the port refuses everything that cannot answer, the ward goes dark. MAC authentication bypass is the fallback that keeps those devices on the network. ## What actually happens on the wire 1. The port comes up and issues EAP identity requests. Nothing answers. 2. After the configured number of retries and the timeout, the switch gives up on 802.1X. 3. The switch takes the source address of the first frame the device sends and builds a RADIUS Access-Request from it — conventionally with the address as both user name and password, the same address in Calling-Station-Id, and Service-Type set to Call-Check to mark it as an address check rather than a user login. 4. The policy server looks the address up in its bypass rule set and returns an accept with an authorisation profile (a VLAN assignment, a per-session ACL, or both), or a reject. There is no challenge anywhere in that exchange. Compare it with EAP-TLS, where the endpoint must produce a signature only the holder of a private key could produce. MAB has no equivalent step, and it never can — the whole premise is a device that cannot compute anything on your behalf. ## Why the address is not a credential A MAC address is 48 bits, of which the first 24 are the IEEE-assigned vendor prefix. It is: - **printed on the device**, usually on a label on the chassis or the box it came in; - **broadcast constantly** as the source address of every frame, so anyone with a port on the same segment learns it without touching the device; - **software-settable** on essentially every network interface made in the last two decades. So an attacker standing in the same room as the camera has three easy routes to the identity — read the label, watch the wire, or note it off an asset sticker — and one command to present it. Unplug the camera, plug in a laptop with that address, and the port's bypass check is satisfied. ## The direction of the claim What a MAB accept proves: *a frame bearing an address on the allow-list arrived on this port at this time.* What it does not prove: that the device is the one you enrolled, that it is healthy, that it is the make you think it is, or that it is still in the ceiling. Candidates who describe MAB as authenticating the device have the direction wrong, and that error is what makes them treat the accept as a security decision rather than a logged exception. ## What you actually get out of it MAB is not useless. Two things survive: - **Default deny still holds for the unknown.** An address that is not on the list is refused, so an attacker with an unmodified laptop gets nothing from a lobby socket. Making them do the extra step of copying an address is worth something. - **You get a record.** Every accept and reject is logged with the address, the port and the time, so an inventory exists that did not exist before, and a device appearing on a port it has never used before is visible. ## The price, which is the part interviewers probe Every device admitted this way turns into a line in a bypass list. That line needs an owner, a device record, a review date, and — the part that decides how much the spoof is worth — a tight authorisation on the accept. A bypass entry that lands the device in a broad segment hands an attacker who copies one label the same reach the real device has. A bypass entry that lands on a per-session ACL permitting exactly the archive the camera writes to, and nothing else, makes the spoof cost the attacker a camera's worth of access. That is the honest summary to give in an interview: **MAB does not authenticate; it narrows.** The security is not in the check, it is in what the accept is allowed to do, and in the discipline that keeps the list from growing into a permanent, unowned exception register.

  • If MAB proves nothing, why bother with it instead of just opening the port?
    Because default deny still applies to everything not on the list, and because you get a record. An attacker with an unmodified laptop is refused, and has to first learn and present a permitted address. Every accept and reject is logged with address, port and time, which gives you an inventory and makes a device appearing on a strange port visible. An open port gives you neither.
  • Why does the switch try 802.1X before falling back to the address check?
    So that any device which can prove a real credential is never quietly downgraded to a claim anyone can copy. The bypass path is only entered after the identity requests go unanswered and the timeout expires. If you invert that order to speed up onboarding, a device with a perfectly good certificate gets admitted on its address instead, and you have silently made the weak path the normal one.
  • Where should the security effort go once you accept that MAB is unavoidable?
    Into the authorisation attached to the accept, and into the list's hygiene. A bypass entry that lands on a per-session ACL permitting only the one destination the device needs makes a copied address nearly worthless. A bypass entry that lands in a broad segment makes it worth as much as the device itself. Then: an owner per entry, a device record, and a review date.

A visitor badge with a name printed on it and no photograph. The desk can confirm the name is on today's list, which is worth something — but anyone who reads the badge over your shoulder can say the same name.

saying these in an interview costs you the question

  • Calls MAB authentication and treats the accept as proof of identity
  • Believes MAC addresses are burned in and cannot be changed
  • Assumes an attacker needs physical access to the device to learn its address
  • Puts the security in the check rather than in what the accept authorises
  • Treats the bypass list as a config file rather than an exception register with owners

context

open as a page

Why does 802.1X with PEAP-MSCHAPv2 still admit an attacker holding a password pulled from a stolen laptop image, and what does EAP-TLS cost instead?

level: juniorimportance: must knowfreq 72%

basics

~20 s

PEAP-MSCHAPv2 authenticates a password, and a password travels: whoever holds it authenticates from any laptop. So 802.1X admits a credential, not a device. EAP-TLS binds admission to a per-device key, but every device must be enrolled first.

open as a page

On an 802.1X Wi-Fi SSID, what does server-certificate validation in the client actually stop?

level: juniorimportance: must knowfreq 60%

basics

~20 s

It stops an attacker's radio that beacons your SSID from becoming the server your device authenticates to. Without it the supplicant builds its EAP tunnel to whoever answered and sends the credential exchange inside it.

open as a page

An attacker patches a laptop into an 802.1X access port: what passes before authentication, and what does that cost you?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Only EAPOL. The port's uncontrolled channel carries 802.1X frames; DHCP, ARP and everything else are dropped until authentication authorizes the controlled channel. Anything with no supplicant - imaging, headless kit - therefore sees a dead socket.

open as a page

A visitor left alone in a meeting room plugs into the live wall socket — what does that port hand them, and what does shutting unused ports cost?

level: juniorimportance: must knowfreq 62%

basics

~20 s

A socket that never got admission control hands a stranger a DHCP lease and layer-2 adjacency to everything in that room's VLAN. Shutting unused ports removes that, at the cost of a ticket every time a room is re-cabled.

open as a page

An IP phone with a PC daisy-chained behind it breaks single-host 802.1X: which host mode, and what does it cost?

level: middleimportance: must knowfreq 56%

basics

~20 s

Multi-domain: the phone authenticates into the voice domain and the PC into the data domain, two sessions on one port. It costs single-host's guarantee that exactly one device is ever authorized there, and multi-host would cost far more.

open as a page

A MAC bypass rule permits any address in the camera vendor's OUI range: what can an attacker do with it, and what scoping have you lost?

level: middleimportance: should knowfreq 41%

basics

~20 s

It makes spoofing trivial: an attacker sets any address beginning with that vendor prefix and needs no real camera at all. It also collapses per-device scoping, because one rule can only carry one authorisation for everything it matches.

open as a page

In 802.1X EAP-TLS, what does a machine-store certificate admit that a user-store one an attacker can export does not, and what does it cost to deploy?

level: middleimportance: should knowfreq 55%

basics

~20 s

A machine-store certificate authenticates the device: the port sees a computer identity, and the key can be non-exportable. A user-store certificate follows the person, so an exportable copy admits an attacker's laptop. Machine enrolment needs a management channel first.

open as a page

In a tunnelled EAP exchange, what does an anonymous outer identity hide, and from whom?

level: middleimportance: should knowfreq 45%

basics

~20 s

It hides the real username from anyone listening to the air, because the outer identity is sent in clear before the TLS tunnel exists. It hides nothing from a rogue access point that terminated the tunnel itself.

open as a page

Port-security with a two-MAC limit is on the lobby socket — how does a visitor still get on, and what does the violation mode cost?

level: middleimportance: should knowfreq 55%

basics

~20 s

A MAC address is a claim the endpoint makes, not an identity: the visitor clones the room phone's address and stays inside the limit. Shutdown mode then lets anyone take the port offline; silent-drop modes leave no record.

open as a page

You inherit a 4,000-entry MAC bypass list where any entry is spoofable from a ward socket: how do you shrink it without downing a device?

level: seniorimportance: should knowfreq 47%

basics

~20 s

Narrow before you delete. Tighten the authorisation on every entry first, run the removal decision in log-only mode against real traffic, attribute each surviving entry to an owner and a device record, and retire the rest through agreed change windows.

open as a page

802.1X enforcement is eight weeks away and the asset register lists 4,200 endpoints — why is that the wrong number to plan enrolment against, and what does the leftover exception list hand an attacker?

level: seniorimportance: should knowfreq 45%

basics

~20 s

The register lists what someone recorded, not what is on the wire. Plan against devices observed authenticating while 802.1X runs without blocking. Whatever you never found becomes a standing exception, a permanent unauthenticated way in.

open as a page

Your 802.1X SSID admits handsets you do not manage — how do you assure their certificate settings?

level: seniorimportance: should knowfreq 38%

basics

~20 s

You cannot read a client-side setting, so measure it: with authorisation, announce a decoy of your own SSID with an untrusted certificate and count the devices that proceed. Then provision profiles where you can, and state the coverage you lack.

open as a page

A switch spliced between the wall socket and an authenticated phone: why does the port stay authorized, and what stops it?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Because the session ends on link-down and the spliced switch keeps the wall port's link up. Reauthentication only re-tests whoever answers EAPOL, not a silent rider. Only per-frame protection such as MACsec on the access link actually stops it.

open as a page

Your floor plan and your port database disagree about which socket feeds the visitor lounge — how do you get ground truth, and what does it cost?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Neither record is evidence; both are typed by teams that do not talk. The switch proves a port is active, never which wall plate it feeds — so ground truth means an escorted, room-by-room cable trace that decays as the building changes.

open as a page

One 802.1X port template must ship to closets on two switch vendors after an acquisition: what do you pin, and who pays?

level: principalimportance: should knowfreq 29%

basics

~20 s

Pin behaviour, not syntax: host mode per port class, timers, session lifetime and failure posture, stated identically on both platforms rather than inherited from either vendor's defaults. The bill is inventory work and any hardware refresh.

open as a page

You run 802.1X for a dozen client tenants whose endpoints you cannot image, and nine have no enrolment pipeline — which credential can you actually ship each one, and what does the weaker one let an attacker do?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

You can only ship the credential a tenant's device management can deliver. With a pipeline, enrol machine certificates. Without one, a password method is what ships, and it admits any device holding that password — not just the tenant's.

open as a page

A laptop in the car park beacons your corporate SSID — what does hunting and containing it cost?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Detection costs airtime or hardware: serving radios must leave the channel to scan, or you buy sensors per site. Containment costs more, since it can disrupt a neighbouring tenant, may be unlawful, and never fixes the client setting.

open as a page

Who signs for a MAC bypass list of spoofable hospital devices when the team that owns them refuses the risk and the vendor forbids changes?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Translate each entry into a sentence the device owner can accept or refuse, tie renewal to the inventory cycle they already run, and escalate anything unsigned as a time-boxed accepted risk to an owner above both teams — never delete unilaterally.

open as a page

You propose every socket in a visitor-reachable room defaults to a zone a stranger's laptop cannot use — who signs it, and who refuses?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

It needs one accountable owner for the physical-to-logical map, since facilities, physical security and the network team each hold a piece and none can sign alone. Refusal comes from room bookings and from whoever funds the re-patch and the permanent exception queue.

open as a page