Courseiva
mediumMultiple Choice

CCNP Practice Question: Is configuring 802.1X on a Cisco Catalyst 9300…

A network engineer is configuring 802.1X on a Cisco Catalyst 9300 switch for a wired network. The engineer wants to allow devices that do not support 802.1X (e.g., printers) to still access the network using MAB (MAC Authentication Bypass). The engineer configures the interface with 'authentication port-control auto', 'dot1x pae authenticator', and 'mab'. However, after connecting a printer, the switch logs show 'MAB failed' repeatedly. The printer's MAC address is in the RADIUS server database. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that MAB requires EAP or that the client must respond to EAP packets, but MAB is a non-EAP method that bypasses the 802.1X supplicant entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The RADIUS server is not configured to accept MAC addresses in the format sent by the switch (e.g., with dots or colons).

The most likely cause is that the RADIUS server expects the MAC address in a specific format (e.g., with colons or hyphens), but the switch sends it in a different format (e.g., with dots or no separators). MAB works by the switch sending the printer's MAC address as the username and password in a RADIUS Access-Request. If the format does not match the server's database, authentication fails, even though the MAC is present. This is a common configuration mismatch between Cisco switches and RADIUS servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The RADIUS server is not configured to accept MAC addresses in the format sent by the switch (e.g., with dots or colons).

    Why this is correct

    During MAC Authentication Bypass, the switch uses the source MAC address as both username and password for the RADIUS request. Cisco IOS typically formats this as dotted hex (e.g., xxxx.xxxx.xxxx) or sometimes hyphenated (e.g., xx-xx-xx-xx-xx-xx). If the RADIUS server's user database or identity store is configured to accept colon-separated or concatenated format only, the authentication fails because the credentials do not match any expected entry. This is a classic configuration mismatch, not a protocol or timer issue.

  • ✗

    The switch is not configured with 'dot1x timeout tx-period' to initiate MAB.

    Why it's wrong here

    The dot1x timeout tx-period timer controls how frequently the switch retransmits EAP-Request/Identity frames toward the supplicant during 802.1X authentication. MAB, however, is a fallback that the switch triggers after 802.1X fails or times out; it does not depend on this timer. To enable MAB you must explicitly issue the 'mab' command on the interface, often combined with 'authentication order' or 'authentication priority' to define the fallback sequence. An incorrect tx-period might affect how long the port waits before falling back, but it does not initiate MAB.

  • ✗

    The interface is configured as 'switchport mode trunk', which does not support MAB.

    Why it's wrong here

    MAC Authentication Bypass is not limited to access ports; it functions equally well on trunk ports. In fact, MAB is often deployed on trunk links to authenticate devices such as IP phones or upstream switches that need to pass multiple VLANs. The switch still learns the source MAC address and forwards the RADIUS request regardless of port mode. Therefore, setting the interface as 'switchport mode trunk' is not the cause of a MAB failure.

  • ✗

    The printer is not responding to EAP-Request/Identity packets.

    Why it's wrong here

    MAB is designed for devices that lack an 802.1X supplicant, like a network printer, so the absence of any response to EAP-Request/Identity is expected and triggers the fallback procedure. If the printer were responding with EAP packets, the switch would treat it as a 802.1X client and continue the EAP exchange, which is a different authentication path. Thus, the printer's silence does not cause the MAB failure; instead, the switch should have used the MAC address after waiting a short time, and any failure would occur later in the RADIUS exchange.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.