13.1 Endpoint Security Architecture: 802.1X, Cisco ISE Posture, and Profiling

Key Takeaways

  • IEEE 802.1X delivers port-based access control using three core entities: Supplicant (endpoint), Authenticator (switch or WLC), and Authentication Server (Cisco ISE) communicating over EAPoL and RADIUS.

  • Extensible Authentication Protocol (EAP) mechanisms provide distinct security guarantees: EAP-TLS mandates mutual PKI certificate verification, PEAP protects inner MSCHAPv2 credentials inside a server-authenticated TLS tunnel, and EAP-FAST utilizes Protected Access Credentials (PAC).

  • MAC Authentication Bypass (MAB) provides network access for headless endpoints—such as printers, IP phones, and IoT sensors—that lack native 802.1X supplicants by evaluating the device MAC address as a RADIUS credential.

  • Cisco Identity Services Engine (ISE) device profiling aggregates telemetry across multiple probes—including DHCP options, HTTP user-agent headers, CDP/LLDP discovery, SNMP queries, and MAC OUIs—to classify endpoint hardware and operating systems.

  • Posture assessment verifies endpoint hygiene (OS patch level, active antivirus signatures, host firewall, disk encryption) using Cisco Secure Client persistent or temporal agents, dynamically applying quarantine VLANs or redirect ACLs for non-compliant systems.

Last updated: October 2026

Endpoint Security Architecture: 802.1X, Cisco ISE Posture, and Profiling

Modern enterprise networks face significant access control challenges driven by the proliferation of Bring Your Own Device (BYOD) smartphones, unmanaged Internet of Things (IoT) sensors, and rogue physical connections. Traditional perimeter firewalls cannot prevent unauthorized devices from connecting directly to access-layer switch ports or corporate wireless networks. Establishing zero-trust enterprise security requires validating endpoint identity, device context, and operational health before granting data plane connectivity. Cisco Identity Services Engine (ISE) serves as the centralized policy engine, coordinating network access control across wired, wireless, and VPN infrastructures.


IEEE 802.1X Port-Based Network Access Control Architecture

IEEE 802.1X defines a standardized framework for port-based network admission control. The architecture decouples physical port connectivity from network authorization, preventing unauthorized data frames from entering the switching fabric until an endpoint successfully proves its identity.

+------------------+                    +--------------------+                    +-------------------+
|    SUPPLICANT    |                    |   AUTHENTICATOR    |                    |   AUTH SERVER     |
| (Endpoint / PC)  |                    |  (Switch or WLC)   |                    |    (Cisco ISE)    |
+------------------+                    +--------------------+                    +-------------------+
         |                                        |                                         |
         |------- 1. EAPoL-Start ---------------->|                                         |
         |<------ 2. EAP-Request / Identity ------|                                         |
         |------- 3. EAP-Response / Identity ---->|                                         |
         |                                        |------- 4. RADIUS Access-Request ------->|
         |                                        |        (EAP-Response / Identity)        |
         |                                        |                                         |
         |                                        |<------ 5. RADIUS Access-Challenge <-----|
         |                                        |        (EAP-Method Negotiation)         |
         |<------ 6. EAP-Request (Method) --------|                                         |
         |------- 7. EAP-Response (Credentials) ->|                                         |
         |                                        |------- 8. RADIUS Access-Request ------->|
         |                                        |        (EAP-Credentials)                |
         |                                        |                                         |
         |                                        |<------ 9. RADIUS Access-Accept ---------|
         |                                        |        (dACL, SGT, VLAN Assignment)     |
         |<------ 10. EAP-Success ----------------|                                         |
         |                                        | [Port Transitions to AUTHORIZED State]  |
         |================== Data Plane Traffic Permitted ==================================|

Architectural Roles

The 802.1X standard divides network admission into three distinct logical roles:

  1. Supplicant (Endpoint Client): A software agent residing on the client device (such as the native Windows/macOS 802.1X client or Cisco Secure Client). The supplicant responds to authentication requests originating from the network access device.
  2. Authenticator (Network Access Device - NAD): The intermediate network hardware—typically a Cisco Catalyst switch or Catalyst 9800 Wireless LAN Controller (WLC)—controlling physical or logical ingress ports. Before authentication succeeds, the authenticator maintains the port in an unauthorized state, discarding all user data traffic and permitting only 802.1X control frames (EtherType 0x888E). The authenticator acts as a translation gateway, relaying Layer 2 Extensible Authentication Protocol over LAN (EAPoL) frames from the endpoint into Layer 3 UDP-encapsulated RADIUS packets (UDP ports 1812/1813 or legacy 1645/1646) directed toward Cisco ISE.
  3. Authentication Server (Cisco ISE): The centralized policy server that maintains authentication databases, integrates with external identity providers (such as Microsoft Active Directory, LDAP, or SAML-based identity services), and evaluates authorization rules. Upon validating client credentials, ISE transmits a RADIUS Access-Accept datagram containing authorization parameters—such as a dynamic downloadable Access Control List (dACL), a Security Group Tag (SGT), and an assigned VLAN—instructing the authenticator to transition the port into an authorized state.

802.1X Component Interaction Matrix

ComponentOperational EntitySupported ProtocolsPrimary Function
SupplicantEndpoint client (OS native or Cisco Secure Client)EAPoL (IEEE 802.1X, EtherType 0x888E)Initiates login; encapsulates user/machine credentials into EAP frames
AuthenticatorAccess switch (e.g., Catalyst 9300) or WLCEAPoL (downlink) / RADIUS (uplink)Enforces port authorization states; proxies EAP transactions between client and ISE
Authentication ServerCisco Identity Services Engine (ISE)RADIUS (RFC 2865/2866), EAP protocolsValidates credentials; checks policy engine; returns authorization profiles (VLAN, dACL, SGT)

Extensible Authentication Protocol (EAP) Frameworks

EAP (RFC 3748) is an architectural framework that provides support for multiple authentication methods without requiring the intermediate authenticator to interpret the underlying cryptographic mechanisms. The negotiation occurs directly between the supplicant and the authentication server across an EAP container.

1. EAP-TLS (EAP Transport Layer Security)

Standardized in RFC 5216, EAP-TLS represents the strongest authentication mechanism for enterprise environments. It requires a Public Key Infrastructure (PKI) to issue X.509 digital certificates to both the authentication server (ISE) and the supplicant endpoint. During the TLS handshake, mutual cryptographic validation occurs: the supplicant verifies the ISE server certificate against its trusted certificate authority (CA) root, and ISE validates the client certificate against enterprise directory attributes. Because authentication relies entirely on asymmetric cryptographic keys, EAP-TLS is completely immune to offline password dictionary attacks, credential replay, and brute-force cracking.

2. PEAP (Protected EAP)

Jointly developed by Cisco, Microsoft, and RSA Security, PEAP was designed to provide robust security without the administrative burden of provisioning digital certificates onto every endpoint device. PEAP establishes authentication across two sequential phases:

  • Phase 1 (Outer Tunnel): The supplicant initiates a TLS handshake with ISE. ISE presents its server certificate to the client. The client validates the ISE certificate and negotiates an encrypted TLS tunnel. No client certificate is required in this phase.
  • Phase 2 (Inner Authentication): Inside the protected TLS tunnel, the client authenticates using a secondary EAP method, most commonly PEAPv0 with EAP-MSCHAPv2 (Microsoft Challenge Handshake Authentication Protocol version 2). Because user credentials (usernames and password hashes) travel exclusively within the encrypted TLS tunnel, they are shielded from passive eavesdropping and man-in-the-middle interception.

3. EAP-FAST (Flexible Authentication via Secure Tunneling)

Standardized in RFC 4851, Cisco developed EAP-FAST to replace the vulnerable Lightweight EAP (LEAP) protocol. EAP-FAST establishes an encrypted tunnel using symmetric Protected Access Credentials (PAC) rather than public key server certificates, eliminating PKI complexity. A PAC key can be provisioned in-band through automatic dynamic exchange (Phase 0) or pre-shared out-of-band by administrators. Once the secure tunnel is established using the PAC key (Phase 1), internal user authentication executes over MSCHAPv2 or generic token cards (Phase 2).

Enterprise EAP Protocol Comparison

EAP MethodRFC StandardServer CertificateClient CertificateInner Auth ProtocolPrimary Enterprise Use Case
EAP-TLSRFC 5216Mandatory (X.509)Mandatory (X.509)Cryptographic handshakeHigh-security corporate-managed laptops, domain workstations
PEAP-MSCHAPv2Proprietary / IETF DraftMandatory (X.509)Not RequiredEAP-MSCHAPv2 (password)Enterprise BYOD, Active Directory domain-joined users without PKI
EAP-FASTRFC 4851Optional (uses PAC)Not RequiredEAP-MSCHAPv2 / GTCHeterogeneous enterprise environments seeking tunnel security without PKI

MAC Authentication Bypass (MAB) for Headless Devices

Many physical enterprise devices—such as network printers, IP security cameras, badge readers, building environmental sensors, and legacy medical equipment—lack the processing hardware or software operating system required to host an 802.1X supplicant. If a switch port enforces strict 802.1X, these devices cannot authenticate and are locked out of the network.

MAC Authentication Bypass (MAB) serves as a fallback mechanism for headless endpoints:

  1. 802.1X Timeout: The switch port attempts 802.1X authentication by transmitting EAP-Request/Identity frames. When the attached headless device fails to respond within configured retry intervals (e.g., three attempts spaced 30 seconds apart), the 802.1X process times out.
  2. MAB Invocation: The switch transitions the authentication process to MAB. It inspects the source MAC address of the first received Ethernet data frame from the endpoint.
  3. RADIUS Authentication: The switch constructs a standard RADIUS Access-Request packet. It populates both the User-Name (RADIUS Attribute 1) and User-Password (RADIUS Attribute 2) fields with the client's 12-digit hexadecimal MAC address (e.g., aabbccddeeff), formatted according to switch configuration.
  4. ISE Validation: Cisco ISE receives the Access-Request, looks up the MAC address within its internal endpoint database or external Identity Management Store, and evaluates authorization rules.
+----------+               +-------------------+               +-----------+
| Headless |               |   Access Switch   |               | Cisco ISE |
|  Device  |               |  (Authenticator)  |               |  (Server) |
+----------+               +-------------------+               +-----------+
     |                               |                               |
     | [Silent to EAPoL Requests]    |                               |
     |<-- EAP-Request/Identity (x3) -|                               |
     |                               | [802.1X Timed Out]            |
     |--- Standard IP Packet ------->| [Captures Source MAC]         |
     |                               |--- RADIUS Access-Request ---->|
     |                               |    User: 001122334455         |
     |                               |    Pass: 001122334455         |
     |                               |<-- RADIUS Access-Accept ------|
     |                               |    (dACL: Printer_Access)     |
     |                               | [Port Placed in MAB State]    |

MAB Security Caution: Because Ethernet MAC addresses are transmitted in plaintext across Layer 2 broadcast domains, an attacker can easily spoof the MAC address of an authorized printer or camera using software tools. Consequently, MAB must never be deployed in isolation; it must be paired with Cisco ISE profiling, sticky MAC security, and restrictive downloadable ACLs that limit communication strictly to necessary application servers.


Cisco ISE Device Profiling and Context Gathering

To counter MAC spoofing and dynamically assign granular permissions, Cisco ISE employs Device Profiling. Profiling continuously gathers behavioral telemetry from network endpoints, evaluates attributes against profiling policies, and assigns certainty factors to classify devices into specific categories (e.g., Apple-iPad, Cisco-IP-Phone-8845, Axis-Surveillance-Camera).

+-------------------------------------------------------------------------+
|                     CISCO ISE PROFILING ENGINE                          |
|  Aggregates Telemetry Probes -> Evaluates Rules -> Assigns Identity Tag |
+-------------------------------------------------------------------------+
         ^                 ^                 ^                 ^
         |                 |                 |                 |
+-----------------+ +---------------+ +---------------+ +-----------------+
|   DHCP Probe    | |  HTTP Probe   | | CDP/LLDP Probe| | SNMP/NMAP Probe |
| Option 55 & 60  | |  User-Agent   | | System Name   | | sysDescr & OUI  |
+-----------------+ +---------------+ +---------------+ +-----------------+

Profiling Probes

ISE collects endpoint data using several specialized telemetry probes:

  • DHCP Probe: When an endpoint broadcasts a DHCP Discover or Request packet, the access switch (acting as a DHCP Relay Agent with ip helper-address) forwards a copy of the packet to ISE. ISE inspects Option 55 (Parameter Request List) and Option 60 (Vendor Class Identifier). Because different operating systems request network parameters in distinct, unique sequences, DHCP Option 55 provides an exceptionally reliable fingerprint of the client OS.
  • HTTP User-Agent Probe: When an unauthenticated client opens a web browser, the switch redirects the HTTP session to an ISE portal. ISE parses the User-Agent string embedded in the HTTP header, which discloses the precise browser version, operating system build, and hardware architecture.
  • CDP and LLDP Probes: Cisco Discovery Protocol (CDP) and Link Layer Discovery Protocol (LLDP) packets transmitted by IP phones, switches, and video endpoints are received by the access switch and forwarded to ISE via RADIUS accounting attributes or SNMP. Telemetry includes device model names, software releases, and power requirements.
  • RADIUS Probe: Captures attributes sent in RADIUS authentication and accounting packets, including the endpoint MAC Organizationally Unique Identifier (OUI, the first 3 octets assigned to the hardware manufacturer), NAS-Port-Type, and Framed-IP-Address.
  • SNMP and NMAP Probes: ISE can actively query network devices via SNMP or initiate targeted NMAP scans to detect open TCP/UDP listening ports, banner responses, and active network services.

Posture Assessment and Endpoint Compliance Lifecycle

Even when an endpoint presents valid user credentials and authenticates via 802.1X, the device itself may harbor vulnerabilities, missing operating system patches, disabled endpoint protection, or malware. Posture Assessment evaluates the operational health and security hygiene of the client system before permitting unrestricted enterprise access.

+---------------------------------------------------------------------------+
|                    ISE POSTURE COMPLIANCE LIFECYCLE                       |
+---------------------------------------------------------------------------+

   [1. INITIAL CONNECTION]                 [2. HEALTH EVALUATION]
   Endpoint authenticates                  Cisco Secure Client Agent
   State: UNKNOWN                          checks local system health
   Switch applies Redirect-ACL             - OS Patch Version
   Traffic redirected to ISE               - Antivirus Signature Age
              |                            - Firewall State
              v                            - BitLocker / Disk Encryption
      +---------------+                                   |
      |  Health Check |                                   |
      +---------------+                                   |
              |                                           |
     +--------+--------+                                  |
     |                 |                                  v
     v                 v                      [3. POLICY DECISION]
[COMPLIANT]     [NON-COMPLIANT] <-------------------------+
     |                 |
     |                 +---------> [4. DYNAMIC REMEDIATION]
     |                             Redirected to Patch Server / Antivirus Update
     |                             Remediation succeeds -> Re-check Posture
     v                                                    |
[5. AUTHORIZATION ACCEPT] <-------------------------------+
ISE issues RADIUS CoA (RFC 5176)
Switch removes Redirect-ACL
Full corporate network access granted

Cisco Secure Client Posture Agents

Posture checks are performed by the Cisco Secure Client (formerly AnyConnect) software deployed in one of two modes:

  1. Persistent Agent: A permanent background service installed on corporate-managed assets. It continuously monitors security parameters, executes posture validation during every network connection event, and reports changes in system health in real time.
  2. Temporal (Dissolvable) Agent: An ephemeral executable downloaded through the ISE client provisioning portal for unmanaged BYOD or contractor systems. It performs an initial compliance scan, transmits the results to ISE, and automatically uninstalls itself when the session ends.

Monitored Posture Conditions

The ISE posture policy checks multiple host attributes:

  • Operating System Hygiene: Validates minimum OS build numbers, service packs, and active installation of mandatory security hotfixes.
  • Antivirus and Anti-Malware: Verifies that an approved endpoint protection platform is actively running, real-time file scanning is enabled, and virus definition signatures have been updated within the preceding 7 days.
  • Host Firewall State: Ensures the local operating system firewall (e.g., Windows Defender Firewall) is active on all network profiles.
  • Disk Encryption: Validates that full-disk encryption (such as BitLocker on Windows or FileVault on macOS) is actively protecting local physical drives.

Posture Compliance States and Dynamic Remediation

Following evaluation, ISE assigns one of three compliance states:

  • Compliant: The endpoint satisfies all mandatory security checks. ISE issues a RADIUS Change of Authorization (CoA) per RFC 5176 to the authenticator switch. The switch clears temporary access restrictions and applies the final corporate authorization profile (dACL, SGT, and production VLAN).
  • Non-Compliant: The endpoint fails one or more critical checks. ISE instructs the authenticator to isolate the host inside a Remediation VLAN or apply a restrictive redirect ACL. The endpoint is granted access only to remediation infrastructure—such as internal Windows Server Update Services (WSUS), antivirus definition distribution servers, or software download portals. Once the Secure Client downloads the required updates, it initiates a re-scan. Upon passing, ISE transmits a CoA to grant full network access.
  • Unknown: The endpoint has not yet run the posture agent. The authenticator applies a quarantine redirect ACL that intercepts HTTP traffic and presents the client with a web portal prompting agent installation.

Endpoint Security Beyond Network Access Control

ENCOR topic 5.4.b lists endpoint security as a component of network security design. Network access control decides whether a device may connect; endpoint security products protect the device and its traffic after it connects:

Product (former name)Where it worksWhat it does
Cisco Secure Endpoint (AMP for Endpoints)Agent on laptops, servers, and mobile devicesChecks file reputation, blocks known malware, records file and process activity, and raises retrospective alerts when a file is later judged malicious
Cisco Umbrella (also delivered within Cisco Secure Access)DNS-layer and cloud security serviceBlocks requests to malicious domains at DNS resolution time, before a connection is made, on or off the corporate network
Cisco Secure Email (Email Security Appliance)Email gatewayFilters spam, phishing, and malicious attachments and links
Cisco Secure Web Appliance (Web Security Appliance)Web proxyApplies URL filtering, reputation scoring, and malware scanning to web traffic
Cisco Secure Malware Analytics (Threat Grid)Cloud or on-premises sandboxRuns unknown files in isolation and reports their behavior to the other products
Cisco ISEPolicy serverControls network access with 802.1X, MAB, profiling, posture, and SGT assignment

These products share threat intelligence from Cisco Talos, so a file or domain judged malicious in one place can be blocked by the others.


Guest Lifecycle Management

Enterprise facilities frequently host visitors, contractors, and vendors requiring isolated Internet connectivity. Cisco ISE centralizes guest access management through Central Web Authentication (CWA):

  1. Initial Association: The guest associates with an open or pre-shared key (PSK) guest SSID, or connects to a designated guest Ethernet port. The switch authenticates the MAC address via MAB.
  2. URL Redirection: ISE returns an authorization profile containing a URL-redirect attribute pointing to the ISE Guest Portal and a Redirect ACL that permits DNS and DHCP while intercepting HTTP/HTTPS requests.
  3. Portal Authentication: When the guest opens a browser, the switch intercepts the traffic and redirects the browser to the ISE Guest Portal. Guest onboarding workflows support:
    • Hotspot Access: Click-through acceptance of acceptable use policies (AUP).
    • Self-Service Registration: Guests enter their name, mobile phone number, and email. ISE generates a temporary username and password, delivered via SMS or email one-time password (OTP).
    • Sponsored Guest Access: Employees log into a dedicated Sponsor Portal to approve guest requests and generate credentials for visiting clients.
  4. Change of Authorization (CoA): Once guest credentials are authenticated, ISE issues a RADIUS CoA (Disconnect or Re-authenticate) to the switch or WLC. The authenticator removes the redirect ACL and binds the guest session to a restrictive Guest dACL that limits access exclusively to the public Internet, isolating internal corporate resources.
Test Your Knowledge

Which Extensible Authentication Protocol (EAP) method provides mutual cryptographic authentication by requiring X.509 digital certificates to be installed on both the endpoint supplicant and the Cisco ISE authentication server?

A

PEAPv0 with EAP-MSCHAPv2

B

EAP-TLS (Transport Layer Security)

C

EAP-FAST (Flexible Authentication via Secure Tunneling)

D

MAC Authentication Bypass (MAB)

Test Your Knowledge

An enterprise deployment requires identifying the operating system build and device type of endpoints connecting to campus switches. Which Cisco ISE profiling probe analyzes the Parameter Request List (Option 55) and Vendor Class Identifier (Option 60) forwarded by access-layer switches?

A

HTTP User-Agent Probe

B

CDP / LLDP Probe

C

DHCP Probe

D

SNMP Query Probe

Test Your Knowledge

During a posture assessment workflow, an endpoint running Cisco Secure Client fails an antivirus definition currency check. What operational mechanism does Cisco ISE utilize to dynamically update the switch port authorization state once the endpoint remediates the issue?

A

RADIUS Change of Authorization (CoA, RFC 5176) sent to the access switch

B

SNMP SET message requesting an immediate switch interface factory reload

C

Gratuitous ARP broadcast transmitted across all local campus VLANs

D

Spanning Tree Protocol Topology Change Notification (TCN) BPDU

Sections you finish are checked off in the contents.