# MAB Authorization

> MAB (MAC Authentication Bypass) facilitates port-based access control through the utilization of the endpoint's MAC address. Additionally, it offers enhanced network visibility, as the authentication process enables the combination of device IP address, MAC address, switch, and port.
> MAB can be implemented as a backup or supplementary mechanism to IEEE 802.1X. In the absence of IEEE 802.1X-enabled devices on the network, MAB can be implemented as a standalone authentication mechanism.


## Step 1. MAC addresses.

> In order for the MAB authorization service to function correctly, it is necessary to input the system's MAC addresses. 
> This may be accomplished in a number of ways, as illustrated below.
{.is-info}

1. From the Main Menu select **MAC addresses** (section Objects) and fill in the required form data,
2. As before, in the same menu, select the **Import from file** button. Import data from a previously prepared csv file.
3. From the main menu, select **Endpoints** (Obiects section), add a new item and fill out the form that appears. Remember to complete the MAC addresses field in the form. You can select previously created addresses from the list or add them using the **+** button. Save the set values.
4. As before, from the main menu, select **Endpoints** (Obiects section), select the **Import from file** button. Import data from a previously prepared csv file.

> To make the further process of configuring the MAB easier, it's a good idea to group the added objects right away. In the form of each modality, there is an Object Groups field. This is a drop-down list from which you select the object groups you created earlier in Menu > Administration > Object Groups.
{.is-info}

## Step 2. Access policies.

1. From the main menu select **Access policies** (Configuration section).
2. Click on the **Add rule** button.
3. In the form that appears, enter the following data:

| Form fields | Value | 
| --- | --- |
| Name | Type any name |
| Authentication method to the network | MAC |
| Action | Access to vlan |
| Send VLAN tag back |  Yes (checkbox) |
| Vlan | Select from the list the VLAN to be assigned to the users of the organization |
| Device group MAC addresses | Select from the list of object groups if mac addresses or terminal devices have been previously grouped |
| Undefined Endpoints means | Any Endpoints |
| Network device | Select from the list the WiFi controllers and/or network devices on which the authorization service will be activated |
| WiFi network | Optional: if you selected a wifi controller above, select the SSID |

4. Save the set values.
5. To make your changes to access policies take effect, press the **Install list** button.

## Step 3. Enhance authentication security (optional)

1. Find the newly added policy on the list and click the button **Details** located in the same row.
2. Click on **Response action**.
3. Next, you need to program the verification mechanism. To do this, select the **Action type** in the form: SNMP (requires credential configuration), DHCP (requires DHCP server in NACVIEW), or NMAP. In the **Validation action** field, select: notify and block.
4. Save the set values and **Install list**.

> After the initial authorization, the system will create a validation template for future verification. In the case of changes to the components of the end device or its replacement, the stored template should be deleted. To do this, go to the end device, press the preview button next to the validation template, and select the clear option.
{.is-info}


