Philip thanks for the links! It looks like using hybrid authentication on the switch port might be the way to go... Now I need to figure out how to test it out on a small number of ports to see how it works. I have a radius server set up and functioning. Just figuring out the MAC portion is my challenge. Thanks for the idea! Scott Hybrid Authentication When a hybrid access policy is enabled on a switchport, the client will first be prompted to provide their domain credentials for 802.1X authentication. If 802.1X authentication fails, it will deny the client and will not move to MAB authentication. If the switch does not receive any EAP packets, 802.1X authentication will timeout in 8 seconds, and the client's MAC address will then be authenticated via MAB. If 802.1X authentication timeout and MAB fails, the device will be put on a "guest" VLAN, if one is defined. Hybrid authentication is helpful in environments where not every device supports 802.1X authentication since MAB exists as a failover mechanic.
... View more