Switch User Manual

Configuring Multiple Authentication Methods
SecureStack C3 Configuration Guide 26-37
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowsausertoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)mustbeenabledglobally
andconfiguredappropriatelyonthedesiredportswithits
correspondingcommandsetdescribed
inthischapter.Theprecedenceconfiguredfortheauthenticationmethodsdetermineswhich
authenticationmethodisactuallyappliedtotheuser,device,orport.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.Authenticationprecedencecanbeconfiguredwiththe
setmultiauthprecedence
command.
About Multi-User Authentication
Multiuserauthenticationreferstotheabilitytoauthenticatemorethanoneuserordeviceonthe
sameport,witheachuserordevicebeingprovidedtheappropriatelevelofnetworkresources
basedonpolicy.
Whenasinglesupplicantconnectedtoanaccess layerportauthenticates,apolicyprofilecanbe
dynamicallyappliedtoalltrafficontheport.Whenmultiuserauthenticationisnotimplemented,
andmorethanonesupplicantisconnectedtoaport,thefirmwaredoesnotprovisionnetwork
resourcesonaperuserorperdevicebasis,eventhoughdifferentusersordevicesmayrequirea
differentset
ofnetworkresources.
Inordertosupportprovisioningnetworkresourcesonaperuserbasis,byapplyingthepolicy
configuredintheRADIUSfilterID orRFC3580tunnelattributesforagivenuserordevice,the
switchmustbethepointofauthenticationfortheattacheddevices.TheRADIUS
filterIDand
tunnelattributesarepartoftheRADIUSuseraccountandareincludedintheRADIUSaccess
acceptmessageresponsereceivedbytheswitchfromtheauthenticationserver.
Themaximumnumberofmultipleuserssupportedperportdependsonyourplatform.Referto
Appendix A,PolicyandAuthenticationCapacitiesfor
adescriptionofthemultiusercapacities
forthisdevice.Bydefault,thenumberofallowedusersperportissetto1.Toconfigurethe
numberofallowedusersperport,usethesetmultiauthportnumuserscommand.Usetheshow
multiauthportcommandtodisplaythecurrentvalues
of“Maxusers”and “A l l o w e d users”per
port.
Commands
For information about... Refer to page...
show multiauth 26-38
set multiauth mode 26-39
clear multiauth mode 26-39
set multiauth precedence 26-40
clear multiauth precedence 26-40
show multiauth port 26-41
set multiauth port 26-41