Switch User Manual
Configuring Multiple Authentication Methods
SecureStack C3 Configuration Guide 26-37
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowsausertoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)mustbeenabledglobally
andconfiguredappropriatelyonthedesiredportswithits
correspondingcommandsetdescribed
inthischapter.Theprecedenceconfiguredfortheauthenticationmethodsdetermineswhich
authenticationmethodisactuallyappliedtotheuser,device,orport.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.Authenticationprecedencecanbeconfiguredwiththe
setmultiauthprecedence
command.
About Multi-User Authentication
Multi‐userauthenticationreferstotheabilitytoauthenticatemorethanoneuserordeviceonthe
sameport,witheachuserordevicebeingprovidedtheappropriatelevelofnetworkresources
basedonpolicy.
Whenasinglesupplicantconnectedtoanaccess layerportauthenticates,apolicyprofilecanbe
dynamicallyappliedtoalltrafficontheport.Whenmulti‐userauthenticationisnotimplemented,
andmorethanonesupplicantisconnectedtoaport,thefirmwaredoesnotprovisionnetwork
resourcesonaper‐userorper‐devicebasis,eventhoughdifferentusersordevicesmayrequirea
differentset
ofnetworkresources.
Inordertosupportprovisioningnetworkresourcesonaper‐userbasis,byapplyingthepolicy
configuredintheRADIUSfilter‐ID orRFC3580tunnelattributesforagivenuserordevice,the
switchmustbethepointofauthenticationfortheattacheddevices.TheRADIUS
filter‐IDand
tunnelattributesarepartoftheRADIUSuseraccountandareincludedintheRADIUSaccess‐
acceptmessageresponsereceivedbytheswitchfromtheauthenticationserver.
Themaximumnumberofmultipleuserssupportedperportdependsonyourplatform.Referto
Appendix A,PolicyandAuthenticationCapacitiesfor
adescriptionofthemulti‐usercapacities
forthisdevice.Bydefault,thenumberofallowedusersperportissetto1.Toconfigurethe
numberofallowedusersperport,usethesetmultiauthportnumuserscommand.Usetheshow
multiauthportcommandtodisplaythecurrentvalues
of“Maxusers”and “A l l o w e d users”per
port.
Commands
For information about... Refer to page...
show multiauth 26-38
set multiauth mode 26-39
clear multiauth mode 26-39
set multiauth precedence 26-40
clear multiauth precedence 26-40
show multiauth port 26-41
set multiauth port 26-41