Specifications
Authentication Overview
April 15, 2011 Page 4 of 36
switchcancontainanyFilter‐IDattributeconfiguredontheauthenticationserver,allowingpolicy
tobeappliedfortheauthenticatinguser.
PWAenhancedmodeissupported.PWAenhancedmodeallowsauseronanun‐authenticated
PWAporttoenteranyURLintothebrowserandbepresentedthePWAlogin
pageontheirinitial
webaccess.Whenenhancedmodeisdisabled,ausermustenterthecorrectURLtoaccesslogin.
Themodularswitches,B‐SeriesandC‐Seriesstackablefixedswitches,andthestandalonefixed
switchessupportPWA.
Convergence End Point (CEP)
CEPdetectsanIPtelephonyorvideodeviceonaportand dynamicallyappliesaspecificpolicyto
theport.Theswitchdetectsaconvergenceendpointbyinspectingreceivedpacketsforspecific
trafficattributes.CEPdoesnotrequireaRADIUSconfiguration.
TheCEPimplementationsupportsthefollowingdetectionmethods:
• Cisco
PhoneDetection‐thefirmwareparsesaCiscoDiscoveryProtocol(CDP)packetto
identifythephonetype.IfitwassentbyanIPphone,thefirmwareusesthephonetype.A
responseissentbacktothephone,verifyingauthentication.
• SiemensHiPathPhoneDetection‐TCP/UPDportnumbersnooping
isused.Port4060isthe
defaultportforcommunication.
• H.323PhoneDetection‐TCP/UDPportnumbersnoopingandreservedIPaddresssnooping
areused.Ports1718‐1720andIPaddress224.0.1.41arethedefaultvalues.
• SessionInitiationProtocol(SIP)PhoneDetection‐TCP/UDPportnumbersnoopingand
reserved
IPaddresssnoopingareused.Port5060andIPaddress224.0.1.75arethedefault
values.
ThemodularswitchessupportCEP.
Multi-User And MultiAuth Authentication
Thissectionwilldiscussmulti‐userandMultiAuthauthentication.Multi‐userandMultiAuthare
separateconcepts.Theprimarydifferencebetweenthetwoisasfollows:
•Multi‐userauthenticationreferstotheabilitytoauthenticatemultipleusersanddeviceson
thesameport,witheachuserordevicebeingprovidedtheappropriate
levelofnetwork
resourcesbaseduponpolicy.
•MultiAuthauthenticationreferstotheabilityofasingleormultipleuser(s),device(s),or
port(s)tosuccessfullyauthenticateusingmultipleauthenticationmethodsatthesametime,
suchas802.1x,PWA,andMAC,withprecedencedeterminingwhic hauthenticationmethodis
actuallyappliedtothat
user,device,orport.
Note: For stackable fixed switches and standalone fixed switches:
• One user per PWA-configured port can be authenticated
• PWA authentication supports RFC 3580 VLAN authorization on B3, B5, C3, C5,and G3 devices