Specifications

Authentication Overview
April 15, 2011 Page 4 of 36
switchcancontainanyFilterIDattributeconfiguredontheauthenticationserver,allowingpolicy
tobeappliedfortheauthenticatinguser.
PWAenhancedmodeissupported.PWAenhancedmodeallowsauseronanunauthenticated
PWAporttoenteranyURLintothebrowserandbepresentedthePWAlogin
pageontheirinitial
webaccess.Whenenhancedmodeisdisabled,ausermustenterthecorrectURLtoaccesslogin.
Themodularswitches,BSeriesandCSeriesstackablefixedswitches,andthestandalonefixed
switchessupportPWA.
Convergence End Point (CEP)
CEPdetectsanIPtelephonyorvideodeviceonaportand dynamicallyappliesaspecificpolicyto
theport.Theswitchdetectsaconvergenceendpointbyinspectingreceivedpacketsforspecific
trafficattributes.CEPdoesnotrequireaRADIUSconfiguration.
TheCEPimplementationsupportsthefollowingdetectionmethods:
Cisco
PhoneDetectionthefirmwareparsesaCiscoDiscoveryProtocol(CDP)packetto
identifythephonetype.IfitwassentbyanIPphone,thefirmwareusesthephonetype.A
responseissentbacktothephone,verifyingauthentication.
SiemensHiPathPhoneDetectionTCP/UPDportnumbersnooping
isused.Port4060isthe
defaultportforcommunication.
H.323PhoneDetectionTCP/UDPportnumbersnoopingandreservedIPaddresssnooping
areused.Ports1718‐1720andIPaddress224.0.1.41arethedefaultvalues.
SessionInitiationProtocol(SIP)PhoneDetectionTCP/UDPportnumbersnoopingand
reserved
IPaddresssnoopingareused.Port5060andIPaddress224.0.1.75arethedefault
values.
ThemodularswitchessupportCEP.
Multi-User And MultiAuth Authentication
ThissectionwilldiscussmultiuserandMultiAuthauthentication.MultiuserandMultiAuthare
separateconcepts.Theprimarydifferencebetweenthetwoisasfollows:
•Multiuserauthenticationreferstotheabilitytoauthenticatemultipleusersanddeviceson
thesameport,witheachuserordevicebeingprovidedtheappropriate
levelofnetwork
resourcesbaseduponpolicy.
•MultiAuthauthenticationreferstotheabilityofasingleormultipleuser(s),device(s),or
port(s)tosuccessfullyauthenticateusingmultipleauthenticationmethodsatthesametime,
suchas802.1x,PWA,andMAC,withprecedencedeterminingwhic hauthenticationmethodis
actuallyappliedtothat
user,device,orport.
Note: For stackable fixed switches and standalone fixed switches:
One user per PWA-configured port can be authenticated
PWA authentication supports RFC 3580 VLAN authorization on B3, B5, C3, C5,and G3 devices