Specifications
Authentication Overview
April 15, 2011 Page 5 of 36
Multi-User Authentication
Multi‐userauthenticationprovidesfortheper‐userorper‐deviceprovisioningofnetwork
resourceswhenauthenticating.Itsupportstheabilitytoreceivefromtheauthenticationserver:
•Apolicytrafficprofile,basedontheuseraccount’sRADIUSFilter‐IDconfiguration
•AbaseVLAN‐ID,basedontheRFC3580tunnelattributesconfiguration,
alsoknownas
dynamicVLANassignment
Whenasinglesupplicantconnectedtoanaccess layerportauthenticates,apolicyprofilecanbe
dynamicallyappliedtoalltrafficontheport.Whenmulti ‐userauthenticationisnot implemented,
andmorethanonesupplicantisconnectedtoaport,firmwaredoesnotprovision
network
resourcesonaper‐userorper‐devicebasis.Differentusersordevicesmayrequireadifferentset
ofnetworkresources.ThefirmwaretracksthesourceMACaddressforeachauthenticatinguser
regardlessoftheauthenticatingprotocolbeingused.Provisioningnetworkresourcesona
per‐userbasisisaccomplished
byapplyingthepolicyconfiguredintheRADIUSFilter‐ID,orthe
baseVLAN‐IDconfiguredintheRFC3580tunnelattributes,foragivenuser’sMACaddress.The
RADIUSFilter‐IDandtunnelattributesarepartoftheRADIUSuseraccountandareincludedin
theRADIUSAcceptmessageresponse
fromtheauthenticationserver.
Thenumberofallowedusersperportcanbeconfiguredusingthesetmultiauthportnumusers
command.Theshowmultiauthportcommanddisplaysboththeallowednumberofusers
configuredandthemaximumnumberofuserssupportedperportforthedevice.Theallowed
numberofusers
defaultstothemaximumnumberofsupportedusersfortheportforamodular
switchplatformandto1forthestackablefixedswitchandstandal onefixedswitchplatforms.
InFigure 1eachuseronportge.1.5sendsanauthenticationrequesttotheRADIUSserver.Based
upontheSourceMACaddress(SMAC),
RADIUSlooksuptheaccountforthatuserandincludes
theFilter‐IDassociatedwiththataccountintheauthenticationresponsebacktotheswitch(see
section“TheRADIUSFilter‐ID”onpage 9forFilter‐IDinformation).Thepolicyspecifiedinthe
Filter‐IDisthenappliedtothe
user.SeesectionRFC3580onpage 10forinformationondynamic
VLANassignmentandtunnelattributeconfiguration.
Note: Multi-user authentication on stackable fixed switch and standalone fixed switch platforms
requires that the switch be the point of authentication, in order to apply policy.