Specifications

Authentication Overview
April 15, 2011 Page 6 of 36
Figure 1 Applying Policy to Multiple Users on a Single Port
MultiAuth Authentication
Authenticationmodesupportprovidesforthe globalsettingofasingleauthenticationmode
802.1X(strictmode)ormultiplemodes(MultiAuth)peruserorportwhenauthenticating.
Strictmodeistheappropriatemodewhenauthenticatingasingle802.1Xuser.Alltrafficonthe
portreceivesthesamepolicyinstrictmode.When
authenticatingPWA,CEP,orMAC,youmust
useMultiAuthauthentication,whetherauthenticatingasingleormultiplesupplicants.
MultiAuthauthenticationsupportsthesimultaneousconfigurationofuptothreeauthentication
methodsperuseronthesameport,butonlyonemethodperuserisactuallyapplied.When
MultiAuthauthenticationportshaveacombination
ofauthenticationmethodsenabled,andauser
issuccessfullyauthenticatedformorethanonemethodatthesametime,theconfigured
authenticationmethodprecedencewilldeterminewhichRADIUSreturnedFilterIDwillbe
processedandresultinanappliedtrafficpolicyprofile.SeeSettingMultiAuthAuthentication
Precedenceonpage 21
forauthenticationmethodprecedencedetails.
ThenumberofusersordevicesMultiAuthauthenticationsupportsdependsuponthetypeof
device,whethertheportsarefixedaccessoruplink,andwhetherincreasedportcapacityorextra
chassisusercapacityMUAlicenseshavebeenapplied.Seethefirmwarecustomerreleasenote
thatcomes
withyourdevicefordetailsonthenumberofusersordevicessupportedperport.
InFigure 2,multipleusersareauthenticatedonasingleporteachwithadifferentauthentication
method.Inthiscase,eachuseronasingleportsuccessfullyauthenticateswithadifferent
authenticationtype.Theauthenticationmethodis
includedintheauthenticationcredentialssent
totheRADIUSserver.RADIUSlooksuptheuseraccountforthatuserbasedupontheSMAC.The
FilterIDforthatuserisreturnedtotheswitchintheauthenticationresponse,andthe
authenticationisvalidatedforthatuser.
User 1
SMAC
00-00-00-11-11-11
User 2
SMAC
00-00-00-22-22-22
User 3
SMAC
00-00-00-33-33-33
Authentication
Request
Authentication
Credentials User 2
User1 Filter ID --> Policy X
User2 Filter ID --> Policy Y
User3 Filter ID --> Policy Z
Authentication
Credentials User 1
Authentication
Credentials User 3
Dynamic Admin Rule
for Policy 1
SMAC = 00-00-00-11-11-11
ge.1.5
Dynamic Admin Rule
for Policy 2
SMAC = 00-00-00-22-22-22
ge.1.5
Dynamic Admin Rule
for Policy 3
SMAC = 00-00-00-33-33-33
ge.1.5
Authentication
Response
Authentication
Request
Authentication
Response
Authentication
Request
Switch
Authentication
Response
Radius Server
Port ge.1.5