Specifications

Configuring Multiple Authentication Methods
21-34 Security Configuration
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowsuserstoauthenticateusinguptotwo
methodsonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)must beenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiau th
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemultiuserauthenticationfeatureallowsauserandtheirIPphonetobothto
useasingleportontheC3buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackC3isimplementedbyassigninganingressed
packetreceivedona
porttoapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIP phoneis
staticallymappedusingtheVLANtopolicy mappingfeature
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanind icat e dpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtagged
packetstothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetastheportʹs
PVIDismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismapped tothepolicyrolesetintheFilterID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbe
thePVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Thecommandsneededtoreview,enable,disable,andconfiguremultipleauthenticationarelisted
below:
Note: The only Multi-User Authentication supported on the C3 is User + IP phone. The IP phone
has to authenticate using 802.1x or MAC authentication, but the User may authenticate using
802.1x, PWA, or MAC authentication.
For information about... Refer to page...
show multiauth 21-36
set multiauth mode 21-37
clear multiauth mode 21-37
set multiauth precedence 21-38
clear multiauth precedence 21-38