Specifications

Configuring Multiple Authentication Methods
SecureStack B2 Configuration Guide 19-33
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)mustbeenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemultiuserauthenticationfeatureallowsauserandtheirIP phonetobothuse
asingleportontheB2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackB2isimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIP phoneisstatically
mappedusingtheVLANtopolicymappingfea ture
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.RefertotheUsage
sectionforthecommandsetpolicyruleonpage 1210foradditionalinformation.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.When
thedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVIDismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismappedtothepolicy
rolesetintheFilterID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethePVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: B2 devices support up to three authenticated users per port.
Note: The only Multi-User Authentication supported on the B2 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.
For information about... Refer to page...
show multiauth 19-34
set multiauth mode 19-35
clear multiauth mode 19-35