Specifications
Configuring Authentication
April 15, 2011 Page 22 of 36
switchdevices).Youmaychangetheprecedenceforoneormoremethodsbysettingthe
authenticationmethodsintheorderofprecedencefromhightolow.Anymethodsnotenteredare
givenalowerprecedencethanthemethodsenteredintheirpre‐existingorder.Forinstance,ifyou
startwiththe
defaultorderandonlysetPWAandMAC,thenewprecedenceorderwillbePWA,
MAC,802.1x,andCEP.
Giventhedefaultorderofprecedence(802.1x,PWA,MAC,andCEP),ifauserwastosuccessfully
authenticatewithPWAandMAC,theauthenticationmethodRADIUSFilter‐IDappliedwouldbe
PWA,becauseithasahigherpositionintheorder.AMACsessionwouldauthenticate,butits
associatedRADIUSFilter‐IDwouldnotbeapplied.
Procedure 8describessettingtheorderforMultiAuthauthenticationprecedence.
Setting MultiAuth Authentication Port Properties
MultiAuthauthenticationsupportstheconfigurationofMultiAuthportandmaximumnumberof
usersperportproperties.TheMultiAuthportpropertycanbeconfiguredasfollows:
• AuthenticationOptional–Authenticationmethodsareactiveontheportbaseduponthe
globalandportauthentica tionmethod.Beforeauthenticationsucceeds,thecurrentpolicyrole
applied
totheportisassignedtotheingresstraffic.Thisisthedefaultroleifnoauthenticated
userordeviceexistsontheport.Afterauthenticationsucceeds,theuserordeviceisallowed
toaccessthenetworkaccordingtothepolicyinformationreturnedfromtheauthentication
server,intheform
oftheRADIUSFilter‐IDattribute,orthestaticconfigurationontheswitch.
Thisisthedefaultsetting.
• AuthenticationRequired–Authenticationmethodsareactiveontheport,basedonthe
globalandperportauthenticationmethodconfigured.Beforeauthenticationsucceeds,no
trafficisforwardedontothenetwork.Afterauthenticationsucceeds,
theuserordevicegains
accesstothenetworkbaseduponthepolicyinfo rmationreturnedbytheauthenticationserver
intheformoftheRADIUSFilter‐IDattribute,orthestaticconfigurationontheswitch.
• ForceAuthenticated–Theportiscompletelyaccessiblebyallusersanddevicesconnectedto
theport,allauthenticationmethodsareinactiveontheport,andallframesareforwarded
ontothenetwork.
• ForceUnauthenticated–Theportiscompletelyclosedforaccessbyallusersanddevices
connectedtotheport.Allauthenticationmethodsareinactiveandallframesarediscarded.
Procedure 8 MultiAuth Authentication Precedence Configuration
Step Task Command(s)
1. Set a new order of precedence for the selection
of the RADIUS Filter-ID that will be returned
when multiple authentication methods are
authenticated at the same time for a single user.
set multiauth precedence {[dot1x] [mac]
[pwa] [cep] [radius-snooping]}
2. Reset the order MultiAuth authentication
precedence to the default values.
clear multiauth precedence