Specifications

Configuring Authentication
April 15, 2011 Page 22 of 36
switchdevices).Youmaychangetheprecedenceforoneormoremethodsbysettingthe
authenticationmethodsintheorderofprecedencefromhightolow.Anymethodsnotenteredare
givenalowerprecedencethanthemethodsenteredintheirpreexistingorder.Forinstance,ifyou
startwiththe
defaultorderandonlysetPWAandMAC,thenewprecedenceorderwillbePWA,
MAC,802.1x,andCEP.
Giventhedefaultorderofprecedence(802.1x,PWA,MAC,andCEP),ifauserwastosuccessfully
authenticatewithPWAandMAC,theauthenticationmethodRADIUSFilterIDappliedwouldbe
PWA,becauseithasahigherpositionintheorder.AMACsessionwouldauthenticate,butits
associatedRADIUSFilterIDwouldnotbeapplied.
Procedure 8describessettingtheorderforMultiAuthauthenticationprecedence.
Setting MultiAuth Authentication Port Properties
MultiAuthauthenticationsupportstheconfigurationofMultiAuthportandmaximumnumberof
usersperportproperties.TheMultiAuthportpropertycanbeconfiguredasfollows:
AuthenticationOptionalAuthenticationmethodsareactiveontheportbaseduponthe
globalandportauthentica tionmethod.Beforeauthenticationsucceeds,thecurrentpolicyrole
applied
totheportisassignedtotheingresstraffic.Thisisthedefaultroleifnoauthenticated
userordeviceexistsontheport.Afterauthenticationsucceeds,theuserordeviceisallowed
toaccessthenetworkaccordingtothepolicyinformationreturnedfromtheauthentication
server,intheform
oftheRADIUSFilterIDattribute,orthestaticconfigurationontheswitch.
Thisisthedefaultsetting.
AuthenticationRequiredAuthenticationmethodsareactiveontheport,basedonthe
globalandperportauthenticationmethodconfigured.Beforeauthenticationsucceeds,no
trafficisforwardedontothenetwork.Afterauthenticationsucceeds,
theuserordevicegains
accesstothenetworkbaseduponthepolicyinfo rmationreturnedbytheauthenticationserver
intheformoftheRADIUSFilterIDattribute,orthestaticconfigurationontheswitch.
ForceAuthenticatedTheportiscompletelyaccessiblebyallusersanddevicesconnectedto
theport,allauthenticationmethodsareinactiveontheport,andallframesareforwarded
ontothenetwork.
ForceUnauthenticatedTheportiscompletelyclosedforaccessbyallusersanddevices
connectedtotheport.Allauthenticationmethodsareinactiveandallframesarediscarded.
Procedure 8 MultiAuth Authentication Precedence Configuration
Step Task Command(s)
1. Set a new order of precedence for the selection
of the RADIUS Filter-ID that will be returned
when multiple authentication methods are
authenticated at the same time for a single user.
set multiauth precedence {[dot1x] [mac]
[pwa] [cep] [radius-snooping]}
2. Reset the order MultiAuth authentication
precedence to the default values.
clear multiauth precedence