Specifications

Configuring 802.1X Authentication
RoamAbout Mobility System Software Configuration Guide 17-15
Binding User Authentication to Machine Authentication
BondedAuth™(bondedauthentication)isasecurityfeaturethatbindsan802.1Xusers
authenticationtoauthenticationofthemachinefromwhichtheuserisattemptingtologon.When
thisfeatureisenabled,MSSauthenticatesauseronlyifthemachinefromwhichtheuserlogson
hasalreadybeenauthenticated
separately.
Bydefault,MSSdoesnotbinduserauthenticationtomachineauthentication.Atrustedusercan
logonfromanymachineatt achedtothenetwork.
YoucanuseBondedAuthwithMicrosoftWindowsclientsthatsupportseparate802.1X
authenticationforthemachineitselfandforauserwhousesthemachine
tologontothenetwork.
NetworkadministratorssometimesusemachineauthenticationinaMicrosoftActiveDirectory
domaintorunloginscripts,andtocontroldefaults,applicationaccessandupdates,andsoon.
BondedAuthprovidesanaddedsecuritymeasure,byensuringthatatrustedusercanlogonto
thenetwork
onlyfromatrustedmachineknowntoActiveDirectory.
Forexample,ifuserbob.mycorp.comhasatrustedlaptopPCusedforworkbutalsohasa
personallaptopPC,youmightwanttobindBob’sauthenticationwiththeauthenticationofhis
workplacelaptop,host/boblaptop.mycorp.com.Inthiscase,Bobcanlog
ontothecompany
networkonlyfromhisworklaptop.
WhenBondedAuthisenabled, MSSretainsinformationaboutthemachine’ssessionwhenauser
logsonfromthatmachine.MSSauthenticatestheuseronlyiftherehasalreadybeenasuccessful
machineauthentication.Evidenceofthemachine’ssessioninMSS
indicatesthatthemachinehas
successfullyauthenticatedandisthereforetru st edbyMSS.IfMSSdoesnothavesession
informationforthemachine,MSSrefusestoauthenticatetheuseranddoesnotallowtheuser
ontothenetworkfromtheunauthenticatedmachine.
Authentication Rule Requirements
BondedAuthrequiresan802.1Xauthenticationruleforthemachineitself,andaseparate 8 02.1X
authenticationrulefortheuser(s).Usethebondedoptionintheuserauthenticationrule,butnot
inthemachineauthenticationrule.
Theauthenticationruleforthemachinemustbehigherupinthelistofau thentication
rulesthan
theauthenticationrulefortheuser.
Youmustuse802.1Xauthenticationrules.The802.1Xauthenticationruleforthemachinemust
usepassthroughastheprotocol.EnterasysNetworksrecommendsthatyoualsousepass
throughfortheusersauthentica tionrule.
Theruleforthemachineandtherule
fortheusermustuseaRADIUSservergroupasthemethod.
(Generally,inaBondedAuthconfiguration,theRADIUSserverswilluseauserdatabasestored
onanActiveDirectoryserver.)
(Foraconfigurationexample,seeBondedAuthConfigurationExampleonpage 1717.)
EnterasysNetworksrecommendsthatyoumake
therulesasgeneralaspossible.Forexample,if
theActiveDirectorydomainismycorp.com,thefollowinguserglobsmatchonallmachinenames
andusersinthedomain:
Note: If the 802.1X reauthentication parameter or the RADIUS Session-Timeout parameter is
applicable, the user must log in before the 802.1X reauthentication timeout or the RADIUS session-
timeout for the machine’s session expires. Normally, these parameters apply only to clients that use
dynamic WEP, or use WEP-40 or WEP-104 encryption with WPA or RSN.