Configuring Multiple Authentication Methods
Enterasys D-Series CLI Reference 17-33
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)must beenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemulti‐userauthenticationfeatureallowsauserand theirIPphonetobothuse
asingleportontheD2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheD‐Seriesisimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLAN‐to‐policyrolemappings.
ThepolicyrolefortheIP phoneisstatically
mappedusingtheVLAN‐to‐policymappingfea ture
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVID
ismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismapped tothepolicyrolesetintheFilter‐ID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethe
PVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: D2 devices support up to two authenticated users per port.
Note: The only Multi-User Authentication supported on the D2 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.
For information about... Refer to page...
show multiauth 17-34
set multiauth mode 17-35
clear multiauth mode 17-35