EasyManuals Logo
Home>Enterasys>Switch>D-Series

Enterasys D-Series User Manual

Enterasys D-Series
540 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #495 background imageLoading...
Page #495 background image
Configuring Multiple Authentication Methods
Enterasys D-Series CLI Reference 17-33
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)must beenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemultiuserauthenticationfeatureallowsauserand theirIPphonetobothuse
asingleportontheD2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheDSeriesisimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIP phoneisstatically
mappedusingtheVLANtopolicymappingfea ture
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVID
ismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismapped tothepolicyrolesetintheFilterID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethe
PVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: D2 devices support up to two authenticated users per port.
Note: The only Multi-User Authentication supported on the D2 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.
For information about... Refer to page...
show multiauth 17-34
set multiauth mode 17-35
clear multiauth mode 17-35

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys D-Series and is the answer not in the manual?

Enterasys D-Series Specifications

General IconGeneral
BrandEnterasys
ModelD-Series
CategorySwitch
LanguageEnglish

Related product manuals