Configuring Multiple Authentication Methods
SecureStack C2 Configuration Guide 23-33
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)mustbeenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemulti‐userauthenticationfeatureallowsauserandtheirIP phonetobothuse
asingleportontheC2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackC2isimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLAN‐to‐policyrolemappings.
ThepolicyrolefortheIP phoneisstatically
mappedusingtheVLAN‐to‐policymappingfea ture
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.RefertotheUsage
sectionforthecommand“setpolicyrule”onpage 11‐10foradditionalinformation.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.When
thedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVIDismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismappedtothepolicy
rolesetintheFilter‐ID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethePVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: C2 devices support up to six authenticated users per port.
Note: The only Multi-User Authentication supported on the C2 is User + IP phone. The IP phone
has to authenticate using 802.1x or MAC authentication, but the User may authenticate using
802.1x, PWA, or MAC authentication.
For information about... Refer to page...
show multiauth 23-34
set multiauth mode 23-35
clear multiauth mode 23-35