EasyManua.ls Logo

Enterasys b5

Enterasys b5
714 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Multiple Authentication Methods
Enterasys B5 CLI Reference 22-37
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowsausertoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)must beenabledglobally
andconfiguredappropriatelyonthedesiredportswithits
correspondingcommandsetdescribed
inthischapter.Theprecedenceconfiguredfortheauthenticationmethodsdetermineswhich
authenticationmethodisactuallyappliedtotheuser,device,orport.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.Authenticationprecedencecanbeconfiguredwiththe
setmultiauthprecedence
command.
About Multi-User Authentication
Multiuserauthenticationreferstotheabilitytoauthenticate morethanoneuserordeviceonthe
sameport,witheachuserordevicebeingprovidedtheappropriatelevelofnetworkresources
basedonpolicy.
Whenasinglesupplicantconnectedtoanaccess layerportauthenticates,apolicyprofilecanbe
dynamicallyappliedtoalltrafficontheport.Whenmultiuserauthenticationisnotimplemented,
andmorethanonesupplicantisconnectedtoaport,thefirmwaredoesnotprovisionnetwork
resourcesonaperuserorperdevicebasis,eventhoughdifferentusersordevicesmayrequirea
differentset
ofnetworkresources.
Inordertosupportprovisioningnetworkresourcesonaperuserbasis,byapplyingthepolicy
configuredintheRADIUSfilterIDorRFC3580tunnelat tributesforagivenuserordevice,the
switchmustbethepointofauthenticationfortheattacheddevi ces.TheRADIUS
filterIDand
tunnelattributesarepartoftheRADIUSuseraccountandareincludedintheRADIUSaccess
acceptmessageresponsereceivedbytheswitchfromtheauthenticationserver.
Themaximumnumberofmultipleuserssupportedperportdependsonyourplatform.Referto
Appendix A,PolicyandAuthenticationCapacitiesfor
adescriptionofthemultiusercapacities
foryourdevice.Bydefault,thenumberofallowedusersperportissetto1.Toconfigurethe
numberofallowedusersperport,usethesetmultiauthportnumuserscommand.Usetheshow
multiauthportcommandtodisplaythecurrentvalues
of“Maxusers”and“A l l o w e d users”per
port.
Commands
For information about... Refer to page...
show multiauth 22-38
set multiauth mode 22-39
clear multiauth mode 22-39
set multiauth precedence 22-40
clear multiauth precedence 22-40
show multiauth port 22-41
set multiauth port 22-41

Table of Contents