EasyManuals Logo

Enterasys SecureStack B3 User Manual

Enterasys SecureStack B3
582 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #538 background imageLoading...
Page #538 background image
Configuring Multiple Authentication Methods
20-30 Security Configuration
Parameters
None.
Defaults
None.
Mode
Switchcommand,readwrite.
Example
ThisexampleresetstheMACauthenticationsignificantbitsto48.
B3(su)->clear macauthentication significant-bits
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusinguptotwomethods
onthesameport.Inorderformultipleauthentication tofunctiononthede vice,eachpossible
methodofauthentication(MACauthentication,802.1X,PWA)mustbeenabledgloballyand
configuredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribedin
thischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemultiuserauthenticationfeatureallowsauserandtheirIPphonetobothuse
asingleportontheB3buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackB3isimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIPphoneisstatically
mappedusingtheVLANtopolicymappingfeature
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanind icat e dpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetasthe portʹsPVID
ismappedtothedefaultpolicy
Note: B3 devices support up to eight authenticated users per port.
Note: The only Multi-User Authentication supported on the B3 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys SecureStack B3 and is the answer not in the manual?

Enterasys SecureStack B3 Specifications

General IconGeneral
BrandEnterasys
ModelSecureStack B3
CategorySwitch
LanguageEnglish

Related product manuals