Configuring Multiple Authentication Methods
20-30 Security Configuration
Parameters
None.
Defaults
None.
Mode
Switchcommand,read‐write.
Example
ThisexampleresetstheMACauthenticationsignificantbitsto48.
B3(su)->clear macauthentication significant-bits
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusinguptotwomethods
onthesameport.Inorderformultipleauthentication tofunctiononthede vice,eachpossible
methodofauthentication(MACauthentication,802.1X,PWA)mustbeenabledgloballyand
configuredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribedin
thischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemulti‐userauthenticationfeatureallowsauserandtheirIPphonetobothuse
asingleportontheB3buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackB3isimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLAN‐to‐policyrolemappings.
ThepolicyrolefortheIPphoneisstatically
mappedusingtheVLAN‐to‐policymappingfeature
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanind icat e dpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetasthe portʹsPVID
ismappedtothedefaultpolicy
Note: B3 devices support up to eight authenticated users per port.
Note: The only Multi-User Authentication supported on the B3 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.