Configuring Multiple Authentication Methods
18-30 Security Configuration
Parameters
None.
Defaults
None.
Mode
Switchcommand,read‐write.
Example
ThisexampleresetstheMACauthenticationsignificantbitsto48.
C2(su)->clear macauthentication significant-bits
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusinguptotwomethods
onthesameport.Inorderformultipleauthentication tofunctiononthede vice,eachpossible
methodofauthentication(MACauthentication,802.1X,PWA)mustbeenabledgloballyand
configuredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribedin
thischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemulti‐userauthenticationfeatureallowsauserandtheirIPphonetobothuse
asingleportontheC2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheSecureStackC2isimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLAN‐to‐policyrolemappings.
ThepolicyrolefortheIPphoneisstatically
mappedusingtheVLAN‐to‐policymappingfeature
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanind icat e dpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetasthe portʹsPVID
ismappedtothedefaultpolicy
Note: C2 devices support up to eight authenticated users per port.
Note: The only Multi-User Authentication supported on the C2 is User + IP phone. The IP phone
has to authenticate using 802.1x or MAC authentication, but the User may authenticate using
802.1x, PWA, or MAC authentication.