Enterasys D-Series Specifications Page 495

  • Download
  • Add to my manuals
  • Print
  • Page
    / 540
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 494
Configuring Multiple Authentication Methods
Enterasys D-Series CLI Reference 17-33
Configuring Multiple Authentication Methods
About Multiple Authentication Types
Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication, 802.1X,PWA)must beenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorresponding
commandsetdescribed
inthischapter.
Multipleauthenti cationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.
Configuring Multi-User Authentication (User + IP phone)
TheUser+IPphonemultiuserauthenticationfeatureallowsauserand theirIPphonetobothuse
asingleportontheD2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheDSeriesisimplementedbyassigninganingressed
packetreceivedonaport
toapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIP phoneisstatically
mappedusingtheVLANtopolicymappingfea ture
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpackets
tothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVID
ismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismapped tothepolicyrolesetintheFilterID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethe
PVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: D2 devices support up to two authenticated users per port.
Note: The only Multi-User Authentication supported on the D2 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.
For information about... Refer to page...
show multiauth 17-34
set multiauth mode 17-35
clear multiauth mode 17-35
Page view 494
1 2 ... 490 491 492 493 494 495 496 497 498 499 500 ... 539 540

Comments to this Manuals

No comments