Multi-Supplicant Authentication; Authentication - Dell C9000 Series Networking Configuration Manual

Hide thumbs Also See for C9000 Series:
Table of Contents

Advertisement

Guest VLAN id:
Auth-Fail VLAN:
Auth-Fail VLAN id:
Auth-Fail Max-Attempts:
Critical VLAN:
Critical VLAN id:
Mac-Auth-Bypass:
Mac-Auth-Bypass Only:
Static-MAB:
Static-MAB Profile:
Tx Period:
Quiet Period:
ReAuth Max:
Supplicant Timeout:
Server Timeout:
Re-Auth Interval:
Max-EAP-Req:
Host Mode:
Auth PAE State:
Backend State:

Multi-Supplicant Authentication

802.1X multi-supplicant authentication enables multiple devices on a single authenticator port to access the
network by authenticating each device. In addition, multi-supplicant authentication uses dynamic MAC-based
VLAN assignment to place devices on different VLANs. This feature is different from multi-host authentication
in which multiple devices connected to a single authenticator port can access the network after only the one
device is authenticated, and all hosts are placed in the same VLAN as the authenticated device.
Multi-supplicant authentication is needed, for example, in the case of a workstation at which a VoIP phone
and PC are connected to a single authenticator port. Multi-host authentication could authenticate the first
device to respond, and then both devices could access the network. However, if you wanted to place them in
different VLANs — a VoIP VLAN and a data VLAN — you would need to authenticate the devices separately so
that the RADIUS server can send each device's VLAN assignment during that devices authentication process.
During the authentication process, the switch is able to learn the MAC address of the device though the
EAPoL frames, and the VLAN assignment from the RADIUS server. With this information it creates an
authorized-MAC-to-VLAN mapping table per port. Then, the system can tag all incoming untagged frames
with the appropriate VLAN-ID based on the table entries.
Configuring Multi-Supplicant Authentication
To enable multi-supplicant authentication on a port, enter the dot1x host-mode multi-auth command
in Interface mode. To return to the default single-host authentication mode, enter the no dot1x host-
mode command. To verify the currently configured authentication mode, enter the show dot1x interface
command.
Dell(conf-if-te-1/3)# dot1x host-mode multi-auth
Dell(conf-if-te-1/3)# do show dot1x interface tengigabitethernet 0103
802.1x information on Te 0/0:
-----------------------------
Dot1x Status:
NONE
Disable
NONE
NONE
Disable
NONE
Disable
Disable
Disable
NONE
30 seconds
60 seconds
2
30 seconds
30 seconds
3600 seconds
2
SINGLE_HOST
Connecting
Idle
Enable
802.1X
121

Advertisement

Table of Contents
loading

Table of Contents