Open1X Authentication; Multidomain Authentication - Cisco Catalyst 2960-X Security Configuration Manual

Cisco ios release 15.0(2)ex
Hide thumbs Also See for Catalyst 2960-X:
Table of Contents

Advertisement

Open1x Authentication

• multi-auth—Multiauthentication allows one authentication on a voice VLAN and multiple authentications
• multi-domain—Multidomain authentication allows two authentications: one on the voice VLAN and
Related Topics
Configuring Flexible Authentication Ordering, on page 350
Open1x Authentication
Open1x authentication allows a device access to a port before that device is authenticated. When open
authentication is configured, a new host can pass traffic according to the access control list (ACL) defined on
the port. After the host is authenticated, the policies configured on the RADIUS server are applied to that
host.
You can configure open authentication with these scenarios:
• Single-host mode with open authentication–Only one user is allowed network access before and after
• MDA mode with open authentication–Only one user in the voice domain and one user in the data domain
• Multiple-hosts mode with open authentication–Any host can access the network.
• Multiple-authentication mode with open authentication–Similar to MDA, except multiple hosts can be
Related Topics
Configuring Open1x, on page 352

Multidomain Authentication

The switch supports multidomain authentication (MDA), which allows both a data device and voice device,
such as an IP phone (Cisco or non-Cisco), to authenticate on the same switch port. The port is divided into a
data domain and a voice domain.
For all host modes, the line protocol stays up before authorization when port-based authentication is
Note
configured.
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
292
on the data VLAN.
one on the data VLAN.
authentication.
are allowed.
authenticated.
Note
If open authentication is configured, it takes precedence over other authentication
controls. This means that if you use the authentication open interface configuration
command, the port will grant access to the host irrespective of the authentication
port-control interface configuration command.
Configuring IEEE 802.1x Port-Based Authentication
OL-29048-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents