802.1X Multiple Authentication Mode; Mac Move - Cisco Catalyst 2960-XR Security Configuration Manual

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

Configuring IEEE 802.1x Port-Based Authentication
This figure shows 802.1x port-based authentication in a wireless LAN.
Figure 20: Multiple Host Mode Example

802.1x Multiple Authentication Mode

Multiple-authentication (multiauth) mode allows one client on the voice VLAN and multiple authenticated
clients on the data VLAN. When a hub or access point is connected to an 802.1x-enabled port,
multiple-authentication mode provides enhanced security over multiple-hosts mode by requiring authentication
of each connected client. For non-802.1x devices, you can use MAC authentication bypass or web authentication
as the fallback method for individual host authentications to authenticate different hosts through by different
methods on a single port.
Multiple-authentication mode also supports MDA functionality on the voice VLAN by assigning authenticated
devices to either a data or voice VLAN, depending on the VSAs received from the authentication server.
Guest VLAN and authentication-failed VLAN features are supported for ports configured in
Note
multiple-authentication mode.
Beginning with Cisco IOS Release 12.2(55)SE, you can assign a RADIUS-server-supplied VLAN in multi-auth
mode, under these conditions:
• Only one voice VLAN assignment is supported on a multi-auth port.
• The behavior of the critical-auth VLAN is not changed for multi-auth mode. When a host tries to

MAC Move

When a MAC address is authenticated on one switch port, that address is not allowed on another authentication
manager-enabled port of the switch. If the switch detects that same MAC address on another authentication
manager-enabled port, the address is not allowed.
There are situations where a MAC address might need to move from one port to another on the same switch.
For example, when there is another device (for example a hub or an IP phone) between an authenticated host
and a switch port, you might want to disconnect the host from the device and connect it directly to another
port on the same switch.
You can globally enable MAC move so the device is reauthenticated on the new port. When a host moves to
a second port, the session on the first port is deleted, and the host is reauthenticated on the new port.
OL-29434-01
authenticate and the server is not reachable, all authorized hosts are reinitialized in the configured VLAN.
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
802.1x Multiple Authentication Mode
223

Advertisement

Table of Contents
loading

Table of Contents