Configuring Multiple Authentication Methods
Enterasys D-Series CLI Reference 17-33
Configuring Multiple Authentication Methods

About Multiple Authentication Types

Whenenabled,multipleauthenticationtypesallowuserstoauthenticateusingmorethanone
methodonthesameport.Inorderformultipleauthenticationtofunctiononthedevice,each
possiblemethodofauthentication(MACauthentication,802.1X,PWA)mustbeenabledglobally
andconfiguredappropriatelyonthedesiredportswithitscorrespondingcommandsetdescribed
inthischapter.
Multipleauthenticationmodemustbegloballyenabledonthedeviceusingthesetmultiauth
modecommand.

Configuring Multi-User Authentication (User + IP phone)

TheUser+IPphonemultiuserauthenticationfeatureallowsauserandtheirIPphonetobothuse
asingleportontheD2buttohaveseparatepolicyroles.
ʺUser+IPPhoneʺAuthenticationontheDSeriesisimplementedbyassigninganingressed
packetreceivedonaporttoapolicyrolebasedontheVLANthepacketwasassignedto,andnot
thepacketʹssourceMACaddress.Therefore,onaportconfiguredforUser+IPPhone
Authentication,thereexiststwodifferentVLANtopolicyrolemappings.
ThepolicyrolefortheIPphoneisstaticallymappedusingtheVLANtopolicymappingfeature
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(forexample,Voice
VLAN)toanindicatedpolicyrole(forexample,IPPhonepolicyrole).Therefore,itisrequiredthat
IPphoneisconfiguredtosendVLANtaggedpacketstothe“Voice”VLAN.
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork.Whenthedefault
policyroleisassignedonaport,theVLANsetastheportʹsPVIDismappedtothedefaultpolicy
role.Whenapolicyroleisdynamicallyappliedtoaportastheresultofasuccessfully
authenticatedsession,the“authenticatedVLAN”ismappedtothepolicyrolesetintheFilterID
returnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbethePVIDoftheport,
ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedinthePVIDOverride
ifthePVIDOverrideisenabled.
Commands
Note: D2 devices support up to two authenticated users per port.
Note: The only Multi-User Authentication supported on the D2 is User + IP phone. The IP phone
and the user may authenticate using 802.1x or MAC authentication.
For information about... Refer to page...
show multiauth 17-34
set multiauth mode 17-35
clear multiauth mode 17-35