This figure shows 802.1x port-based authentication in a wireless LAN.
Figure 20: Multiple Host Mode Example
802.1x Multiple Authentication Mode
Multiple-authentication (multiauth) mode allows one client on the voice VLAN and multiple authenticated
clients on the data VLAN. When a hub or access point is connected to an 802.1x-enabled port,
multiple-authentication mode provides enhanced security over multiple-hosts mode by requiring authentication
of each connected client. For non-802.1x devices, you can use MAC authentication bypass or web authentication
as the fallback method for individual host authentications to authenticate different hosts through by different
methods on a single port.
Multiple-authentication mode also supports MDA functionality on the voice VLAN by assigning authenticated
devices to either a data or voice VLAN, depending on the VSAs received from the authentication server.
Guest VLAN and authentication-failed VLAN features are supported for ports configured in
multiple-authentication mode.
Note
Beginning with Cisco IOS Release 12.2(55)SE, you can assign a RADIUS-server-supplied VLAN in multi-auth
mode, under these conditions:
•
Only one voice VLAN assignment is supported on a multi-auth port.
•
The behavior of the critical-auth VLAN is not changed for multi-auth mode. When a host tries to
authenticate and the server is not reachable, all authorized hosts are reinitialized in the configured VLAN.
MAC Move
When a MAC address is authenticated on one switch port, that address is not allowed on another authentication
manager-enabled port of the switch. If the switch detects that same MAC address on another authentication
manager-enabled port, the address is not allowed.
There are situations where a MAC address might need to move from one port to another on the same switch.
For example, when there is another device (for example a hub or an IP phone) between an authenticated host
and a switch port, you might want to disconnect the host from the device and connect it directly to another
port on the same switch.
You can globally enable MAC move so the device is reauthenticated on the new port. When a host moves to
a second port, the session on the first port is deleted, and the host is reauthenticated on the new port.
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01
223
Configuring IEEE 802.1x Port-Based Authentication
802.1x Multiple Authentication Mode