auth-mode

Specifies the authentication mode, for example, single-host, multiple-hosts, or multiple-untagged.
Syntax
auth-mode { multiple-hosts | multiple-untagged | single-host | single-untagged }
Command Default

By default, single-untagged is the authentication mode.

Parameters
multiple-hosts

Specifies that Flexible authentication operates in multiple-host mode.

multiple-untagged

Specifies that Flexible authentication operates in multiple-untagged mode.

single-host

Specifies that Flexible authentication operates in single-host mode.

single-untagged

Specifies that Flexible authentication operates in single-untagged mode.

Usage Guidelines

The port-level auth-mode configuration overrides the global auth-mode configuration.

For ICX 8200 devices, when the multiple‑untagged keyword is used, the VRF must be configured on the VLAN interfaces (VEs) for all VLANs to which authenticated clients will be assigned before client authentication occurs. Dynamic changes to VRF configuration are not supported while authenticated clients are present in the VLAN. If authenticated clients are assigned to VLANs associated with a non‑default VRF, inter‑VLAN traffic must be routed within the same VRF; clients cannot communicate across different VRFs.

Modes

authentication configuration sub-mode

Examples

The following example configures Flexible authentication single host mode.

device# configure terminal
device(config)# authentication
device(config-authen)# auth-mode single-host
History
Release version Command history
08.0.80 This command was introduced.