Authentication Modes
Flexible authentication supports the following
four modes to address the requirements of different usage models. The
authentication-enabled ports can be configured to be members of any mode using
the
auth-mode command
at the global level or using the authentication auth-mode command from the interface.
- Multiple Untagged: Different clients on the same port
can be placed in different untagged VLANs. Each client can be assigned a
different VLAN by the RADIUS server. Some clients who fail can move to a
restricted VLAN. Some clients who time out can move to a guest VLAN and other
VLANs.
Note:Does the limitation mentioned below also apply to ICX 8100?yesThe following limitation applies to ICX 8100 and ICX 8200 devices. To support DHCP snooping for Flexible authentication clients in multiple untagged mode, DHCP snooping should also be enabled on the Flexible authentication auth-default VLAN.
Example Flexible authentication configuration:
ICX8200-48P Router# configure terminal ICX8200-48P Router(config)# authentication ICX8200-48P Router(config-authen)# auth-default-vlan 12 ICX8200-48P Router(config-authen)# auth-mode multiple-untagged ICX8200-48P Router(config-authen)# exit
ICX8200-48P Router(config)# ip dhcp snooping vlan 12
ICX8200-48P Router(config)# ipv6 dhcp6 snooping vlan 12
- Single Untagged: This is the default auth-mode, where all the clients belong to one untagged VLAN only. This mode is the most common use case. When a hub and multiple clients are connected, the first client is moved to the RADIUS-assigned VLAN, and the subsequent clients are placed in the same VLAN. The subsequent authenticated clients are moved to the same VLAN even if RADIUS does not return any VLAN. If RADIUS returns different untagged VLANs, subsequent clients are blocked.
- Single Host: This mode allows authentication of only one host, and the status of the host is determined by the authentication. Access for all subsequent hosts is denied or blocked. In contrast, any connected IP phones are allowed access without authentication. The session exists only for the first host authenticated.
- Multiple Hosts: This mode allows authentication of the first device only, and the status of all other devices depends on the authentication status of the first device. This mode is typically used when the connecting device is a wireless AP that is authenticated by the ICX device, and the AP authenticates all pass-through wireless clients on the ICX device.
Dynamic assignment of VLANs in these modes varies depending on the format of the VLAN information in the RADIUS-returned Access-Accept message and whether the authentication is initiated by tagged or untagged ports. For more information, refer to Dynamic VLAN Assignment.