cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3331
Views
0
Helpful
8
Replies

[ISE]Does Multi-auth work for hub only? How about switch?

yijiework
Level 1
Level 1

I need to use 2960s lanlite version as a access switch, but this model can do nothing with posture and web auth.

So I have to use multi-auth instead on compact switch for endpoint auth.

But I noticed only HUB can work with multi-auth.

Is there any solution for my requirement?

8 Replies 8

Saurav Lodh
Level 7
Level 7

Multi-auth is designed when there are multiple endpoints connected to the same switchport and you want only one endpoint to authenticate. If one endpoint authenticates succesfully then all the other endpoints will enter the network without authentication.

So, when are multiple endpoints connected to a switchport ? Certainly when using a hub, but also when an automous access point, a laptop will multiple virtual machines, or even a switches connects to a switchport configured with 802.1x

Please rate if this helps

multi-auth-Allow one client on the voice VLAN and multiple authenticated clients on the data VLAN. Each host is individually authenticated.

A manual said this.

Yes you're right, I was thinking of "multi-host" instead of "multi-auth". Sorry for the confusion

Tarik Admani
VIP Alumni
VIP Alumni

Hi you cannot use dot1x for hosts connected on a switch that is capable of spanning tree. The dot1x supplicant send frames to a reserved destination Mac that falls within the spanning tree range.

Basically any frames for dot1x are dropped from the switch behind the port.


Sent from Cisco Technical Support Android App

So maybe I can make 802.1x work by disablling STP?

And if my access switchs use default configuration, should I disable STP on vlan1?

yijiework
Level 1
Level 1

ADDITION:

I use 2960s as access switch, and haven't changed stock configuration.

Should I configurate it to make it work?

Tarik Admani
VIP Alumni
VIP Alumni

You shouldnt have to worry about your main switch. Just the switch plugged in behind it. Also make sure you have proper protection in place so a loop doesnt affect the rest of your network.


Sent from Cisco Technical Support Android App

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: