Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

multiple users same machine 802.1x/peap

I am trying to get multiple users to use the same machine but have different vlans assigned. i.e if user 1 logs in he gets vlan 1 if user2 logs in he gets vlan2. This works fine if I reboot between users, however, if I do shutdown, log off user1, the ctrl alt del and log in with user2, the switch never receives the eapol logoff, therefore never reauthenticates user2 and the switchport remains in vlan 1. Anyone else seen this behaviour?

1 REPLY
Silver

Re: multiple users same machine 802.1x/peap

Have you enabled the multiple-host option on the port in question? With the multiple-host option "not" enabled, when a host logs off, the server sends an EAPOL-logoff message causing the switch port to transition to the unauthorized state. Thus, when a new user logs in, the authentication process will be initiated again. My guess is that with the multiple-host option enabled, this message is being supressed since there might be other active hosts on the port, and sending the port into the unauthorized state will cut off the still-active hosts. Thus if you are not seeing the eapol logoff, you are probably seeing behaviour that is expected. Either this or you are running into some bug.

129
Views
0
Helpful
1
Replies
CreatePlease login to create content