<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Multi Auth or Multi Host in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3753514#M487983</link>
    <description>&lt;P style="text-align: left;"&gt;One more question, if i need to go with the Multi Auth. What the factors should i need to consider and how can i start the thing?&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Nov 2018 13:17:28 GMT</pubDate>
    <dc:creator>jm.virtual01</dc:creator>
    <dc:date>2018-11-27T13:17:28Z</dc:date>
    <item>
      <title>Cisco ISE Multi Auth or Multi Host</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750414#M487907</link>
      <description>&lt;P&gt;I am confuse, between multi auth. and multi host arrangement. Can someone help to face this situation?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 03:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750414#M487907</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2018-11-21T03:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Multi Auth or Multi Host</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907#M487981</link>
      <description>&lt;P&gt;A quick overivew of multi-host, multi-domain, multi-auth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;multi-host&lt;/STRONG&gt;: Multiple mac addresses can be in DATA domain. Only first mac is authenticated.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;multi-domain&lt;/STRONG&gt;: Only 1 mac address can be in DATA domain and only 1 mac address can be in VOICE domain&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;multi-&lt;/STRONG&gt;&lt;STRONG&gt;auth&lt;/STRONG&gt;: Multiple mac addresses can be in DATA domain (all authenticated individually) and only 1 MAC address can be in Voice domain.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3750907#M487981</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-11-21T16:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Multi Auth or Multi Host</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3753514#M487983</link>
      <description>&lt;P style="text-align: left;"&gt;One more question, if i need to go with the Multi Auth. What the factors should i need to consider and how can i start the thing?&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 13:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3753514#M487983</guid>
      <dc:creator>jm.virtual01</dc:creator>
      <dc:date>2018-11-27T13:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Multi Auth or Multi Host</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3753519#M487985</link>
      <description>&lt;H3 class="topictitle3"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;I suggest you go through this reference document -&amp;nbsp; &lt;A href="https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_8021x/configuration/15-2mt/sec-ieee-802x-multi-auth.html" target="_blank"&gt;https://www.cisco.com/en/US/docs/ios-xml/ios/sec_usr_8021x/configuration/15-2mt/sec-ieee-802x-multi-auth.html&lt;/A&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Guidelines for Configuring IEEE 802.1X Multiple Authentication&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__GUID-0217497A-235E-4DD6-B074-87966D92314C" class="section"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__GUID-0217497A-235E-4DD6-B074-87966D92314C" target="_blank"&gt;&lt;/A&gt;
&lt;P&gt;Assign a RADIUS-server-supplied VLAN in multiple authentication mode, under these conditions:&lt;/P&gt;
&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__GUID-437A876D-0701-48DE-BF9E-5BE54DCEDC8C" target="_blank"&gt;&lt;/A&gt;
&lt;UL id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__GUID-437A876D-0701-48DE-BF9E-5BE54DCEDC8C"&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_E6F15AD818CB4694A26E03CF6DB6B00F"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_E6F15AD818CB4694A26E03CF6DB6B00F" target="_blank"&gt;&lt;/A&gt;The host is the first host authorized on the port, and the RADIUS server supplies VLAN information.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_9DB66044718D4E39844219859706EECD"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_9DB66044718D4E39844219859706EECD" target="_blank"&gt;&lt;/A&gt;Subsequent hosts are authorized with a VLAN that matches the operational VLAN.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_BC9A646B11C24BC0B351862379692F3E"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_BC9A646B11C24BC0B351862379692F3E" target="_blank"&gt;&lt;/A&gt;A host is authorized on the port with no VLAN assignment, and subsequent hosts either have no VLAN assignment, or their VLAN information matches the operational VLAN.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_7B7666162D5F44F4BA83F7692236865A"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_7B7666162D5F44F4BA83F7692236865A" target="_blank"&gt;&lt;/A&gt;The first host authorized on the port has a group VLAN assignment, and subsequent hosts either have no VLAN assignment, or their group VLAN matches the group VLAN on the port. Subsequent hosts must use the same VLAN from the VLAN group as the first host. If a VLAN list is used, all hosts are subject to the conditions specified in the VLAN list.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_49342E3E32E94B5AB297053A53A8413A"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_49342E3E32E94B5AB297053A53A8413A" target="_blank"&gt;&lt;/A&gt;Only one voice VLAN assignment is supported on a multi-auth port .&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_A904538F21DE4917BCFC468DFE14CFA4"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_A904538F21DE4917BCFC468DFE14CFA4" target="_blank"&gt;&lt;/A&gt;After a VLAN is assigned to a host on the port, subsequent hosts must have matching VLAN information or be denied access to the port.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_D6DC0F2509E640BD8204A99684F7FBE0"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_D6DC0F2509E640BD8204A99684F7FBE0" target="_blank"&gt;&lt;/A&gt;You cannot configure a guest VLAN or an auth-fail VLAN in multi-auth mode.&lt;/LI&gt;
&lt;LI id="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_9390D2E368EC41A79DA869C5B359F4ED"&gt;&lt;A name="GUID-BD33C234-399A-46B5-9BB0-64A8D533A245__LI_9390D2E368EC41A79DA869C5B359F4ED" target="_blank"&gt;&lt;/A&gt;The behavior of the critical-auth VLAN is not changed for multi-auth mode. When a host tries to authenticate and the server is not reachable, all authorized hosts are reinitialized in the configured VLAN.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 Nov 2018 13:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multi-auth-or-multi-host/m-p/3753519#M487985</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-11-27T13:26:01Z</dc:date>
    </item>
  </channel>
</rss>

