<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi-Auth on 2960x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3219377#M551261</link>
    <description>&lt;P&gt;Then is multi-host the option that you are looking for? It will allow multiple mac address on the same port to be authenticated.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2017 11:12:49 GMT</pubDate>
    <dc:creator>chrisgray1</dc:creator>
    <dc:date>2017-11-20T11:12:49Z</dc:date>
    <item>
      <title>Multi-Auth on 2960x</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3218738#M551260</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try to configure a 2960x for mac authentication with Radius. For now I need only MAC authentication, no voice vlan, no different vlan´s. I just want to restrict access to the network to predefined MAC addresses.&lt;/P&gt;
&lt;P&gt;In single host mode it works well... I see my client authenticated by Radius. But I´ll neet multi-auth on some ports but the option is not available, only multi-domain, multi-host and single-host:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;xxx(config-if)#authentication host-mode ?&lt;BR /&gt;&amp;nbsp; multi-domain&amp;nbsp; Multiple Domain Mode&lt;BR /&gt;&amp;nbsp; multi-host&amp;nbsp;&amp;nbsp;&amp;nbsp; Multiple Host Mode&lt;BR /&gt;&amp;nbsp; single-host&amp;nbsp;&amp;nbsp; SINGLE HOST Mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is what I did so far:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conf t&lt;BR /&gt;&amp;nbsp;aaa new-model&lt;BR /&gt;&amp;nbsp;aaa authentication dot1x default group radius&lt;BR /&gt;&amp;nbsp;aaa authorization network default group radius (optional)&lt;BR /&gt;&amp;nbsp;dot1x system-auth-control&lt;BR /&gt;&amp;nbsp;radius server radius&lt;BR /&gt;&amp;nbsp;address ipv4 xx.xx.xx.xx auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;timeout 2&lt;BR /&gt;&amp;nbsp;retransmit 1&lt;BR /&gt;&amp;nbsp;key *****&lt;BR /&gt;&amp;nbsp;aaa session-id common&lt;BR /&gt;&amp;nbsp;authentication mac-move permit&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;conf terminal&lt;BR /&gt;&amp;nbsp;interface Gi0/11&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport access vlan 1&lt;BR /&gt;&amp;nbsp;dot1x port-control auto&lt;BR /&gt;&amp;nbsp;authentication order mab&lt;BR /&gt;&amp;nbsp;authentication priority mab&lt;BR /&gt;&amp;nbsp;mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ivo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3218738#M551260</guid>
      <dc:creator>Ivo Kessler</dc:creator>
      <dc:date>2020-02-21T18:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Auth on 2960x</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3219377#M551261</link>
      <description>&lt;P&gt;Then is multi-host the option that you are looking for? It will allow multiple mac address on the same port to be authenticated.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 11:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3219377#M551261</guid>
      <dc:creator>chrisgray1</dc:creator>
      <dc:date>2017-11-20T11:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Auth on 2960x</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3219476#M551262</link>
      <description>&lt;P&gt;Multi-host will only authenticate the first MAC address that appears on the port and let all others through without authenticating them though.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/447063"&gt;@Ivo Kessler&lt;/a&gt;&amp;nbsp;what IOS version are you running?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 15:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-auth-on-2960x/m-p/3219476#M551262</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-11-20T15:03:51Z</dc:date>
    </item>
  </channel>
</rss>

