<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication host-mode multi-auth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4280173#M565040</link>
    <description>&lt;P&gt;See &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt; &amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-883346157" target="_self"&gt;MAC Limits&lt;/A&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This does not limit the number of endpoints from connecting or authenticating on the port. Use &lt;FONT face="courier new,courier"&gt;limit address-count &lt;EM&gt;maximum&lt;/EM&gt;&lt;/FONT&gt; CLI under the device-tracking policy to limit the number of endpoints allowed to use identity-based services.&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;c9300-Sw(config)#device-tracking policy IPDT_POLICY
c9300-Sw(config-device-tracking)#no protocol udp
c9300-Sw(config-device-tracking)#tracking enable
c9300-Sw(config-device-tracking)#&lt;STRONG&gt;limit address-count 10&lt;/STRONG&gt; &amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2021 23:52:05 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2021-01-26T23:52:05Z</dc:date>
    <item>
      <title>Authentication host-mode multi-auth</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4279962#M565024</link>
      <description>&lt;P&gt;if you configure AUTHENTICATION HOST-MODE MULTI-AUTH on your switch port allowing a single device in the voice domain and multiple devices on the data domain, is it possible to limit the number of devices on the data domain. For example, a single phone and 2 devices but not 3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 18:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4279962#M565024</guid>
      <dc:creator>Pete C</dc:creator>
      <dc:date>2021-01-26T18:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication host-mode multi-auth</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4280020#M565026</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/562198"&gt;@Pete C&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;please take a look at the following presentation: &lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2018/pdf/BRKSEC-3690.pdf" target="_blank" rel="noopener"&gt;Cisco Live BRKSEC-3690&lt;/A&gt;. (search for &lt;STRONG&gt;ip device tracking&lt;/STRONG&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 19:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4280020#M565026</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-01-26T19:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication host-mode multi-auth</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4280173#M565040</link>
      <description>&lt;P&gt;See &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt; &amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-883346157" target="_self"&gt;MAC Limits&lt;/A&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;This does not limit the number of endpoints from connecting or authenticating on the port. Use &lt;FONT face="courier new,courier"&gt;limit address-count &lt;EM&gt;maximum&lt;/EM&gt;&lt;/FONT&gt; CLI under the device-tracking policy to limit the number of endpoints allowed to use identity-based services.&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;c9300-Sw(config)#device-tracking policy IPDT_POLICY
c9300-Sw(config-device-tracking)#no protocol udp
c9300-Sw(config-device-tracking)#tracking enable
c9300-Sw(config-device-tracking)#&lt;STRONG&gt;limit address-count 10&lt;/STRONG&gt; &amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 23:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-host-mode-multi-auth/m-p/4280173#M565040</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-01-26T23:52:05Z</dc:date>
    </item>
  </channel>
</rss>

