- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2021 05:36 AM
Is it possible to authenticate APs / small switches and also Voice on the same port as clients?
as far as I know:
* APs and switches : authentication host-mode multi-host
* IP Phone + PC on the same port: authentication host-mode multi-auth.
Is it possible to have the same configuration on all ports? Can I use multi-auth to authenticate the phones and the APs / switches as well?
Solved! Go to Solution.
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2021 06:32 PM
Yes. That is the goal for consistency and we call that the universal switchport configuration.
Please read the ISE Secure Wired Access Prescriptive Deployment Guide which has our best practice configurations to handle all types of endpoints. Always use Multi-Auth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2021 05:44 AM
Hi
yes you can since APs will use MAB as authentication method and DATA as a domain, using authentication host-mode multi-auth. will allow only one voice domain and multiple data domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2021 06:13 AM
So I can apply a port template that has "authentication host-mode multi-auth" for both AP / Switches ports and for ports connected to IP Phones?
What if the port is configured as trunk? what will be the affect?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2021 06:48 AM
yes you can use "authentication host-mode multi-auth", I don't recommend to apply dot1x configuration on trunk port
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2021 05:43 AM
Is it possible to authenticate APs / small switches and also Voice on the same port as clients?
as far as I know:
* APs and switches : authentication host-mode multi-host
* IP Phone + PC on the same port: authentication host-mode multi-auth.
Is it possible to have the same configuration on all ports? Can I use multi-auth to authenticate the phones and the APs / switches as well?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-06-2021 06:32 PM
Yes. That is the goal for consistency and we call that the universal switchport configuration.
Please read the ISE Secure Wired Access Prescriptive Deployment Guide which has our best practice configurations to handle all types of endpoints. Always use Multi-Auth.
