cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4484
Views
0
Helpful
5
Replies

Configuring Multi-auth host mode for IP Phones and APs / switches

SMD28316
Level 1
Level 1

Is it possible to authenticate APs / small switches and also Voice on the same port as clients?

 

as far as I know:

* APs and switches : authentication host-mode multi-host

* IP Phone + PC on the same port: authentication host-mode multi-auth.

 

Is it possible to have the same configuration on all ports? Can I use multi-auth to authenticate the phones and the APs / switches as well?

1 Accepted Solution

Accepted Solutions

thomas
Cisco Employee
Cisco Employee

Yes. That is the goal for consistency and we call that the universal switchport configuration.

Please read the ISE Secure Wired Access Prescriptive Deployment Guide which has our best practice configurations to handle all types of endpoints. Always use Multi-Auth.

Host Modes.png

View solution in original post

5 Replies 5

Hi 

yes you can since APs will use MAB as authentication method and DATA as a domain, using authentication host-mode multi-auth. will allow only one voice domain and multiple data domain.

 

 

So I can apply a port template that has "authentication host-mode multi-auth" for both AP / Switches ports and for ports connected to IP Phones?

 

What if the port is configured as trunk? what will be the affect?

yes you can use "authentication host-mode multi-auth", I don't recommend to apply dot1x configuration on trunk port 

 

 

SMD28316
Level 1
Level 1

Is it possible to authenticate APs / small switches and also Voice on the same port as clients?

 

as far as I know:

* APs and switches : authentication host-mode multi-host

* IP Phone + PC on the same port: authentication host-mode multi-auth.

 

Is it possible to have the same configuration on all ports? Can I use multi-auth to authenticate the phones and the APs / switches as well?

thomas
Cisco Employee
Cisco Employee

Yes. That is the goal for consistency and we call that the universal switchport configuration.

Please read the ISE Secure Wired Access Prescriptive Deployment Guide which has our best practice configurations to handle all types of endpoints. Always use Multi-Auth.

Host Modes.png