

For more information, see theĬonfiguration Guide for CISCO Secure ACS. The switch must have a RADIUS configuration and be connected to the Cisco secure access control server (ACS). For more information, see the documentation for your Cisco platform and theĬisco IOS Security Configuration Guide: Securing User Services. You should understand the concepts of the RADIUS protocol and have an understanding of how to create and apply access control lists (ACLs). The web authentication method is not supported on Cisco integrated services routers (ISRs) or Integrated Services Routers Generation 2 (ISR G2s) in Cisco IOS Release 15.2(2)T. If the authentication order includes web authentication, configure a fallback profile that enables web authentication on the switch and the interface. If the authentication order includes the 802.1X port authentication method, you must enable IEEE 802.1X authentication on the switch.

If appropriate, you must enable ACL download. The switch must be connected to a Cisco secure Access Control System (ACS) and RADIUS authentication, authorization, and accounting (AAA) must be configured for Web authentication. For more information, see theĬonfiguring IEEE 802.1X Port-Based Authentication module. You should understand the concepts of port-based network access control and have an understanding of how to configure port-based network access control on your Cisco platform. Prerequisites for IEEE 802.1X Multidomain Authentication IEEE 802.1X Port-Based Network Access Control Navigator to find information about platform support and Cisco software image Which each feature is supported, see the feature information table. The features documented in this module, and to see a list of the releases in Release notes for your platform and software release.

May not support all the features documented in this module.

Configuration Examples for IEEE 802.1X Multidomain Authentication.How to Configure IEEE 802.1X Multidomain Authentication.Information About IEEE 802.1X Multidomain Authentication.Restrictions for IEEE 802.1X Multidomain Authentication.Prerequisites for IEEE 802.1X Multidomain Authentication.Multidomain authentication (MDA) allows both a data device and voice device, such as an IP phone (Cisco or non-Cisco), to authenticate on the same switch port.
