Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dostap
New Contributor

802.1X-mac-based authentification for multiple device per port

I need to do next configuration for two 802.1x devices per single fortiswitch port:

 - ipphone with EAP-MD5 802.1x authentification;

 - PC behind the phone with EAP-TLS certificate based authentification.

As I understand I need configure 802.1X-mac-based authentification on port for this scheme. Shoud it works without keeping all devices mac-address database on RADIUS server?  

Thanks.

1 Solution
pminarik
Staff
Staff

The mac-based vs port-based authorization is a distinction between whether each and every unique MAC address needs to perform 802.1x authentication separately to gain access (mac-based) when connected to this same switch-port, or whether a single device authenticating will authorize the entire switch-port for access, allowing devices with other MAC address to pass traffic through the switch-port. (port-based).

 

MAC-authentication bypass (MAB) is a separate concept, available for both modes, optional.

[ corrections always welcome ]

View solution in original post

2 REPLIES 2
pminarik
Staff
Staff

The mac-based vs port-based authorization is a distinction between whether each and every unique MAC address needs to perform 802.1x authentication separately to gain access (mac-based) when connected to this same switch-port, or whether a single device authenticating will authorize the entire switch-port for access, allowing devices with other MAC address to pass traffic through the switch-port. (port-based).

 

MAC-authentication bypass (MAB) is a separate concept, available for both modes, optional.

[ corrections always welcome ]
dostap

Thanks a lot. Now it's clear for me.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors