<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SecureStack/D/G/I-Series Defaults regarding Multiauth Mode: Multi or Strict in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/securestack-d-g-i-series-defaults-regarding-multiauth-mode-multi/m-p/49023#M567</link>
    <description>Article ID: 12499&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
SecureStack C3, C2, B3, B2, A2&lt;BR /&gt;
G-Series&lt;BR /&gt;
D-Series&lt;BR /&gt;
I-Series &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Changes&lt;/B&gt;&lt;BR /&gt;
With default multiauth configurations (no commands visible from a 'show config multiauth'), issued a 'show multiauth' query on multiple devices. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
No apparent reason why some devices default to "System mode : multi" and some default to "System mode : strict". &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
When policy commands are supported - whether used or not - then multiauth mode defaults to "multi". Otherwise, it defaults to "strict". &lt;BR /&gt;
&lt;BR /&gt;
As a result:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;The C3, C2, G-Series, and I-Series, which support policy with no need for licensing, always default to "multi". 
&lt;/LI&gt;&lt;LI&gt;The A2, which has no policy support, always defaults to "strict". 
&lt;/LI&gt;&lt;LI&gt;The B3, B2, and D-Series, which support policy upon application of a policy license (&lt;A href="http://bit.ly/1uuPHCH" target="_blank" rel="nofollow noreferrer noopener"&gt;10833&lt;/A&gt;), default to "strict" when unlicensed and to "multi" when licensed.&lt;/LI&gt;&lt;/UL&gt;
This is demonstrated below, for the D-Series. Note that upon application of a policy license (&lt;A href="http://bit.ly/1bQrXRb" target="_blank" rel="nofollow noreferrer noopener"&gt;10791&lt;/A&gt;), the system attempts to retain the existing multiauth mode by insertion of an explicit 'set multiauth mode strict' command in the configuration. Similarly, upon removal of a policy license, the system inserts a 'set multiauth mode multi' command. In either case, removal of that 'set multiauth mode...' command yields the described default behavior.&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;show multiauth&lt;BR /&gt;
 &lt;BR /&gt;
Multiple authentication system configuration&lt;BR /&gt;
-------------------------------------------------&lt;BR /&gt;
Supported types               : dot1x, mac&lt;BR /&gt;
Maximum number of users       : 36&lt;BR /&gt;
Current number of users       : 0&lt;BR /&gt;
System mode                   : strict&lt;BR /&gt;
Default precedence            : dot1x, mac&lt;BR /&gt;
Admin precedence&lt;BR /&gt;
Operational precedence        : dot1x, mac&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;set license D2Policy&lt;BR /&gt;
 &lt;BR /&gt;
Terms of this license may be found at&lt;BR /&gt;
 &lt;BR /&gt;
http://www.enterasys.com/support/fla.aspx&lt;BR /&gt;
 &lt;BR /&gt;
Do you accept the terms of the applicable policy license (y/n) &lt;N&gt;?y&lt;BR /&gt;
License successfully enabled&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
set multiauth mode strict&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;set multiauth mode multi&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;show multiauth&lt;BR /&gt;
 &lt;BR /&gt;
Multiple authentication system configuration&lt;BR /&gt;
-------------------------------------------------&lt;BR /&gt;
Supported types               : dot1x, pwa, mac&lt;BR /&gt;
Maximum number of users       : 36&lt;BR /&gt;
Current number of users       : 0&lt;BR /&gt;
System mode                   : multi&lt;BR /&gt;
Default precedence            : dot1x, pwa, mac&lt;BR /&gt;
Admin precedence&lt;BR /&gt;
Operational precedence        : dot1x, pwa, mac&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Functions as Designed (FAD). &lt;BR /&gt;
&lt;BR /&gt;
Be aware of the "multiauthentication mode" guidelines as described above. &lt;BR /&gt;
See also: &lt;A href="http://bit.ly/1qD0tGH" target="_blank" rel="nofollow noreferrer noopener"&gt;10283&lt;/A&gt; and &lt;A href="http://bit.ly/19HVA21" target="_blank" rel="nofollow noreferrer noopener"&gt;11246&lt;/A&gt;.&lt;/N&gt;</description>
    <pubDate>Thu, 21 Nov 2013 04:19:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-21T04:19:00Z</dc:date>
    <item>
      <title>SecureStack/D/G/I-Series Defaults regarding Multiauth Mode: Multi or Strict</title>
      <link>https://community.extremenetworks.com/t5/faqs/securestack-d-g-i-series-defaults-regarding-multiauth-mode-multi/m-p/49023#M567</link>
      <description>Article ID: 12499&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
SecureStack C3, C2, B3, B2, A2&lt;BR /&gt;
G-Series&lt;BR /&gt;
D-Series&lt;BR /&gt;
I-Series &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Changes&lt;/B&gt;&lt;BR /&gt;
With default multiauth configurations (no commands visible from a 'show config multiauth'), issued a 'show multiauth' query on multiple devices. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
No apparent reason why some devices default to "System mode : multi" and some default to "System mode : strict". &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
When policy commands are supported - whether used or not - then multiauth mode defaults to "multi". Otherwise, it defaults to "strict". &lt;BR /&gt;
&lt;BR /&gt;
As a result:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;The C3, C2, G-Series, and I-Series, which support policy with no need for licensing, always default to "multi". 
&lt;/LI&gt;&lt;LI&gt;The A2, which has no policy support, always defaults to "strict". 
&lt;/LI&gt;&lt;LI&gt;The B3, B2, and D-Series, which support policy upon application of a policy license (&lt;A href="http://bit.ly/1uuPHCH" target="_blank" rel="nofollow noreferrer noopener"&gt;10833&lt;/A&gt;), default to "strict" when unlicensed and to "multi" when licensed.&lt;/LI&gt;&lt;/UL&gt;
This is demonstrated below, for the D-Series. Note that upon application of a policy license (&lt;A href="http://bit.ly/1bQrXRb" target="_blank" rel="nofollow noreferrer noopener"&gt;10791&lt;/A&gt;), the system attempts to retain the existing multiauth mode by insertion of an explicit 'set multiauth mode strict' command in the configuration. Similarly, upon removal of a policy license, the system inserts a 'set multiauth mode multi' command. In either case, removal of that 'set multiauth mode...' command yields the described default behavior.&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;show multiauth&lt;BR /&gt;
 &lt;BR /&gt;
Multiple authentication system configuration&lt;BR /&gt;
-------------------------------------------------&lt;BR /&gt;
Supported types               : dot1x, mac&lt;BR /&gt;
Maximum number of users       : 36&lt;BR /&gt;
Current number of users       : 0&lt;BR /&gt;
System mode                   : strict&lt;BR /&gt;
Default precedence            : dot1x, mac&lt;BR /&gt;
Admin precedence&lt;BR /&gt;
Operational precedence        : dot1x, mac&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;set license D2Policy&lt;BR /&gt;
 &lt;BR /&gt;
Terms of this license may be found at&lt;BR /&gt;
 &lt;BR /&gt;
http://www.enterasys.com/support/fla.aspx&lt;BR /&gt;
 &lt;BR /&gt;
Do you accept the terms of the applicable policy license (y/n) &lt;N&gt;?y&lt;BR /&gt;
License successfully enabled&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
set multiauth mode strict&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;set multiauth mode multi&lt;BR /&gt;
D2(su)-&amp;gt;show config multiauth&lt;BR /&gt;
 &lt;BR /&gt;
#multiauth&lt;BR /&gt;
!&lt;BR /&gt;
end&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;show multiauth&lt;BR /&gt;
 &lt;BR /&gt;
Multiple authentication system configuration&lt;BR /&gt;
-------------------------------------------------&lt;BR /&gt;
Supported types               : dot1x, pwa, mac&lt;BR /&gt;
Maximum number of users       : 36&lt;BR /&gt;
Current number of users       : 0&lt;BR /&gt;
System mode                   : multi&lt;BR /&gt;
Default precedence            : dot1x, pwa, mac&lt;BR /&gt;
Admin precedence&lt;BR /&gt;
Operational precedence        : dot1x, pwa, mac&lt;BR /&gt;
 &lt;BR /&gt;
D2(su)-&amp;gt;&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Functions as Designed (FAD). &lt;BR /&gt;
&lt;BR /&gt;
Be aware of the "multiauthentication mode" guidelines as described above. &lt;BR /&gt;
See also: &lt;A href="http://bit.ly/1qD0tGH" target="_blank" rel="nofollow noreferrer noopener"&gt;10283&lt;/A&gt; and &lt;A href="http://bit.ly/19HVA21" target="_blank" rel="nofollow noreferrer noopener"&gt;11246&lt;/A&gt;.&lt;/N&gt;</description>
      <pubDate>Thu, 21 Nov 2013 04:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/securestack-d-g-i-series-defaults-regarding-multiauth-mode-multi/m-p/49023#M567</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-21T04:19:00Z</dc:date>
    </item>
  </channel>
</rss>

