<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About Multi-User Authentication on the DFE in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/about-multi-user-authentication-on-the-dfe/m-p/51536#M724</link>
    <description>Article ID: 5468 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
DFE&lt;BR /&gt;
N-EOS-PPC&lt;BR /&gt;
N-EOS-PUC &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Authentication&lt;BR /&gt;
MUA&lt;BR /&gt;
802.1x&lt;BR /&gt;
MAC Authentication&lt;BR /&gt;
PWA &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Multi-User Authentication (MUA) is the ability to permit multiple users &lt;I&gt;per port&lt;/I&gt; to authenticate using any combination of 802.1x / MAC / PWA+ authentication. This might be required in networks having Access switches which are not authentication-capable. The DFE, both Platinum and Gold series, has had a MUA capability (with differing limitations) since the release of 4.00.50 firmware in April 2004. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; What are the present (f/w 4.x) &lt;B&gt;hard limits for Authenticated Stations&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
Platinum: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A maximum of eight authenticated users (802.1x, MAC, PWA+) per fixed copper front panel port for Access modules: 2G4072-52, 7H4382-25, 7H4382-49, 7H4383-49, 7H4202-72, 7H4203-72, 7G4282-41, and 7G4202-60 
&lt;/LI&gt;&lt;LI&gt;A maximum of 128 authenticated users (802.1x, MAC, PWA+) per fiber and modular (Mini-GBIC) front panel port for Uplink modules: 7G-6MGBIC, 7G4270-12, 7G4202-30, 7H4284-49, and 7K4290-02 
&lt;/LI&gt;&lt;LI&gt;A maximum of 128 authenticated users (802.1x, MAC, PWA+) per Backplane or LAG port for any DFE module type 
&lt;/LI&gt;&lt;LI&gt;A maximum of &lt;U&gt;one&lt;/U&gt; 802.1x authenticated user per port 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 authenticated users per module 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 authenticated users per chassis&lt;/LI&gt;&lt;/UL&gt;
Gold: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A maximum of one user and one IP phone per port 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 users (including IP phones) per chassis&lt;/LI&gt;&lt;/UL&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Can the &lt;B&gt;hard limits be increased?&lt;/B&gt; &lt;BR /&gt;
&lt;BR /&gt;
Yes, for the Platinum series &lt;I&gt;only&lt;/I&gt;. Firmware 5.01.58 and higher has the capablity of High-Capacity licensing, expanding the user/port/system density for both Access and Uplink Module front-panel ports. LAG and Backplane ports retain their user density limit of 128. This is all summarized in the table below.&lt;BR /&gt;
&lt;BR /&gt;
                    standard   w/ N-EOS-PPC   w/ N-EOS-PUC*&lt;BR /&gt;
                     offering   (per module)   (per chassis)&lt;BR /&gt;
                     4.x, 5.x     f/w 5.x        f/w 5.x&lt;BR /&gt;
                &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on Access Modules      8           256             8&lt;BR /&gt;
                                   1024 (f/w 5.41.25+)&lt;BR /&gt;
  &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on Uplink Modules     128          256            128&lt;BR /&gt;
                                   1024 (f/w 5.41.25+)&lt;BR /&gt;
 &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on LAG/Backplane      128          128            128&lt;BR /&gt;
 &lt;BR /&gt;
 Users per module    module        1024          module&lt;BR /&gt;
                    dependent                  dependent&lt;BR /&gt;
 &lt;BR /&gt;
 Users per system     1024         1024           2048&lt;BR /&gt;
* Supported in the 2G4072-52, or for 7C111-installed systems, only with firmware 6.01.01.0020 and higher. &lt;BR /&gt;
&lt;BR /&gt;
A further, very significant change with 5.x is that the "single 802.1x user per port" restriction is removed, for the Platinum series &lt;I&gt;only&lt;/I&gt;. Limitations fall within the bounds of current multi-user authentication limits and capacities and those of the expected High-capacity licensing. In other words, 802.1x capability now expands to what is already stated for MAC and PWA limitations. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; What are the present (f/w 4.x) &lt;B&gt;soft limits for Authenticated Stations&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
A maximum of 65535 rules (VLAN + Priority) per chassis (57344 rules reserved for standard rules, 8191 rules reserved for policy profile assignment [admin-pid] rules)&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Standard rules (L2/L3/L4, IP+Socket, ICMP Type+Code) are designed to assign a VLAN or a CoS (Class of Service) to the traffic they match. 
&lt;/LI&gt;&lt;LI&gt;Admin-pid rules (L2/L3/L4, IP+Socket, ICMP Type+Code) are designed to assign a Policy (Profile) to the traffic they match and are used by the VLAN-to-Policy Mapping feature, by the dynamic agents (after authentication returns a result) and to assign a default policy to a port (on the Gold series). 
&lt;/LI&gt;&lt;LI&gt;Both standard and admin-pid rules can syslog, trap or disable the port when hit, even if they aren’t assigning VLAN, CoS or Policy (Profile), using the Rule Hit/Accounting feature .&lt;/LI&gt;&lt;/UL&gt;
A maximum of 1023 roles per chassis&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Are the &lt;B&gt;soft limits expected to change?&lt;/B&gt; &lt;BR /&gt;
&lt;BR /&gt;
No. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; How do I &lt;B&gt;install the licenses&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
To install the N-EOS-PPC:&lt;BR /&gt;
set license port-capacity &amp;lt;&lt;I&gt;license_key&lt;/I&gt;&amp;gt; slot &amp;lt;&lt;I&gt;slot#&lt;/I&gt;&amp;gt; &lt;BR /&gt;
To install the N-EOS-PUC:&lt;BR /&gt;
set license user-capacity &amp;lt;&lt;I&gt;license_key&lt;/I&gt;&amp;gt; &lt;BR /&gt;
&lt;BR /&gt;
The system must be rebooted after issuing these commands, in order for the license(s) to be applied. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Are there any &lt;B&gt;configuration guides&lt;/B&gt; available?&lt;BR /&gt;
&lt;BR /&gt;
The best configuration resource available at this time is the &lt;A href="https://extranet.enterasys.com/Downloads/Pages/Platinum.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;DFE Configuration Guide&lt;/A&gt;. There is significant effort underway to expand upon this, concentrating on sample configurations.</description>
    <pubDate>Wed, 06 Nov 2013 21:50:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-11-06T21:50:00Z</dc:date>
    <item>
      <title>About Multi-User Authentication on the DFE</title>
      <link>https://community.extremenetworks.com/t5/faqs/about-multi-user-authentication-on-the-dfe/m-p/51536#M724</link>
      <description>Article ID: 5468 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
DFE&lt;BR /&gt;
N-EOS-PPC&lt;BR /&gt;
N-EOS-PUC &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
Authentication&lt;BR /&gt;
MUA&lt;BR /&gt;
802.1x&lt;BR /&gt;
MAC Authentication&lt;BR /&gt;
PWA &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
Multi-User Authentication (MUA) is the ability to permit multiple users &lt;I&gt;per port&lt;/I&gt; to authenticate using any combination of 802.1x / MAC / PWA+ authentication. This might be required in networks having Access switches which are not authentication-capable. The DFE, both Platinum and Gold series, has had a MUA capability (with differing limitations) since the release of 4.00.50 firmware in April 2004. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; What are the present (f/w 4.x) &lt;B&gt;hard limits for Authenticated Stations&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
Platinum: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A maximum of eight authenticated users (802.1x, MAC, PWA+) per fixed copper front panel port for Access modules: 2G4072-52, 7H4382-25, 7H4382-49, 7H4383-49, 7H4202-72, 7H4203-72, 7G4282-41, and 7G4202-60 
&lt;/LI&gt;&lt;LI&gt;A maximum of 128 authenticated users (802.1x, MAC, PWA+) per fiber and modular (Mini-GBIC) front panel port for Uplink modules: 7G-6MGBIC, 7G4270-12, 7G4202-30, 7H4284-49, and 7K4290-02 
&lt;/LI&gt;&lt;LI&gt;A maximum of 128 authenticated users (802.1x, MAC, PWA+) per Backplane or LAG port for any DFE module type 
&lt;/LI&gt;&lt;LI&gt;A maximum of &lt;U&gt;one&lt;/U&gt; 802.1x authenticated user per port 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 authenticated users per module 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 authenticated users per chassis&lt;/LI&gt;&lt;/UL&gt;
Gold: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;A maximum of one user and one IP phone per port 
&lt;/LI&gt;&lt;LI&gt;A maximum of 1024 users (including IP phones) per chassis&lt;/LI&gt;&lt;/UL&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Can the &lt;B&gt;hard limits be increased?&lt;/B&gt; &lt;BR /&gt;
&lt;BR /&gt;
Yes, for the Platinum series &lt;I&gt;only&lt;/I&gt;. Firmware 5.01.58 and higher has the capablity of High-Capacity licensing, expanding the user/port/system density for both Access and Uplink Module front-panel ports. LAG and Backplane ports retain their user density limit of 128. This is all summarized in the table below.&lt;BR /&gt;
&lt;BR /&gt;
                    standard   w/ N-EOS-PPC   w/ N-EOS-PUC*&lt;BR /&gt;
                     offering   (per module)   (per chassis)&lt;BR /&gt;
                     4.x, 5.x     f/w 5.x        f/w 5.x&lt;BR /&gt;
                &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on Access Modules      8           256             8&lt;BR /&gt;
                                   1024 (f/w 5.41.25+)&lt;BR /&gt;
  &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on Uplink Modules     128          256            128&lt;BR /&gt;
                                   1024 (f/w 5.41.25+)&lt;BR /&gt;
 &lt;BR /&gt;
 Users per Port&lt;BR /&gt;
 on LAG/Backplane      128          128            128&lt;BR /&gt;
 &lt;BR /&gt;
 Users per module    module        1024          module&lt;BR /&gt;
                    dependent                  dependent&lt;BR /&gt;
 &lt;BR /&gt;
 Users per system     1024         1024           2048&lt;BR /&gt;
* Supported in the 2G4072-52, or for 7C111-installed systems, only with firmware 6.01.01.0020 and higher. &lt;BR /&gt;
&lt;BR /&gt;
A further, very significant change with 5.x is that the "single 802.1x user per port" restriction is removed, for the Platinum series &lt;I&gt;only&lt;/I&gt;. Limitations fall within the bounds of current multi-user authentication limits and capacities and those of the expected High-capacity licensing. In other words, 802.1x capability now expands to what is already stated for MAC and PWA limitations. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; What are the present (f/w 4.x) &lt;B&gt;soft limits for Authenticated Stations&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
A maximum of 65535 rules (VLAN + Priority) per chassis (57344 rules reserved for standard rules, 8191 rules reserved for policy profile assignment [admin-pid] rules)&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Standard rules (L2/L3/L4, IP+Socket, ICMP Type+Code) are designed to assign a VLAN or a CoS (Class of Service) to the traffic they match. 
&lt;/LI&gt;&lt;LI&gt;Admin-pid rules (L2/L3/L4, IP+Socket, ICMP Type+Code) are designed to assign a Policy (Profile) to the traffic they match and are used by the VLAN-to-Policy Mapping feature, by the dynamic agents (after authentication returns a result) and to assign a default policy to a port (on the Gold series). 
&lt;/LI&gt;&lt;LI&gt;Both standard and admin-pid rules can syslog, trap or disable the port when hit, even if they aren’t assigning VLAN, CoS or Policy (Profile), using the Rule Hit/Accounting feature .&lt;/LI&gt;&lt;/UL&gt;
A maximum of 1023 roles per chassis&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Are the &lt;B&gt;soft limits expected to change?&lt;/B&gt; &lt;BR /&gt;
&lt;BR /&gt;
No. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; How do I &lt;B&gt;install the licenses&lt;/B&gt;? &lt;BR /&gt;
&lt;BR /&gt;
To install the N-EOS-PPC:&lt;BR /&gt;
set license port-capacity &amp;lt;&lt;I&gt;license_key&lt;/I&gt;&amp;gt; slot &amp;lt;&lt;I&gt;slot#&lt;/I&gt;&amp;gt; &lt;BR /&gt;
To install the N-EOS-PUC:&lt;BR /&gt;
set license user-capacity &amp;lt;&lt;I&gt;license_key&lt;/I&gt;&amp;gt; &lt;BR /&gt;
&lt;BR /&gt;
The system must be rebooted after issuing these commands, in order for the license(s) to be applied. &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;&amp;gt;&lt;/B&gt; Are there any &lt;B&gt;configuration guides&lt;/B&gt; available?&lt;BR /&gt;
&lt;BR /&gt;
The best configuration resource available at this time is the &lt;A href="https://extranet.enterasys.com/Downloads/Pages/Platinum.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;DFE Configuration Guide&lt;/A&gt;. There is significant effort underway to expand upon this, concentrating on sample configurations.</description>
      <pubDate>Wed, 06 Nov 2013 21:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/about-multi-user-authentication-on-the-dfe/m-p/51536#M724</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-11-06T21:50:00Z</dc:date>
    </item>
  </channel>
</rss>

