Administrator Guide

Figure 9. Multi-Host Authentication Mode
When you configure multi-host mode authentication, the first client to respond to an identity request is authenticated and subsequent
responses are still ignored. However, because the authenticator expects the possibility of multiple responses, no system log is generated.
After the first supplicant is authenticated, all end users connected to the authorized port are allowed to access the network.
If the authorized port becomes unauthorized due to re-authentication failure or the supplicant sends an EAPOL logoff frame, all connected
end users are denied access to the network.
If you change the host mode on a port that is already authenticated:
From single-host to multi-host — All devices connected to the port that were previously blocked may access the network; the
supplicant does not re-authenticate.
From multi-host to single-host — The port restarts the authentication process. The first end user to respond is authenticated and
allowed access.
Configuring Multi-Host Authentication
To enable multi-host authentication on a port, enter the dot1x host-mode multi-host command in Interface mode. To return to
the default single-host authentication mode, enter the no dot1x host-mode command. To verify the currently configured
authentication mode, enter the show dot1x interface command.
Dell(conf-if-te-2/1)# dot1x host-mode multi-host
Dell(conf-if-te-2/1)# do show dot1x interface tengigabitethernet 2/1
802.1x information on Te 2/1:
-----------------------------
Dot1x Status: Enable
Port Control: AUTO
Port Auth Status: UNAUTHORIZED
Re-Authentication: Disable
Untagged VLAN id: None
Guest VLAN: Disable
Guest VLAN id: NONE
Auth-Fail VLAN: Disable
96
802.1X