Describes 802.1X host modes, which determine how many endpoints can use a port and how the system authenticates each endpoint.
An 802.1X host mode defines the number and types of endpoints that can connect through an authenticated port.
Host mode behavior
Each host mode provides different authentication and access-control behavior.
|
Mode |
Authentication and access behavior |
Typical use |
|---|---|---|
|
Single-host |
Allows one endpoint on the port. After the endpoint is authenticated, the port is authorized. An additional MAC address causes a security violation and disables the interface. |
A host-to-switch topology in which one endpoint connects to a Layer 2 or Layer 3 switch port. |
|
Multi-host |
Allows multiple endpoints but authenticates only the first endpoint. After the first endpoint is authorized, all endpoints can access the network. If the port becomes unauthorized, all endpoints lose access. Security-violation shutdown is disabled. |
A host-to-switch or switch-to-switch topology. |
|
Multi-auth |
Allows multiple endpoints and authenticates each endpoint separately. All endpoints must use the same EPG and VLAN information. |
A port that requires separate authentication for multiple endpoints in the same data EPG and VLAN. |
|
Multidomain |
Provides separate data and voice domains on the same port. |
A topology that connects an IP phone and a data endpoint through the same port. |