Information About Multiple Authentications for a Client
Multiple Authentication feature is an extension of Layer 2 and Layer 3 security types supported for client join.
![]() Note |
You can enable both L2 and L3 authentication for a given SSID. |
![]() Note |
The Multiple Authentication feature is applicable for regular clients only. |
Information About Supported Combination of Authentications for a Client
The Multiple Authentications for a Client feature supports multiple combination of authentications for a given client configured in the WLAN profile.
The following table outlines the supported combination of authentications:
Layer 2 |
Layer 3 |
Supported |
MAB |
CWA |
Yes |
MAB Failure |
LWA |
Yes |
802.1X |
CWA |
Yes |
PSK |
CWA |
Yes |
iPSK + MAB |
CWA |
Yes |
iPSK |
LWA |
No |
MAB Failure + PSK |
LWA |
No |
MAB Failure + PSK |
CWA |
No |
From 16.10.1 onwards, 802.1X configurations on WLAN support web authentication configurations with WPA or WPA2 configuration.
The feature also supports the following AP modes:
-
Local
-
FlexConnect
-
Fabric
![]() Note |
For MAB authentication in APs in local mode, maintain a latency below 100 ms between the controller, acting as the Network Access Server (NAS), and the AAA server. This helps avoid timeouts when waiting for the AP's association response as the AP responds only after receiving feedback from the AAA server, emphasizing the importance of latency. This recommendation does not apply to FlexConnect, where the AP responds immediately to client association requests. Deploy APs in FlexConnect mode if lower latency to AAA servers cannot be guaranteed. |