Multihost Mode

When you must include hubs in your network topology, multihost mode is available as an option. In general, multihost mode does not change the default operation for 802.1X, and it is available on all Catalyst switches. To enable multihost mode on a switch running Cisco IOS software, enter the following command:

dotlx host-mode multi-host

The main difference between single-auth mode and multihost mode is that after a MAC address is authenticated and authorized, any number of MAC addresses behind a hub can access the network. As a result, when using multihost mode alone, there is no way to restrict the number of MAC addresses on a port. The port is open for access by any connected host after the port is authorized using 802.1X. In effect, multihost mode uses 802.1X to authenticate a single port and then authorizes access to any other hosts that might be connected to the port through a hub.

For switches that support 802.1X along with port security, however, a port can be authenticated using 802.1X, and then access can be restricted to specific hosts using port security. After the initial 802.1X authentication, you can use port security to restrict access to specific addresses instead of allowing unrestricted access. When using port security, all subsequent non-EAPOL frames are redirected to the port security process, and 802.1X has no further effect. If the original MAC address that was authenticated through 802.1X terminates service directly through the use of an EAPOL-Logoff frame, the port disconnects from the network, and the network becomes inaccessible to any hosts connected through the port. With multihost mode, you can use 802.1X authentication for a specific port and then use port security on the port to take advantage of features such as aging, shutdown time, violation mode, and the number of MAC addresses allowed.

In general, hubs present challenges in any port-based access-control solution or network topology. Carefully consider the implications of using hubs; their use is not typically recommended for an IBNS solution. If a hub-type topology persists, 802.1X cannot keep adjacent systems connected to hubs from seeing all traffic in all connected devices, and the systems might exploit any number of Layer 2 vulnerabilities. However, if you determine that hubs are necessary in specific situations, such as in conference rooms, use multihost mode with port security. Multihost mode with port security provides the best security possible under the circumstances. This combination of security features helps you achieve the goal of network security, which is to provide the minimum network access that meets the network's functional requirements.

Continue reading here: Working with Devices Incapable of 8021X

Was this article helpful?

+2 0