Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?





Hierarchy Level

Release Information

Statement introduced in Junos OS Release 9.0 for EX Series switches.

Statement added to the [edit services captive-portal interface] hierarchy in Junos OS Release 10.1 for EX Series switches

Statement introduced in Junos OS Release 14.1X53-D30 for the QFX Series.


Configure the MAC-based method used to authenticate clients for 802.1X or captive portal authentication.




single—Authenticates only the first client that connects to an authenticator port. All other clients connecting to the authenticator port after the first are permitted free access to the port without further authentication. If the first authenticated client logs out, all other supplicants are locked out until a client authenticates again.

single-secure—Authenticates only one client to connect to an authenticator port. The host must be directly connected to the switch.

multiple—Authenticates multiple clients individually on one authenticator port. You can configure the number of clients per port. If you also configure a maximum number of devices that can be connected to a port through port security settings, the lower of the configured values is used to determine the maximum number of clients allowed per port.

Required Privilege Level

routing—To view this statement in the configuration.

routing-control—To add this statement to the configuration.