Configuring 802.1X With Vlan User Distribution - Cisco Catalyst 4500 Series Configuration Manual

Release ios xe 3.3.0sg and ios 15.1(1)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

Configuring 802.1X Port-Based Authentication

Configuring 802.1X with VLAN User Distribution

You will need to configure the switch and ACS to configure 802.1X with VLAN user distribution.
Configuring the Switch
To configure the switch, follow these steps:
Create a VLAN group on the switch.
Step 1
Enter the following commands to create a VLAN group and assign some VLANs to the VLAN group.
The following example creates the VLAN group eng-group and maps VLANs 20 to 24 to that group:
Switch# configure terminal
Switch(config)# vlan group eng-group vlan-list 20-24
Switch(config)# end
Switch# show vlan group group-name eng-group
Group Name VLANs Mapped
---------------- -------------------
eng-group
Ensure that the VLANs you specify as part of the VLAN group are enabled on the switch. Only specified
Note
VLANs are considered for assignment.
Step 2
Configure the individual ports for multidomain, single-host or multiple- host.
For details, refer to the
show commands
Use the following show commands to display the member VLANs in a VLAN group:
show command
show vlan group all
show vlan group group-name vlan-group-name
show vlan group group-name vlan-group-name
user-count
The following examples show outputs of the show vlan group command:
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
44-66
20-24
"Enabling 802.1X Authentication" section on page
Chapter 44
Configuring 802.1X Port-Based Authentication
44-28.
Purpose
Displays the member VLANs for all the VLAN
groups configured on the device.
Displays the member VLANs in a VLAN group
with the given VLAN group name.
Displays the user count for each of the member
VLANs of the specified VLAN group
This feature counts only authenticated users and
MAC addresses added through port security for
distribution. It does not consider other learned
MAC addresses. As of Cisco IOS Release
12.2(54)SG, the user count for a VLAN is
incremented when a host is learned through port
security, 802.1X, MAB, or fallback authentication
on that VLAN.
OL-25340-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents