Maximum Number Of Allowed Devices Per Port; Configuring 802.1X Readiness Check - Cisco Catalyst 2975 Software Configuration Manual

Ios release 12.2(55)se
Hide thumbs Also See for Catalyst 2975:
Table of Contents

Advertisement

Chapter 10
Configuring IEEE 802.1x Port-Based Authentication

Maximum Number of Allowed Devices Per Port

This is the maximum number of devices allowed on an 802.1x-enabled port:

Configuring 802.1x Readiness Check

The 802.1x readiness check monitors 802.1x activity on all the switch ports and displays information
about the devices connected to the ports that support 802.1x. You can use this feature to determine if the
devices connected to the switch ports are 802.1x-capable.
The 802.1x readiness check is allowed on all ports that can be configured for 802.1x. The readiness
check is not available on a port that is configured as dot1x force-unauthorized.
Follow these guidelines to enable the readiness check on the switch:
Beginning in privileged EXEC mode, follow these steps to enable the 802.1x readiness check on the
switch:
Command
Step 1
dot1x test eapol-capable [interface
interface-id]
Step 1
configure terminal
Step 2
dot1x test timeout timeout
OL-19720-02
In single-host mode, only one device is allowed on the access VLAN. If the port is also configured with
a voice VLAN, an unlimited number of Cisco IP phones can send and receive traffic through the voice
VLAN.
In multidomain authentication (MDA) mode, one device is allowed for the access VLAN, and one
IP phone is allowed for the voice VLAN.
In multiple-host mode, only one 802.1x supplicant is allowed on the port, but an unlimited number
of non-802.1x hosts are allowed on the access VLAN. An unlimited number of devices are allowed
on the voice VLAN.
The readiness check is typically used before 802.1x is enabled on the switch.
If you use the dot1x test eapol-capable privileged EXEC command without specifying an interface,
all the ports on the switch stack are tested.
When you configure the dot1x test eapol-capable command on an 802.1x-enabled port, and the link
comes up, the port queries the connected client about its 802.1x capability. When the client responds
with a notification packet, it is 802.1x-capable. A syslog message is generated if the client responds
within the timeout period. If the client does not respond to the query, the client is
not 802.1x-capable. No syslog message is generated.
The readiness check can be sent on a port that handles multiple hosts (for example, a PC that is
connected to an IP phone). A syslog message is generated for each of the clients that respond to the
readiness check within the timer period.
Purpose
Enable the 802.1x readiness check on the switch.
(Optional) For interface-id specify the port on which to check for 802.1x
readiness.
Note
(Optional) Enter global configuration mode.
(Optional) Configure the timeout used to wait for EAPOL response. The
range is from 1 to 65535 seconds. The default is 10 seconds.
If you omit the optional interface keyword, all interfaces on the
switch are tested.
Catalyst 2975 Switch Software Configuration Guide
Configuring 802.1x Authentication
10-37

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents