Configuring Nac Layer 2 Ieee 802.1X Validation; Configuring Web Authentication - Cisco 3750G - Catalyst Integrated Wireless LAN Controller Configuration Manual

Software configuration guide
Hide thumbs Also See for 3750G - Catalyst Integrated Wireless LAN Controller:
Table of Contents

Advertisement

Chapter 10
Configuring IEEE 802.1x Port-Based Authentication

Configuring NAC Layer 2 IEEE 802.1x Validation

In Cisco IOS Release 12.2(25)SED or later, you can configure NAC Layer 2 IEEE 802.1x validation,
which is also referred to as IEEE 802.1x authentication with a RADIUS server.
Beginning in privileged EXEC mode, follow these steps to configure NAC Layer 2 IEEE 802.1x
validation. The procedure is optional.
Command
Step 1
configure terminal
Step 2
interface interface-id
Step 3
dot1x guest-vlan vlan-id
Step 4
dot1x reauthentication
Step 5
dot1x timeout reauth-period {seconds |
server}
Step 6
end
Step 7
show dot1x interface interface-id
Step 8
copy running-config startup-config
This example shows how to configure NAC Layer 2 IEEE 802.1x validation:
Switch# configure terminal
Switch(config)# interface gigabitethernet2/0/1
Switch(config-if)# dot1x reauthentication
Switch(config-if)# dot1x timeout reauth-period server

Configuring Web Authentication

Beginning in privileged EXEC mode, follow these steps to configure authentication, authorization,
accounting (AAA) and RADIUS on a switch before configuring web authentication. The steps enable
AAA by using RADIUS authentication and enable device tracking.
OL-8550-02
Purpose
Enter global configuration mode.
Specify the port to be configured, and enter interface configuration mode.
Specify an active VLAN as an IEEE 802.1x guest VLAN. The range is 1
to 4094.
You can configure any active VLAN except an internal VLAN (routed
port), an RSPAN VLAN, or a voice VLAN as an IEEE 802.1x guest
VLAN.
Enable periodic re-authentication of the client, which is disabled by
default.
Set the number of seconds between re-authentication attempts.
The keywords have these meanings:
seconds—Sets the number of seconds from 1 to 65535; the default is
3600 seconds.
server—Sets the number of seconds based on the value of the
Session-Timeout RADIUS attribute (Attribute[27]) and the
Termination-Action RADIUS attribute (Attribute [29]).
This command affects the behavior of the switch only if periodic
re-authentication is enabled.
Return to privileged EXEC mode.
Verify your IEEE 802.1x authentication configuration.
(Optional) Save your entries in the configuration file.
Catalyst 3750 Switch Software Configuration Guide
Configuring IEEE 802.1x Authentication
10-41

Advertisement

Table of Contents
loading

Table of Contents