Dot1X Port-Control - Cisco Catalyst 2950 Command Reference Manual

Hide thumbs Also See for Catalyst 2950:
Table of Contents

Advertisement

Chapter 2
Catalyst 2950 and 2955 Cisco IOS Commands

dot1x port-control

Use the dot1x port-control interface configuration command to enable manual control of the
authorization state of the port. Use the no form of this command to return to the default setting.
Syntax Description
auto
force-authorized
force-unauthorized Deny all access through this interface by forcing the port to transition to the
Defaults
The default is force-authorized.
Command Modes
Interface configuration
Command History
Release
12.1(6)EA2
Usage Guidelines
You must enable IEEE 802.1x authentication globally on the switch by using the dot1x
system-auth-control global configuration command before enabling IEEE 802.1x authentication on a
specific interface.
The IEEE 802.1x protocol is supported on Layer 2 static-access ports.
You can use the auto keyword only if the port is not configured as one of these:
OL-10102-01
dot1x port-control {auto | force-authorized | force-unauthorized}
no dot1x port-control
Enable IEEE 802.1x authentication on the interface and cause the port to
transition to the authorized or unauthorized state based on the IEEE 802.1x
authentication exchange between the switch and the client.
Disable IEEE 802.1x authentication on the interface and cause the port to
transition to the authorized state without any authentication exchange required.
The port sends and receives normal traffic without IEEE 802.1x-based
authentication of the client.
unauthorized state, ignoring all attempts by the client to authenticate. The
switch cannot provide authentication services to the client through the interface.
Modification
This command was introduced.
Trunk port—If you try to enable IEEE 802.1x authentication on a trunk port, an error message
appears, and IEEE 802.1x is not enabled. If you try to change the mode of an IEEE 802.1x-enabled
port to trunk, the port mode is not changed.
Dynamic ports—A port in dynamic mode can negotiate with its neighbor to become a trunk port. If
you try to enable IEEE 802.1x authentication on a dynamic port, an error message appears, and
IEEE 802.1x authentication is not enabled. If you try to change the mode of an IEEE 802.1x-enabled
port to dynamic, the port mode is not changed.
Catalyst 2950 and Catalyst 2955 Switch Command Reference
dot1x port-control
2-101

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 2955

Table of Contents