802.1x Port Authentication
The switch supports IEEE 802.1x (dot1x) port-based access control that prevents
unauthorized access to the network by requiring users to first submit credentials for
authentication. Client authentication is controlled centrally by a RADIUS server
using EAP (Extensible Authentication Protocol).
Command
dot1x system-auth-control
dot1x default
dot1x max-req
dot1x port-control
dot1x operation-mode
dot1x re-authenticate
dot1x re-authentication
dot1x timeout quiet-period
dot1x timeout re-authperiod
dot1x timeout tx-period
show dot1x
dot1x system-auth-control
This command enables 802.1x port authentication globally on the switch. Use the
no form to restore the default.
Syntax
[no] system-auth-control
Default Setting
Disabled
Command Mode
Global Configuration
Example
Console(config)#dot1x system-auth-control
Console(config)#
Table 4-31. 802.1x Port Authentication
Function
Enables dot1x globally on the switch.
Resets all dot1x parameters to their default values
Sets the maximum number of times that the switch
retransmits an EAP request/identity packet to the client
before it times out the authentication session
Sets dot1x mode for a port interface
Allows single or multiple hosts on an dot1x port
Forces re-authentication on specific ports
Enables re-authentication for all ports
Sets the time that a switch port waits after the Max
Request Count has been exceeded before attempting to
acquire a new client
Sets the time period after which a connected client must
be re-authenticated
Sets the time period during an authentication session that
the switch waits before re-transmitting an EAP packet
Shows all dot1x related information
Authentication Commands
Mode
GC
GC
IC
IC
IC
PE
IC
IC
IC
IC
PE
4
Page
4-77
4-78
4-78
4-79
4-79
4-80
4-80
4-81
4-81
4-82
4-82
4-77
Need help?
Do you have a question about the 100BASE-TX and is the answer not in the manual?