Enabling Multiple 802.1X Authentications - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Chapter 31
Configuring 802.1x Authentication
Note
You must specify at least one RADIUS server before you can enable 802.1x authentication on the switch.
For more information, see the
To enable and initialize 802.1x authentication for access to the switch, perform this task in privileged
mode:
Task
Step 1
Enable 802.1x control on a specific port.
Step 2
Initialize 802.1x on the same port.
Step 3
Verify the 802.1x configuration.
This example shows how to enable 802.1x authentication on port 1 in module 4, initialize 802.1x
authentication on the same port, and verify the configuration:
Console> (enable) set port dot1x 4/1 port-control auto
Port 4/1 dot1x port-control is set to auto.
Trunking disabled for port 4/1 due to Dot1x feature.
Spantree port fast start option enabled for port 4/1.
Console> (enable) set port dot1x 4/1 initialize
Port 4/1 initializing...
Port 4/1 dot1x initialization complete.
Console> show port dot1x 4/1
Port
----- ------------------- ---------- ------------------- -------------
4/1
Port
----- ------------- -----------------
4/1

Enabling Multiple 802.1x Authentications

You can specify multiple authentications so that more than one host can gain access to an 802.1x port.
Multiple authentication is Cisco proprietary and allows multiple dot1x-hosts on a port; every host is
authenticated separately. Use these guidelines when enabling multiple 802.1x authentications:
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Auth-State
BEnd-State Port-Control
connecting
finished
Multiple-Host Re-authentication
disabled
disabled
Traffic from non-802.1x hosts on multiple authenticated ports is blocked.
You cannot enable a guest VLAN on multiple authenticated ports.
You cannot enable multiple authentication on a multiple VLAN access port (MVAP).
Multiple authenticated ports go into the port VLAN and will not go into a RADIUS-assigned VLAN.
You must enable port security on a port before you can enable multiple authentications on the port.
You cannot disable port security on a multiple authenticated port.
Port security timers are used on multiple authenticated ports. Reauthentication timers are not used
on multiple authenticated ports.
"Specifying RADIUS Servers" section on page
Command
set port dot1x mod/port port-control auto
set port dot1x mod/port initialize
show port dot1x mod/port
auto
Configuring 802.1x Authentication on the Switch
30-23.
Port-Status
unauthorized
31-11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents