Cisco WS-C6506 Software Manual page 514

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Downloadable ACLs
-----
5/35
Authenticate the dot1x port and that the downloadable ACL is downloaded and the child ACL is
Step 6
generated. Check the authentication status.
Console> (enable) show port dot1x 5/35
Port
----- ------------------- ---------- ------------------- -------------
5/35 authenticated
Port
----- ------------- -----------------
5/35 SingleAuth
Port
----- ------------- --------------- ------------------ ---------------
5/35 -
Port
----- ------------------------ ----------------------------------
5/35 disabled
Port
----- --------
5/35 disabled
Port
----- -------------------------------------------
5/35 ACSACL#-IP-test-44bb6f49
If the dot1x Auth-state is in the ipawaiting state, add IP to the host (through DHCP or ARP or the
Note
addition of static DHCP snooping bindings). A downloadable ACL will be downloaded and a child ACL
will be created.
If an MSFC is the router, to obtain DHCP-snooping bindings, map the DHCP-snooping ACL to the
authenticated host VLAN. If an external router configuration is used, map the DHCP-snooping ACL to
the host and DHCP-server port.
Sample Output of show Commands
The following sample outputs of show commands that are used for displaying the child ACL and
downloaded ACL after authentication:
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
15-118
------------------
32
Auth-State
Port-Mode
Re-authentication
disabled
Posture-Token Critical-Status Termination action Session-timeout
no
Session-Timeout-Override Url-Redirect
Critical
Port-Name
---------
-
Downloaded ACL
Displays the system-generated ACL information:
Console> (enable) show security acl info dacl1x_5_35
set security acl ip dacl1x_5_35
---------------------------------------------------
arp permit
1. permit arp-inspection any any
2. permit dhcp-snooping
3. permit ip host 9.6.6.104 10.76.255.85 255.255.255.0
4. deny ip host 9.6.6.104 64.104.129.189 255.255.0.0
5. permit tcp host 9.6.6.104 eq 21 host 10.76.255.25
6. deny ip host 9.6.6.104 6.104.129.189 255.255.0.0
------------------------
0
BEnd-State Port-Control
idle
auto
Shutdown-timeout
----------------
disabled
NoReAuth
-
Chapter 15
Configuring Access Control
Port-Status
authorized
Control-Mode
admin
oper
---------------
Both
Both
-
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents