Understanding How 802.1X Authentication Works; Device Roles - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Understanding How 802.1X Authentication Works

Understanding How 802.1X Authentication Works
802.1X defines a client-server-based access control and authentication protocol that restricts
unauthorized devices from connecting to a LAN through publicly accessible ports. 802.1X controls
network access by creating two distinct virtual access points at each port. One access point is an
uncontrolled port; the other is a controlled port. All traffic through the single port is available to both
access points. 802.1X authenticates each user device that is connected to a switch port and assigns the
port to a VLAN before making available any services that are offered by the switch or the LAN. Until
the device is authenticated, 802.1X access control allows only Extensible Authentication Protocol over
LAN (EAPOL) traffic through the port to which the device is connected. After authentication is
successful, normal traffic can pass through the port. You can restrict the traffic in both directions, or you
can restrict just the incoming traffic.
These sections provide the following information:

Device Roles

With 802.1X port-based authentication, the devices in the network have specific roles. (See
Figure 40-1
Workstations
(supplicants)
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
40-2
Configuring 802.1X Authentication on the Switch, page 40-13
Device Roles, page 40-2
Authentication Initiation and Message Exchange, page 40-3
Ports in Authorized and Unauthorized States, page 40-4
Authentication Server, page 40-6
802.1X Parameters Configurable on the Switch, page 40-6
Understanding How 802.1X VLAN Assignments Using a RADIUS Server Work, page 40-7
Understanding How 802.1X Authentication with DHCP Works, page 40-8
Understanding How 802.1X Authentication on Ports Configured for Auxiliary VLAN Traffic
Works, page 40-8
Understanding How 802.1X Authentication for the Guest VLAN Works, page 40-9
Understanding How 802.1X Authentication with Port Security Works, page 40-10
Understanding How 802.1X Authentication with ARP Traffic Inspection Works, page 40-11
802.1X Device Roles
Catalyst switch
Chapter 40
Authentication
server
(RADIUS)
Configuring 802.1X Authentication
Figure
40-1.)
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents