8-24
Cisco Catalyst Blade Switch 3020 for HP Software Configuration Guide
OL-8915-03
Chapter 8 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
•
When you configure the
dot1x test eapol-capable
command on an IEEE 802.1x-enabled port, and
the link comes up, the port queries the connected client about its IEEE 802.1x capability. When the
client responds with a notification packet, it is IEEE 802.1x-capable. A syslog message is generated
if the client responds within the timeout period. If the client does not respond to the query, the client
is not IEEE 802.1x-capable. No syslog message is generated.
•
The readiness check can be sent on a port that handles multiple hosts (for example, a PC that is
connected to an IP phone). A syslog message is generated for each of the clients that respond to the
readiness check within the timer period.
Beginning in privileged EXEC mode, follow these steps to enable the IEEE 802.1x readiness check on
the switch:
Command
Purpose
Step 1
dot1x test eapol-capable
[
interface
interface-id
]
Enable the 802.1x readiness check on the switch.
(Optional) For
interface-id
specify the port on which to check for
IEEE 802.1x readiness.
Note
If you omit the optional
interface
keyword, all interfaces on the
switch are tested.
Step 1
configure terminal
(Optional) Enter global configuration mode.
Step 2
dot1x test timeout
timeout
(Optional) Configure the timeout used to wait for EAPOL response. The
range is from 1 to 65535 seconds. The default is 10 seconds.
Step 3
end
(Optional) Return to privileged EXEC mode.
Step 4
show running-config
(Optional) Verify your modified timeout values.