
31-11
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 31 Configuring 802.1x Authentication
Configuring 802.1x Authentication on the Switch
Note
You must specify at least one RADIUS server before you can enable 802.1x authentication on the switch.
For more information, see the
“Specifying RADIUS Servers” section on page 30-23
.
To enable and initialize 802.1x authentication for access to the switch, perform this task in privileged
mode:
This example shows how to enable 802.1x authentication on port 1 in module 4, initialize 802.1x
authentication on the same port, and verify the configuration:
Console> (enable) set port dot1x 4/1 port-control auto
Port 4/1 dot1x port-control is set to auto.
Trunking disabled for port 4/1 due to Dot1x feature.
Spantree port fast start option enabled for port 4/1.
Console> (enable) set port dot1x 4/1 initialize
Port 4/1 initializing...
Port 4/1 dot1x initialization complete.
Console> show port dot1x 4/1
Port Auth-State BEnd-State Port-Control Port-Status
----- ------------------- ---------- ------------------- -------------
4/1 connecting finished auto unauthorized
Port Multiple-Host Re-authentication
----- ------------- -----------------
4/1 disabled disabled
Enabling Multiple 802.1x Authentications
You can specify multiple authentications so that more than one host can gain access to an 802.1x port.
Multiple authentication is Cisco proprietary and allows multiple dot1x-hosts on a port; every host is
authenticated separately. Use these guidelines when enabling multiple 802.1x authentications:
•
Traffic from non-802.1x hosts on multiple authenticated ports is blocked.
•
You cannot enable a guest VLAN on multiple authenticated ports.
•
You cannot enable multiple authentication on a multiple VLAN access port (MVAP).
•
Multiple authenticated ports go into the port VLAN and will not go into a RADIUS-assigned VLAN.
•
You must enable port security on a port before you can enable multiple authentications on the port.
•
You cannot disable port security on a multiple authenticated port.
•
Port security timers are used on multiple authenticated ports. Reauthentication timers are not used
on multiple authenticated ports.
Task
Command
Step 1
Enable 802.1x control on a specific port.
set port dot1x mod/port port-control auto
Step 2
Initialize 802.1x on the same port.
set port dot1x mod/port initialize
Step 3
Verify the 802.1x configuration.
show port dot1x mod/port