46-6
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
OL-4266-08
Chapter 46 Configuring IEEE 802.1X Port-Based Authentication
Default 802.1X Port-Based Authentication Configuration
Default 802.1X Port-Based Authentication Configuration
Table 46-1
shows the default 802.1X configuration.
802.1X Port-Based Authentication Guidelines and Restrictions
When configuring 802.1X port-based authentication, follow these guidelines and restrictions:
•
When 802.1X is enabled, ports are authenticated before any other Layer 2 or Layer 3 features are
enabled.
•
The 802.1X protocol is supported on both Layer 2 static-access ports and Layer 3 routed ports, but
it is not supported on these port types:
Table 46-1 Default 802.1X Configuration
Feature
Default Setting
Authentication, authorization, and
accounting (AAA)
Disabled
RADIUS server IP address
None specified
RADIUS server UDP authentication port
1812
RADIUS server key
None specified
Per-interface 802.1X protocol enable state
Disabled (force-authorized)
Note
The port transmits and receives normal traffic
without 802.1X-based authentication of the
client.
Periodic reauthentication
Disabled
Number of seconds between
reauthentication attempts
3600 seconds
Quiet period
60 seconds (number of seconds that the router remains in
the quiet state following a failed authentication exchange
with the client)
Retransmission time
30 seconds (number of seconds that the router should
wait for a response to an EAP request/identity frame
from the client before retransmitting the request)
Maximum retransmission number
2 times (number of times that the router will send an
EAP-request/identity frame before restarting the
authentication process)
Multiple host support
Disabled
Client timeout period
30 seconds (when relaying a request from the
authentication server to the client, the amount of time the
router waits for a response before retransmitting the
request to the client)
Authentication server timeout period
30 seconds (when relaying a response from the client to
the authentication server, the amount of time the router
waits for a reply before retransmitting the response to the
server)