9-17
Catalyst 2928 Switch Software Configuration Guide
OL-23389-01
Chapter 9 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
Configuring IEEE 802.1x Authentication
These sections contain this configuration information:
•
Default IEEE 802.1x Authentication Configuration, page 9-17
•
IEEE 802.1x Authentication Configuration Guidelines, page 9-19
•
Configuring IEEE 802.1x Authentication, page 9-17
•
Configuring the Switch-to-RADIUS-Server Communication, page 9-22
(required)
•
Configuring the Host Mode, page 9-23
(optional)
•
Configuring Periodic Re-Authentication, page 9-24
(optional)
•
Manually Re-Authenticating a Client Connected to a Port, page 9-24
(optional)
•
Changing the Quiet Period, page 9-25
(optional)
•
Changing the Switch-to-Client Retransmission Time, page 9-25
(optional)
•
Setting the Switch-to-Client Frame-Retransmission Number, page 9-26
(optional)
•
Setting the Re-Authentication Number, page 9-27
(optional)
•
Configuring IEEE 802.1x Accounting, page 9-27
(optional)
•
Configuring a Guest VLAN, page 9-28
(optional)
•
Configuring a Restricted VLAN, page 9-29
(optional)
•
Configuring MAC Authentication Bypass, page 9-31
(optional)
•
Disabling IEEE 802.1x Authentication on the Port, page 9-31
(optional)
•
Resetting the IEEE 802.1x Authentication Configuration to the Default Values, page 9-32
(optional)
Default IEEE 802.1x Authentication Configuration
shows the default IEEE 802.1x authentication configuration.
Table 9-2
Default IEEE 802.1x Authentication Configuration
Feature
Default Setting
Switch IEEE 802.1x enable state
Disabled.
Per-port IEEE 802.1x enable state
Disabled (force-authorized).
The port sends and receives normal traffic without
IEEE 802.1x-based authentication of the client.
AAA Disabled.
RADIUS server
•
IP address
•
UDP authentication port
•
Key
•
None specified.
•
1812.
•
None specified.
Host mode
Single-host mode.
Control direction
Bidirectional control.
Periodic re-authentication
Disabled.