Auto Identity Interface Templates
The following interface templates are available in the Auto Identity feature:
•
AI_MONITOR_MODE
—
Passively monitors sessions that have authentication in open mode.
•
AI_LOW_IMPACT_MODE
—
Similar to monitor mode, but with a configured static policy such as a
port access control list (PACL).
•
AI_CLOSED_MODE
—
Secure mode in which data traffic is not allowed into the network, until
authentication is complete. This mode is the default.
The following commands are inbuilt in the AI_MONITOR_MODE:
switchport mode access
access-session port-control auto
access-session host-mode multi-auth
dot1x pae authenticator
mab
service-policy type control subscriber AI_DOT1X_MAB_POLICIES
The following commands are inbuilt in the AI_LOW_IMPACT_MODE:
switchport mode access
access-session port-control auto
access-session host-mode multi-auth
dot1x pae authenticator
mab
ip access-group AI_PORT_ACL in
service-policy type control subscriber AI_DOT1X_MAB_POLICIES
The following commands are inbuilt in the AI_CLOSED_MODE:
switchport mode access
access-session closed
access-session port-control auto
access-session host-mode multi-auth
dot1x pae authenticator
mab
service-policy type control subscriber AI_DOT1X_MAB_POLICIES
Auto Identity Built-in Policies
The following five built-in policies are available in the Auto Identity feature:
•
AI_DOT1X_MAB_AUTH
—
Enables flexible authentication with dot1x, and then MAC Address Bypass
(MAB).
•
AI_DOT1X_MAB_POLICIES
—
Enables flexible authentication with dot1x, and then MAB. Applies
critical VLAN in case the Authentication, Authorization, and Accounting (AAA) server is not reachable.
•
AI_DOT1X_MAB_WEBAUTH
—
Enables flexible authentication with dot1x, MAB, and then web
authentication.
•
AI_NEXTGEN_AUTHBYBASS
—
Skips authentication if an IP phone device is detected. Enables the
device classifier
command in global configuration mode and the
voice-vlan
command in interface
configuration mode to detect the device. This is a reference policy map, and users can copy the contents
of this policy map to other policy maps.
•
AI_STANDALONE_WEBAUTH
—
Defines standalone web authentication.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1455
Auto Identity
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......