1-65
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
OL-25303-03
Chapter 1 Configuring IEEE 802.1x Port-Based Authentication
Configuring 802.1x Authentication
To return to the RADIUS server default settings, use the
no radius-server dead-criteria
, the
no
radius-server deadtime
, and the
no radius-server host
global configuration commands. To disable
inaccessible authentication bypass, use the
no authentication event server dead action
interface
configuration command. To disable critical voice VLAN, use the no
authentication event server dead
action authorize voice
interface configuration command.
This example shows how to configure the inaccessible authentication bypass and critical voice VLAN
features:
Switch(config)#
radius-server dead-criteria time 30 tries 20
Switch(config)#
radius-server deadtime 60
Switch(config)#
radius-server host 1.1.1.2 acct-port 1550 auth-port 1560 test username
user1 idle-time 30 key abc1234
Switch(config)#
dot1x critical eapol
Switch(config)#
dot1x critical recovery delay 2000
Switch(config)#
interface gigabitethernet 1/0/1
Switch(config-if)#
authentication event server dead action reinitialicze vlan 20
Switch(config-if)#
switchport voice vlan
Switch(config-if)#
authentication event server dead action authorize voice
Switch(config-if)#
end
Step 5
dot1x critical
{
eapol
|
recovery
delay
milliseconds
}
(Optional) Configure the parameters for inaccessible authentication bypass:
eapol
—Specify that the switch sends an EAPOL-Success message when the
switch successfully authenticates the critical port.
recovery delay
milliseconds
—Set the recovery delay period during which the
switch waits to re-initialize a critical port when a RADIUS server that was
unavailable becomes available. The range is from 1 to 10000 milliseconds. The
default is 1000 milliseconds (a port can be re-initialized every second).
Step 6
interface
interface-id
Specify the port to be configured, and enter interface configuration mode. For the
supported port types, see the
“802.1x Authentication Configuration Guidelines”
Step 7
authentication event server
dead action
{
authorize |
reinitialize
}
vlan
vlan-id
]
Use these keywords to move hosts on the port if the RADIUS server is
unreachable:
•
authorize
–Move any new hosts trying to authenticate to the user-specified
critical VLAN.
•
reinitialize
–Move all authorized hosts on the port to the user-specified
critical VLAN.
Step 8
switchport voice vlan
vlan-id
Specifies the voice VLAN for the port. The voice VLAN cannot be the same as
the critical data VLAN configured in Step 6.
Step 9
authentication event server
dead action authorize voice
Configures critical voice VLAN to move data traffic on the port to the voice
VLAN if the RADIUS server is unreachable.
Step 10
end
Return to privileged EXEC mode.
Step 11
show authentication interface
interface-id
(Optional) Verify your entries.
Step 12
copy running-config
startup-config
(Optional) Save your entries in the configuration file.
Command
Purpose
Summary of Contents for Catalyst 3560-X Series
Page 12: ...Contents 10 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 13: ...Contents 11 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 14: ...Contents 12 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 15: ...Contents 13 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 16: ...Contents 14 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 17: ...Contents 15 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 18: ...Contents 16 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 19: ...Contents 17 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 20: ...Contents 18 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 21: ...Contents 19 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 22: ...Contents 20 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 23: ...Contents 21 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 24: ...Contents 22 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 25: ...Contents 23 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 26: ...Contents 24 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 27: ...Contents 25 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 28: ...Contents 26 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 29: ...Contents 27 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 30: ...Contents 28 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 31: ...Contents 29 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 32: ...Contents 30 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 33: ...Contents 31 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 34: ...Contents 32 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 35: ...Contents 33 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 36: ...Contents 34 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 37: ...Contents 35 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 38: ...Contents 36 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...
Page 42: ...56 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 Preface ...
Page 1538: ...Index IN 58 Catalyst 3750 X and 3560 X Switch Software Configuration Guide OL 25303 03 ...