10-62
Catalyst 3750-E and 3560-E Switch Software Configuration Guide
OL-9775-08
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Configuring 802.1x Authentication
This example shows how to configure a switch as a supplicant:
Switch#
configure terminal
Switch(config)#
cisp enable
Switch(config)#
dot1x credentials test
Switch(config)#
username suppswitch
Switch(config)#
password
myswitch
Switch(config)#
dot1x supplicant force-multicast
Switch(config)#
interface gigabitethernet1/0/1
Switch(config-if)#
switchport trunk encapsulation dot1q
Switch(config-if)#
switchport mode trunk
Switch(config-if)#
dot1x pae supplicant
Switch(config-if)#
dot1x credentials test
Switch(config-if)#
end
Configuring NEAT with Auto Smartports Macros
You can also use an Auto Smartports user-defined macro instead of the switch VSA to configure the
authenticator switch. For Auto Smartports macros, see
Auto Smartports Macros Configuration Guide
and
Release Notes for Auto Smartports Macros
.
Configuring 802.1x Authentication with Downloadable ACLs and Redirect URLs
In addition to configuring 802.1x authentication on the switch, you need to configure the ACS. For more
information, see the
Cisco Secure ACS configuration guides
.
Note
You must configure a downloadable ACL on the ACS before downloading it to the switch.
After authentication on the port, you can use the
show ip access-list
privileged EXEC command to
display the downloaded ACLs on the port.
Configuring Downloadable ACLs
The policies take effect after client authentication and the client IP address addition to the IP device
tracking table. The switch then applies the downloadable ACL to the port.
Beginning in privileged EXEC mode:
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
ip device tracking
Sets the ip device tracking table.
Step 3
aaa new-model
Enables AAA.
Step 4
aaa authorization
network
default
local
group
radius
Sets the authorization method to local. To remove the
authorization method, use the
no aaa authorization network
default local group radius
command.
Step 5
radius-server vsa send authentication
Configure the radius vsa send authentication.
Step 6
interface
interface-id
Specify the port to be configured, and enter interface
configuration mode.
Summary of Contents for Catalyst 3750-E Series
Page 48: ...Contents xlviii Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 ...
Page 52: ...lii Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 Preface ...
Page 1414: ...Index IN 58 Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 ...