12-4
Cisco IE 3000 Switch Software Configuration Guide
OL-13018-03
Chapter 12 Configuring IEEE 802.1x Port-Based Authentication
Understanding IEEE 802.1x Port-Based Authentication
Figure 12-2
shows the authentication process.
Figure 12-2
Authentication Flowchart
The switch re-authenticates a client when one of these situations occurs:
•
Periodic re-authentication is enabled, and the re-authentication timer expires.
You can configure the re-authentication timer to use a switch-specific value or to be based on values
from the RADIUS server.
After 802.1x authentication using a RADIUS server is configured, the switch uses timers based on
the Session-Timeout RADIUS attribute (Attribute[27]) and the Termination-Action RADIUS
attribute (Attribute [29]).
The Session-Timeout RADIUS attribute (Attribute[27]) specifies the time after which
re-authentication occurs.
141679
Ye
s
No
Client
identity i
s
inv
a
lid
All
a
uthentic
a
tion
s
erver
s
a
re down.
All
a
uthentic
a
tion
s
erver
s
a
re down.
Client
identity i
s
v
a
lid
The
s
witch get
s
a
n
EAPOL me
ssa
ge,
a
nd the EAPOL
me
ssa
ge
exch
a
nge begin
s
.
Ye
s
No
1
1
1
1 = Thi
s
occur
s
if the
s
witch doe
s
not detect EAPOL p
a
cket
s
from the client.
Client MAC
a
ddre
ss
identity
i
s
inv
a
lid.
Client MAC
a
ddre
ss
identity
i
s
v
a
lid.
I
s
the client IEEE
802.1x c
a
p
a
ble?
S
t
a
rt IEEE 802.1x port-b
as
ed
a
uthentic
a
tion.
U
s
e in
a
cce
ss
ible
a
uthentic
a
tion byp
ass
(critic
a
l
a
uthentic
a
tion)
to
ass
ign the critic
a
l
port to
a
VLAN.
IEEE 802.1x
a
uthentic
a
tion
proce
ss
time
s
out.
I
s
MAC
a
uthentic
a
tion
byp
ass
en
a
bled?
U
s
e MAC
a
uthentic
a
tion
byp
ass
.
A
ss
ign the port to
a
gue
s
t VLAN.
S
t
a
rt
Done
A
ss
ign the port to
a
VLAN.
Done
Done
A
ss
ign the port to
a
VLAN.
Done
A
ss
ign the port to
a
re
s
tricted VLAN.
Done