236
Configuring IEEE 802.1x Port-Based Authentication
Configuration Examples for Configuring IEEE 802.1x Port-Based Authentication
Configuring Inaccessible Authentication Bypass: Example
This example shows how to configure the inaccessible authentication bypass feature:
Switch(config)#
radius-server dead-criteria time 30 tries 20
Switch(config)#
radius-server deadtime 60
Switch(config)#
radius-server host 1.1.1.2 acct-port 1550 auth-port 1560 test username
user1 idle-time
30 key abc1234
Switch(config)#
dot1x critical eapol
Switch(config)#
dot1x critical recovery delay 2000
Switch(config)#
interface gigabitethernet 1/1
Switch(config)#
radius-server deadtime 60
Switch(config-if)#
dot1x critical
Switch(config-if)#
dot1x critical recovery action reinitialize
Switch(config-if)#
dot1x critical vlan 20
Switch(config-if)#
end
Configuring VLAN Groups: Examples
This example shows how to configure the VLAN groups, to map the VLANs to the groups, and to verify the VLAN group
configurations and mapping to the specified VLANs:
switch(config)#
vlan group eng-dept vlan-list 10
switch(config)#
show vlan group group-name eng-dept
Group Name Vlans Mapped
------------- --------------
eng-dept 10
switch# show dot1x vlan-group all
Group Name Vlans Mapped
------------- --------------
eng-dept 10
hr-dept 20
This example shows how to add a VLAN to an existing VLAN group and to verify that the VLAN was added:
switch(config)#
vlan group eng-dept vlan-list 30
switch(config)#
show vlan group eng-dept
Group Name Vlans Mapped
------------- --------------
eng-dept 10,30
This example shows how to remove a VLAN from a VLAN group:
switch#
no vlan group
eng-dept
vlan-list
10
This example shows that when all the VLANs are cleared from a VLAN group, the VLAN group is cleared:
switch(config)#
no vlan group eng-dept vlan-list 30
Vlan 30 is successfully cleared from vlan group eng-dept.
switch(config)#
show vlan group group-name eng-dept
This example shows how to clear all the VLAN groups:
switch(config)#
no vlan group end-dept vlan-list all
switch(config)#
show vlan-group all
For more information about these commands, see the
Cisco IOS Security Command Reference.
Summary of Contents for IE 4000
Page 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Page 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Page 108: ...104 Configuring Switch Clusters Additional References ...
Page 128: ...124 Performing Switch Administration Additional References ...
Page 130: ...126 Configuring PTP ...
Page 140: ...136 Configuring CIP Additional References ...
Page 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Page 192: ...188 Configuring Switch Based Authentication Additional References ...
Page 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Page 298: ...294 Configuring VLANs Additional References ...
Page 336: ...332 Configuring STP Additional References ...
Page 408: ...404 Configuring DHCP Additional References ...
Page 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Page 490: ...486 Configuring SPAN and RSPAN Additional References ...
Page 502: ...498 Configuring Layer 2 NAT ...
Page 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Page 930: ...926 Configuring IP Unicast Routing Related Documents ...
Page 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Page 978: ...974 Dying Gasp ...
Page 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Page 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Page 996: ...992 Ethernet CFM ...
Page 1066: ...1062 Using an SD Card SD Card Alarms ...