Verifying the 802.1X Configuration
To display 802.1X information, perform one of the following tasks:
Purpose
Command
Displays the 802.1X feature status.
show dot1x
Displays all 802.1X feature status and configuration
information.
show dot1x all
[
details
|
statistics
|
summary
]
Displays the 802.1X feature status and configuration
information for an Ethernet interface.
show dot1x interface ethernet slot/port
[
details
|
statistics
|
summary
]
Displays the 802.1X feature configuration in the running
configuration.
show running-config dot1x
[
all
]
Displays the 802.1X feature configuration in the startup
configuration.
show startup-config dot1x
For detailed information about the fields in the output from these commands, see the
Cisco NX-OS Security
Command Reference
for your platform.
802.1X Support for VXLAN EVPN
Guidelines and Limitations for 802.1X Support for VXLAN EVPN
The following are the guidelines and limitations for 802.1X support for VXLAN EVPN:
• Port channel interfaces or the member ports of the port channel are not supported.
• vPC ports are not supported.
• The current support of the feature uses regular and dynamic EVPN updates on the BGP-EVPN control
plane for 802.1X secure MAC updates. As a result, we cannot prevent the move across EVPN even if
the global policy is “dot1x mac-move deny."
• Ensure that the “dot1x mac-move” policy is configured the same across the fabric. There is no
configuration validation across the nodes, hence it could lead to unexpected behavior if the configuration
policy is not in sync.
• The local to remote MAC moves behavior for the deny and permit modes is permitted. Therefore, the
MAC move is permitted even if the deny mode is enabled.
• Ensure that the dot1x and the port-security ports use different VLANs. The same VLAN cannot be
assigned to both ports.
• Dot1x is not VLAN aware and hence having the same MAC in two different VLANs is not possible.
Depending on the mac-move mode selected, either the MAC will be moved to a new VLAN or it will
be denied.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
205
Configuring 802.1X
Verifying the 802.1X Configuration