Configuring Security
Configuring 802.1X
Cisco 500 Series Stackable Managed Switch Administration Guide
325
18
-
Selected
—Enables using a Guest VLAN for unauthorized ports. If a Guest
VLAN is enabled, the unauthorized port automatically joins the VLAN
selected in the
Guest VLAN ID
field in the
802.1X Port Authentication
page.
After an authentication failure, and if Guest VLAN is activated globally on
a given port, the guest VLAN is automatically assigned to the
unauthorized ports as an Untagged VLAN.
-
Cleared
—Disables Guest VLAN on the port.
•
Authentication Method
—Select the authentication method for the port. The
options are:
-
802.1X Only
—802.1X authentication is the only authentication method
performed on the port.
-
MAC Only
—Port is authenticated based on the supplicant MAC address.
Only 8 MAC-based authentications can be used on the port.
-
802.1X and MAC
—Both 802.1X and MAC-based authentication are
performed on the switch. The 802.1X authentication takes precedence.
NOTE
For MAC authentication to succeed, the RADIUS server supplicant
username and password must be the supplicant MAC address. The MAC
address must be in lower case letters and entered without the “:” or “-”
separators; for example: 0020aa00bbcc.
•
Periodic Reauthentication
—Select to enable port re-authentication
attempts after the specified Reauthentication Period.
•
Reauthentication Period
—Enter the number of seconds after which the
selected port is reauthenticated.
•
Reauthenticate Now
—Select to enable immediate port re-authentication.
•
Authenticator State
—Displays the defined port authorization state. The
options are:
-
Force-Authorized
—Controlled port state is set to Force-Authorized
(forward traffic).
-
Force-Unauthorized
—Controlled port state is set to Force-Unauthorized
(discard traffic).