MES1000, MES2000 Ethernet Switches
177
port (multiple sessions mode). If the port fails authentication in multiple hosts mode, the access to
network resources will be denied for every connected host. Also, advanced settings include administration
of guest VLANs, accessed by users who failed the authentication.
Access port (Access) cannot be the member of the unauthenticated VLAN. Trunk port native
VLAN (Trunk) cannot be the unauthenticated VLAN. But for the port in General PVID mode
it can be the unauthenticated VLAN (only tagged packets can be received in unauthorized
state).
Global configuration mode commands
Command line request in global configuration mode appears as follows:
console(config)#
Table 5.204 —Global configuration mode commands
Command
Value/Default value
Action
dot1x bpdu {filtering |
bridging}
-/filtering
Define 802.1x BPDU port security processing when 802.1x
disabled globally.
-
filtering
—filter 802.1x BPDU packets
-
bridging
—transfer 802.1x BPDU packets like regular data
packets
This function works only when 802.1x authentication
mode is disabled on the switch. To disable 802.1x
authentication, use the following command: no dot1x
system-auth-control.
no dot1x bpdu
Restore the default value.
dot1x guest-vlan timeout
timeout
timeout
: (
30 .. 180) /
Define the timeout between 802.1x authentication mode
activation (or port activation) and adding port to guest VLAN.
no dot1x guest-vlan
timeout
Restore the default value.
dot1x traps mac-
authentication success
-/ disable
Enable trap message transmission, when the client
successfully passes the MAC address authentication based on
802.1x standard.
no dot1x traps mac-
authentication success
Restore the default value.
dot1x traps mac-
authentication failure
-/ disable
Enable trap message transmission, when the client fails the
MAC address authentication based on 802.1x standard.
no dot1x traps mac-
authentication failure
Restore the default value.
dot1x radius-attributes
errors filter-id resource
{accept | reject}
-/
reject
Define the error processing for RADIUS attributes:
- accept—user will be accepted, if the filtering by ID is
unavailable due to resource distribution If the filtering by ID is
unavailable due to other reasons, the user will be rejected.
- reject—If the filtering by ID cannot be defined, the user will
be rejected.
no dot1x radius-attributes
errors filter-id resources
Restore the default value.
dot1x radius-attributes
nas-port format-type
{default | human}
-/default
Sets the port enumeration format in NAS-Port attribute during
802.1x authentication:
-
default
: default value, enumeration is consistent with
internal ifIndexes.
-
human
: port enumeration begins with 1 (as on the front
panel).
no dot1x radius-attributes
nas-port format-type
Restore the default value.