Chapter 7
| Authentication Commands
802.1X Port Authentication
– 200 –
802.1X Port Authentication
The switch supports IEEE 802.1X (dot1x) port-based access control that prevents
unauthorized access to the network by requiring users to first submit credentials
for authentication. Client authentication is controlled centrally by a RADIUS server
using EAP (Extensible Authentication Protocol).
Table 43: 802.1X Port Authentication Commands
Command
Function
Mode
General Commands
dot1x default
Resets all dot1x parameters to their default values
GC
dot1x eapol-pass-through
Passes EAPOL frames to all ports in STP forwarding state
when dot1x is globally disabled
GC
dot1x system-auth-control
Enables dot1x globally on the switch.
GC
Authenticator Commands
dot1x intrusion-action
Sets the port response to intrusion when authentication
fails
IC
dot1x max-req
Sets the maximum number of times that the switch
retransmits an EAP request/identity packet to the client
before it times out the authentication session
IC
dot1x operation-mode
Allows single or multiple hosts on an dot1x port
IC
dot1x port-control
Sets dot1x mode for a port interface
IC
dot1x re-authentication
Enables re-authentication for all ports
IC
dot1x timeout quiet-period
Sets the time that a switch port waits after the Max Request
Count has been exceeded before attempting to acquire a
new client
IC
dot1x timeout re-authperiod
Sets the time period after which a connected client must
be re-authenticated
IC
dot1x timeout supp-timeout
Sets the interval for a supplicant to respond
IC
dot1x timeout tx-period
Sets the time period during an authentication session that
the switch waits before re-transmitting an EAP packet
IC
dot1x re-authenticate
Forces re-authentication on specific ports
PE
Supplicant Commands
dot1x identity profile
Configures dot1x supplicant user name and password
GC
dot1x max-start
Sets the maximum number of times that a port supplicant
will send an EAP start frame to the client
IC
dot1x pae supplicant
Enables dot1x supplicant mode on an interface
IC
dot1x timeout auth-period
Sets the time that a supplicant port waits for a response
from the authenticator
IC
dot1x timeout held-period
Sets the time a port waits after the maximum start count
has been exceeded before attempting to find another
authenticator
IC
Summary of Contents for EX-3524
Page 2: ......
Page 28: ...Figures 28 ...
Page 34: ...Section I Getting Started 34 ...
Page 58: ...Chapter 1 Initial Switch Configuration Setting the System Clock 58 ...
Page 72: ...Chapter 2 Using the Command Line Interface CLI Command Groups 72 ...
Page 156: ...Chapter 5 SNMP Commands Notification Log Commands 156 ...
Page 164: ...Chapter 6 Remote Monitoring Commands 164 ...
Page 218: ...Chapter 7 Authentication Commands Management IP Filter 218 ...
Page 268: ...Chapter 8 General Security Measures Port based Traffic Segmentation 268 ...
Page 292: ...Chapter 9 Access Control Lists ACL Information 292 ...
Page 312: ...Chapter 10 Interface Commands Power Savings 312 ...
Page 324: ...Chapter 11 Link Aggregation Commands Trunk Status Display Commands 324 ...
Page 366: ...Chapter 15 Address Table Commands 366 ...
Page 428: ...Chapter 17 VLAN Commands Configuring Voice VLANs 428 ...
Page 572: ...Chapter 25 IP Interface Commands IPv6 Interface 572 ...
Page 578: ...Section I Appendices 578 ...