Configuring the Switch
3-100
3
• Each switch port that will be used must be set to dot1X “Auto” mode.
• Each client that needs to be authenticated must have dot1X client software
installed and properly configured.
• The RADIUS server and 802.1X client support EAP. (The switch only supports
EAPOL in order to pass the EAP packets from the server to the client.)
• The RADIUS server and client also have to support the same EAP authentication
type – MD5, PEAP, TLS, or TTLS. (Native support for these encryption methods is
provided in Windows XP, and in Windows 2000 with Service Pack 4. To support
these encryption methods in Windows 95 and 98, you can use the AEGIS dot1x
client or other comparable client software)
Displaying 802.1X Global Settings
The 802.1X protocol provides client authentication.
Command Attributes
802.1X System Authentication Control
– The global setting for 802.1X.
Web
– Click Security, 802.1X, Information.
Figure 3-59 802.1X Global Information
CLI
– This example shows the default global setting for 802.1X.
Console#show dot1x
4-153
Global 802.1X Parameters
system-auth-control: enable
802.1X Port Summary
Port Name Status Operation Mode Mode Authorized
1/1 disabled Single-Host ForceAuthorized n/a
1/2 disabled Single-Host ForceAuthorized n/a
.
.
.
802.1X Port Details
802.1X is disabled on port 1/1
.
.
.
802.1X is disabled on port 1/28
Console#
Summary of Contents for 6152PL2 FICHE
Page 2: ......
Page 6: ...vi ...
Page 8: ...viii ...
Page 32: ...Tables xxxii ...
Page 38: ...Figures xxxviii ...
Page 56: ...Initial Configuration 2 10 2 ...
Page 378: ...Configuring the Switch 3 322 3 ...
Page 817: ......