10-40
Catalyst 2975 Switch Software Configuration Guide
OL-19720-02
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Configuring 802.1x Authentication
Configuring 802.1x Authentication
To configure 802.1x port-based authentication, you must enable authentication, authorization, and
accounting (AAA) and specify the authentication method list. A method list describes the sequence and
authentication method to be queried to authenticate a user.
To allow VLAN assignment, you must enable AAA authorization to configure the switch for all
network-related service requests.
This is the 802.1x AAA process:
Step 1
A user connects to a port on the switch.
Step 2
Authentication is performed.
Step 3
VLAN assignment is enabled, as appropriate, based on the RADIUS server configuration.
Step 4
The switch sends a start message to an accounting server.
Step 5
Re-authentication is performed, as necessary.
Step 6
The switch sends an interim accounting update to the accounting server, that is based on the result of
re-authentication.
Step 7
The user disconnects from the port.
Step 8
The switch sends a stop message to the accounting server.
Step 4
interface
interface-id
Specify the port connected to the client that is to be enabled for 802.1x
authentication, and enter interface configuration mode.
Step 5
switchport mode access
Set the port to access mode.
Step 6
authentication violation shutdown
|
restrict
|
protect
|
replace
}
or
dot1x violation-mode
{
shutdown
|
restrict
|
protect
}
Configure the violation mode. The keywords have these meanings:
•
shutdown
–Error disable the port.
•
restrict
–Generate a syslog error.
•
protect
–Drop packets from any new device that sends traffic to the
port.
•
replace
–Removes the current session and authenticates with the new
host.
Step 7
end
Return to privileged EXEC mode.
Step 8
show authentication
or
show dot1x
Verify your entries.
Step 9
copy running-config startup-config
(Optional) Save your entries in the configuration file.
Command
Purpose
Содержание 2975 - Catalyst LAN Base Switch
Страница 36: ...Contents xxxvi Catalyst 2975 Switch Software Configuration Guide OL 19720 02 ...
Страница 40: ...xxxviii Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Preface ...
Страница 62: ...1 22 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 1 Overview Where to Go Next ...
Страница 398: ...13 30 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 13 Configuring VLANs Configuring VMPS ...
Страница 424: ...15 18 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 15 Configuring VTP Monitoring VTP ...
Страница 628: ...26 8 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 26 Configuring UDLD Displaying UDLD Status ...
Страница 660: ...28 8 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 28 Configuring RMON Displaying RMON Status ...
Страница 888: ...38 32 Catalyst 2975 Switch Software Configuration Guide OL 19720 02 Chapter 38 Troubleshooting Troubleshooting Tables ...