9-9
Catalyst 3560 Switch Software Configuration Guide
78-16156-01
Chapter 9 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Authentication
Only one 802.1X-authenticated user is supported on a port. If the multiple-hosts mode is enabled on the
port, the per-user ACL attribute is disabled for the associated port.
The maximum size of the per-user ACL is 4000 ASCII characters.
For examples of vendor-specific attributes, see the
“Configuring the Switch to Use Vendor-Specific
RADIUS Attributes” section on page 8-29
. For more information about configuring ACLs, see
Chapter 27, “Configuring Network Security with ACLs.”
To configure per-user ACLs, you need to perform these tasks:
•
Enable AAA authentication.
•
Enable AAA authorization by using the network keyword to allow interface configuration from the
RADIUS server.
•
Enable 802.1X.
•
Configure the user profile and VSAs on the RADIUS server.
•
Configure the 802.1X port for single-host mode.
Configuring 802.1X Authentication
These sections describe how to configure 802.1X port-based authentication on your switch:
•
Default 802.1X Configuration, page 9-10
•
802.1X Configuration Guidelines, page 9-11
•
Configuring 802.1X Authentication, page 9-11
(required)
•
Configuring the Switch-to-RADIUS-Server Communication, page 9-13
(required)
•
Configuring Periodic Re-Authentication, page 9-14
(optional)
•
Manually Re-Authenticating a Client Connected to a Port, page 9-14
(optional)
•
Changing the Quiet Period, page 9-15
(optional)
•
Changing the Switch-to-Client Retransmission Time, page 9-15
(optional)
•
Setting the Switch-to-Client Frame-Retransmission Number, page 9-16
(optional)
•
Configuring the Host Mode, page 9-17
(optional)
•
Configuring a Guest VLAN, page 9-18
(optional)
•
Resetting the 802.1X Configuration to the Default Values, page 9-18
(optional)