10-20
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Understanding IEEE 802.1x Port-Based Authentication
•
Configure secondary private VLANs as guest VLANs.
Configuring NAC Layer 2 IEEE 802.1x validation is similar to configuring IEEE 802.1x port-based
authentication except that you must configure a posture token on the RADIUS server. For information
about configuring NAC Layer 2 IEEE 802.1x validation, see the
“Configuring NAC Layer 2 IEEE 802.1x
Validation” section on page 10-41
and the
“Configuring Periodic Re-Authentication” section on
page 10-30
.
For more information about NAC, see the
Network Admission Control Software Configuration Guide
.
Using Multidomain Authentication
The switch supports multidomain authentication (MDA), which allows both a data device and voice
device, such as an IP phone (Cisco or non-Cisco), to authenticate on the same switch port. The port is
divided into a data domain and a voice domain.
MDA does not enforce the order of device authentication. However, for best results, we recommend that
a voice device is authenticated before a data device on an MDA-enabled port.
Follow these guidelines for configuring MDA:
•
To configure a switch port for MDA, see the
“Configuring the Host Mode” section on page 10-29
.
•
You must configure the voice VLAN for the IP phone when the host mode is set to multidomain. For
more information, see
Chapter 15, “Configuring Voice VLAN.”
Note
If you use a dynamic VLAN to assign a voice VLAN on an MDA-enabled switch port, the voice
device fails authorization.
•
To authorize a voice device, the AAA server must be configured to send a Cisco Attribute-Value
(AV) pair attribute with a value of
device-traffic-class=voice
. Without this value, the switch
treats the voice device as a data device.
•
The guest VLAN and restricted VLAN features only apply to the data devices on an MDA-enabled
port. The switch treats a voice device that fails authorization as a data device.
•
If more than one device attempts authorization on either the voice or the data domain of a port, it is
error disabled.
•
Until a device is authorized, the port drops its traffic. Non-Cisco IP phones or voice devices are
allowed into both the data and voice VLANs. The data VLAN allows the voice device to contact a
DHCP server to obtain an IP address and acquire the voice VLAN information. After the voice
device starts sending on the voice VLAN, its access to the data VLAN is blocked.
•
A voice device MAC address that is binding on the data VLAN is not counted towards the port
security MAC address limit.
•
You can use dynamic VLAN assignment from a RADIUS server only for data devices.
•
MDA can use MAC authentication bypass as a fallback mechanism to allow the switch port to
connect to devices that do not support IEEE 802.1x authentication. For more information, see the
“MAC Authentication Bypass” section on page 10-25
.
•
When a
data
or a
voice
device is detected on a port, its MAC address is blocked until authorization
succeeds. If the authorization fails, the MAC address remains blocked for 5 minutes.
•
If more than five devices are detected on the
data
VLAN or more than one voice device is detected
on the
voice
VLAN while a port is unauthorized, the port is error disabled.
Содержание 3750G - Catalyst Integrated Wireless LAN Controller
Страница 80: ...1 28 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 1 Overview Where to Go Next ...
Страница 606: ...27 8 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 27 Configuring UDLD Displaying UDLD Status ...
Страница 670: ...31 18 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 31 Configuring SNMP Displaying SNMP Status ...
Страница 1048: ...41 20 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 41 Configuring MSDP Monitoring and Maintaining MSDP ...
Страница 1086: ...43 26 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 43 Troubleshooting Using the crashinfo Files ...
Страница 1104: ...B 4 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Appendix B Supported MIBs Using FTP to Access the MIB Files ...