10-26
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
•
In Cisco IOS Release 12.2(35)SE and later, you can configure a timeout period for hosts that are
connected by MAC authentication bypass but are inactive. The range is 1-65535 seconds. You must
enable port security before configuring a time out value. For more information, see the
“Configuring
Port Security” section on page 25-8
.
Upgrading from a Previous Software Release
In Cisco IOS Release 12.1(14)EA1, the implementation for IEEE 802.1x authentication changed from
the previous release. Some global configuration commands became interface configuration commands,
and new commands were added.
If you have IEEE 802.1x authentication configured on the switch and you upgrade to Cisco IOS Release
12.1(14)EA1 or later, the configuration file will not contain the new commands, and IEEE 802.1x
authentication will not operate. After the upgrade is complete, make sure to globally enable IEEE 802.1x
authentication by using the
dot1x system-auth-control
global configuration command. If IEEE 802.1x
authentication was running in multiple-hosts mode on a port in the previous release, make sure to
reconfigure it by using the
dot1x host-mode multi-host
interface configuration command.
In Cisco IOS Release 12.2(25)SEE, the implementation for IEEE 802.1x authentication changed from
the previous releases. When IEEE 802.1x authentication is enabled, information about Port Fast is no
longer added to the configuration and this information appears in the running configuration:
dot1x pae authenticator
Configuring IEEE 802.1x Authentication
To configure IEEE 802.1x port-based authentication, you must enable authentication, authorization, and
accounting (AAA) and specify the authentication method list. A method list describes the sequence and
authentication method to be queried to authenticate a user.
To allow per-user ACLs or VLAN assignment, you must enable AAA authorization to configure the
switch for all network-related service requests.
This is the IEEE 802.1x AAA process:
Step 1
A user connects to a port on the switch.
Step 2
Authentication is performed.
Step 3
VLAN assignment is enabled, as appropriate, based on the RADIUS server configuration.
Step 4
The switch sends a start message to an accounting server.
Step 5
Re-authentication is performed, as necessary.
Step 6
The switch sends an interim accounting update to the accounting server that is based on the result of
re-authentication.
Step 7
The user disconnects from the port.
Step 8
The switch sends a stop message to the accounting server.
Содержание 3750G - Catalyst Integrated Wireless LAN Controller
Страница 80: ...1 28 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 1 Overview Where to Go Next ...
Страница 606: ...27 8 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 27 Configuring UDLD Displaying UDLD Status ...
Страница 670: ...31 18 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 31 Configuring SNMP Displaying SNMP Status ...
Страница 1048: ...41 20 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 41 Configuring MSDP Monitoring and Maintaining MSDP ...
Страница 1086: ...43 26 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Chapter 43 Troubleshooting Using the crashinfo Files ...
Страница 1104: ...B 4 Catalyst 3750 Switch Software Configuration Guide OL 8550 02 Appendix B Supported MIBs Using FTP to Access the MIB Files ...