
31-9
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 31 Configuring 802.1x Authentication
Authentication Default Configuration
Authentication Default Configuration
Table 31-2
shows the default configuration for authentication.
Authentication Configuration Guidelines
This section provides the guidelines for configuring 802.1x authentication on the switch:
•
802.1x will work with other protocols, but we recommend that you use RADIUS with a remotely
located authentication server.
•
802.1x is supported only on Ethernet ports.
•
You cannot enable 802.1x on a trunk port until you turn off trunking on that port. You cannot enable
trunking on an 802.1x port.
•
You cannot enable 802.1x on a dynamic port until you turn off DVLAN on that port. You cannot
enable DVLAN on an 802.1x port.
•
You cannot enable 802.1x on a channeling port until you turn off channeling on that port. You cannot
enable channeling on an 802.1x port.
•
You cannot enable 802.1x on a switched port analyzer (SPAN) destination port, and you cannot
configure SPAN destination on an 802.1x port. However, you can configure an 802.1x port as a
SPAN source port.
•
You cannot enable the multiple-authentication keyword on an 802.1x-enabled auxiliary VLAN
port. We do not recommend enabling the multiple-host keyword on an 802.1x-enabled auxiliary
port.
Table 31-2
802.1x Authentication Default Configuration
Feature
Default Value
802.1x port control
Force-Authorized
802.1x multiple hosts
Disabled
802.1x system authentication control
Enable
802.1x quiet period time
60 sec
802.1x authenticator to host retransmission time
30 sec
802.1x back-end authenticator to host
retransmission time
30 sec
802.1x back-end authenticator to authentication
server retransmission time
30 sec
802.1x number of frames that are retransmitted
from back-end authenticator to host
2 frames
802.1x automatic host reauthentication time
3600 sec
802.1x automatic authenticator reauthentication
of host
Disabled
802.1x shutdown timeout period
0 seconds