
31-13
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 31 Configuring 802.1x Authentication
Configuring 802.1x Authentication on the Switch
Console> (enable) show port dot1x 4/1
Port Auth-State BEnd-State Port-Control Port-Status
----- ------------------- ---------- ------------------- -------------
4/1 connecting finished auto unauthorized
Port Multiple Host Re-authentication
----- ------------- -----------------
4/1 disabled enabled
Manually Reauthenticating the Host
You can manually reauthenticate the host that is connected to a specific port at any time. When you want
to configure automatic 802.1x host reauthentication, see the
“Setting and Enabling Automatic
Reauthentication of the Host” section on page 31-12
.
To manually reauthenticate a host that is connected to a specific port, perform this task in privileged
mode:
This example shows how to manually reauthenticate the host that is connected to port 1 on module 4:
Console> (enable) set port dot1x 4/1 re-authenticate
Port 4/1 re-authenticating...
dot1x re-authentication successful...
dot1x port 4/1 authorized.
Enabling Multiple Hosts
You can enable a specific port to allow multiple users. When a port is enabled for multiple users, and a
host that is connected to that port is authorized successfully, any host (with any MAC address) is allowed
to send and receive traffic on that port. If you connect multiple hosts to that port through a hub, you can
reduce the security level on that port.
To enable access for multiple users on a specific port, perform this task in privileged mode:
This example shows how to enable access for multiple hosts on port 1 on module 4:
Console> (enable) set port dot1x 4/1 multiple-host enable
Port 4/1 multiple hosts allowed.
Task
Command
Manually reauthenticate the host that is connected
to a specific port.
set port dot1x mod/port re-authenticate
Task
Command
Enable multiple hosts on a specific port.
set port dot1x mod/port multiple-host enable