9-31
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
OL-12247-04
Chapter 9 Configuring IEEE 802.1x Port-Based Authentication
Configuring 802.1x Authentication
Figure 9-6
Authenticator and Supplicant Switch using CISP
Guidelines
•
You can configure NEAT ports with the same configurations as the other authentication ports. When
the supplicant switch authenticates, the port mode is changed from
access
to
trunk
based on the
switch vendor-specific attributes (VSAs). (
device-traffic-class=switch).
•
The VSA changes the authenticator switch port mode from access to trunk and enables 802.1x trunk
encapsulation and the access VLAN if any would be converted to a native trunk VLAN. VSA does
not change any of the port configurations on the supplicant
•
To change the host mode
and
the apply a standard port configuration on the authenticator switch
port, you can also use AutoSmart ports user-defined macros, instead of the switch VSA. This allows
you to remove unsupported configurations on the authenticator switch port and to change the port
mode from
access
to
trunk
. For more information, see
Chapter 12, “Configuring Smartports
For more information, see the
“Configuring an Authenticator and a Supplicant Switch with NEAT”
.
Configuring 802.1x Authentication
These sections contain this configuration information:
•
Default 802.1x Authentication Configuration, page 9-32
•
802.1x Authentication Configuration Guidelines, page 9-34
•
Configuring 802.1x Authentication, page 9-37
(required)
•
Configuring 802.1x Readiness Check, page 9-39
•
Configuring 802.1x Violation Modes, page 9-36
•
Configuring Voice Aware 802.1x Security, page 9-40
•
Configuring the Switch-to-RADIUS-Server Communication, page 9-41
(required)
•
Configuring the Host Mode, page 9-42
(optional)
1
Workstations (clients)
2
Supplicant switch (outside wiring closet)
3
Authenticator switch
4
Access control server (ACS)
5
Trunk port
20571
8
1
2
3
5
4