49-69
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 49 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Port-Based Authentication
For details, refer to the
“Enabling 802.1X Authentication” section on page 49-29
.
show commands
Use the following
show
commands to display the member VLANs in a VLAN group:
The following examples show outputs of the
show vlan group
command:
Switch#
show vlan group all
Group Name VLANs Mapped
---------------- -------------------
eng-dept 3-4
Switch#
show vlan group group-name
my_group
user-count
VLAN : Count
-------------------
3 : 1
4 : 0
5 : 2
7 : 0
9 : 0
Switch#
In this example, VLANs 3,4, 5, 7, and 9 are members of the VLAN group
my group
.
ACS Configuration
After configuring the switch, you must provide the VLAN group name in the ACS configuration.
By default, ACS sends only one VLAN name or group per user. However, you can configure ACS to send more than one tag
per attribute. To do this, you must modify the configuration in ACS for user or group. (See the example shown in
.)
show command
Purpose
show vlan group all
Displays the member VLANs for all the VLAN
groups configured on the device.
show vlan group group-name
vlan-group-name
Displays the member VLANs in a VLAN group
with the given VLAN group name.
show vlan group group-name
vlan-group-name
user-count
Displays the user count for each of the member
VLANs of the specified VLAN group
This feature counts only authenticated users and
MAC addresses added through port security for
distribution. It does not consider other learned
MAC addresses. As of Cisco IOS Release
12.2(54)SG, the user count for a VLAN is
incremented when a host is learned through port
security, 802.1X, MAB, or fallback authentication
on that VLAN.
Содержание Catalyst 4500 Series
Страница 2: ......
Страница 4: ......
Страница 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...