40-18
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 40 Configuring 802.1X Authentication
Configuring 802.1X Authentication on the Switch
This example shows how to set automatic reauthentication to 7200 seconds, enable 802.1X
reauthentication on port 3/1, and verify the configuration:
Console> (enable)
set dot1x re-authperiod 7200
dot1x re-authperiod set to 7200 seconds
Console> (enable)
set port dot1x 3/1 re-authentication enable
Port 3/1 Dot1x re-authentication enabled.
Console> (enable)
show port dot1x 3/1
Port Auth-State BEnd-State Port-Control Port-Status
----- ------------------- ---------- ------------------- -------------
3/1 connecting idle auto unauthorized
Port Port-Mode Re-authentication Shutdown-timeout Control-Mode
admin oper
----- ------------- ----------------- ---------------- ---------------
3/1 MultiAuth enabled disabled Both Both
Console> (enable)
Manually Reauthenticating the Host
You can manually reauthenticate the host that is connected to a specific port at any time. When you want
to configure automatic 802.1X host reauthentication, see the
“Setting and Enabling Automatic
Reauthentication of the Host” section on page 40-17
.
To manually reauthenticate a host that is connected to a specific port, perform this task in privileged
mode:
This example shows how to manually reauthenticate the host that is connected to port 1 on module 3:
Console> (enable)
set port dot1x 3/1 re-authenticate
Port 3/1 re-authenticating...
dot1x re-authentication successful...
dot1x port 3/1 authorized.
Console> (enable)
Enabling Multiple Hosts
You can enable a specific port to allow multiple-user access. When a port is enabled for multiple users,
and a host that is connected to that port is authorized successfully, any host (with any MAC address) is
allowed to send and receive the traffic on that port. If you connect multiple hosts to that port through a
hub, you can reduce the security level on that port.
To enable access for multiple hosts on a specific port, perform this task in privileged mode:
Task
Command
Manually reauthenticate the host that is connected
to a specific port.
set port dot1x
mod/port
re-authenticate
Task
Command
Enable multiple hosts on a specific port.
set port dot1x
mod/port
multiple-host enable