40-42
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 40 Configuring 802.1X Authentication
Configuring 802.1X Authentication on the Switch
–
Used as a nonoperational port VLAN before the port reaches an 802.1X state (authenticated,
guest VLAN, or authentication failure VLAN)
–
Used as an operational VLAN in the authenticated state if no VLAN is provided by the RADIUS
server
–
Can be a private VLAN
•
The 802.1X VLAN behavior is as follows:
–
Used as an operational port VLAN after 802.1X moves the port to an 802.1X state
(authenticated, guest VLAN, or authentication failure VLAN)
–
Can be a private VLAN
Configuration Guidelines
This section provides the guidelines for configuring 802.1X authentication with private VLANs:
•
No changes to the existing CLI are required for configuring 802.1X authentication with private
VLANs.
•
When you add an 802.1X port to a VLAN (RADIUS-assigned VLAN, guest VLAN, or
authentication failure VLAN), the following checks are automatically made:
–
It is verified that the private VLAN is a secondary VLAN
–
It is verified that the secondary VLAN is associated to a valid primary VLAN
If any of the checks fail, an error message is generated and the port is not placed in the private
VLAN.
•
Promiscuous ports and the sc0 interface cannot participate in 802.1X.
•
When you configure an 802.1X port in a private VLAN, BPDU guard is automatically enabled,
trunking is set to off, and the port retains these settings after being removed from the private VLAN.
•
IP phone ports that support 802.1X cannot be private VLAN ports.
Configuring 802.1X Authentication with Private VLANs
These sections describe and provide examples on configuring 802.1X authentication with private
VLANs:
•
Creating Private VLANs, page 40-43
•
Verifying the Private VLAN Configuration, page 40-43
•
Verifying the Pre-802.1X Port Settings, page 40-44
•
Assigning Private VLANs to 802.1X, page 40-45
•
Verifying the Config-Time 802.1X Private VLAN Settings, page 40-45
•
Verifying the Run-Time 802.1X-Assigned Private VLAN Settings, page 40-45