40-46
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 40 Configuring 802.1X Authentication
Configuring 802.1X Authentication on the Switch
Example1: Guest VLAN is an isolated private VLAN (VLANs 400, 401)
Console> (enable)
show port 2/2
* = Configured MAC Address
# = 802.1X Authenticated Port Name.
Port Name Status Vlan Duplex Speed Type
----- -------------------- ---------- ---------- ------ ----------- ------------
2/2 connected guest-400,401 a-half a-10 10/100BaseTX
<...snip...>
Console> (enable)
show port dot1x 2/2
Port Auth-State BEnd-State Port-Control Port-Status
----- ------------------- ---------- ------------------- -------------
2/2 guest-vlan idle auto authorized
<...snip...>
Console> (enable)
show pvlan
Primary Secondary Secondary-Type Ports
------- --------- ---------------- ------------
200 201 twoway-community
400 401 isolated 2/2
800 801 community
Console> (enable)
Example 2: 802.1X authentication failure VLAN is a two-way community private VLAN (VLANs 200, 201)
Console> (enable)
show port 2/2
* = Configured MAC Address
# = 802.1X Authenticated Port Name.
Port Name Status Vlan Duplex Speed Type
----- -------------------- ---------- ---------- ------ ----------- ------------
2/2 connected fail-200,201 a-half a-10 10/100BaseTX
<...snip...>
Console> (enable)
clear port dot1x 2/2
dot1x port statistics cleared successfully for port
Console> (enable)
show port dot1x 2/2
Port Auth-State BEnd-State Port-Control Port-Status
----- ------------------- ---------- ------------------- -------------
2/2 auth-fail idle auto authorized
<...snip...>
Console> (enable)
show pvlan
Primary Secondary Secondary-Type Ports
------- --------- ---------------- ------------
200 201 twoway-community 2/2
400 401 isolated
800 801 community
Console> (enable)
Example 3: 802.1X RADIUS-supplied VLAN is a community private VLAN (VLANs 800, 801)
Console> (enable)
show port 2/2
* = Configured MAC Address
# = 802.1X Authenticated Port Name.
Port Name Status Vlan Duplex Speed Type
----- -------------------- ---------- ---------- ------ ----------- ------------
2/2 connected dot1x-800,801 a-half a-10 10/100BaseTX
Port AuxiliaryVlan AuxVlan-Status
----- ------------- --------------
2/2 none none
Port Security Violation Shutdown-Time Age-Time Max-Addr Trap IfIndex
----- -------- --------- ------------- -------- -------- -------- -------
2/2 disabled shutdown 0 0 1 disabled 61
Port Flooding on Address Limit Last-Src-Addr Vlan TimerType
----- ------------------------- ----------------- ---- ----------