44-25
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 44 Configuring Network Admission Control
Configuring Network Admission Control with LAN Port IP
The following sections describe how to configure IAB:
•
Enabling and Disabling Inaccessible Authentication Bypass, page 44-25
•
Setting the AAA Fail Policy, page 44-25
•
Setting the RADIUS Keepalive Timer, page 44-26
•
Setting the RADIUS Auto-Initialize Feature, page 44-26
•
Displaying the Critical Status of Features on a Port, page 44-27
•
Displaying the AAA Fail Policy on a Port, page 44-27
•
Displaying RADIUS Server Information, page 44-27
•
Displaying the MAC Authorization Bypass Settings on a Port, page 44-28
•
Displaying the Web Authorization Settings on a Port, page 44-28
•
Displaying the EOU Settings on a Port, page 44-29
•
Clearing Policy Mapping on a Port, page 44-29
Enabling and Disabling Inaccessible Authentication Bypass
To enable or disable IAB, perform this task in enable mode:
This example shows how to enable IAB:
Console> (enable)
set port critical 5/1 enable
Port, 5/1 Critical feature enabled.
Console> (enable)
This example shows how to enable IAB:
Console> (enable)
set port critical 5/1 disable
Port, 5/1 Critical feature disabled.
Console> (enable)
Setting the AAA Fail Policy
To set the AAA fail policy, perform this task in enable mode:
This example shows how to set AAA fail policy for EOU:
Console> (enable)
set port eou 12/1 aaa-fail-policy critical-eou-policy
Policy critical-eou-policy mapped as aaa-fail-policy on port 12/1
Console> (enable)
To set web-based proxy authentication on a port, perform this task in enable mode:
Task
Command
Enable or disable IAB
set port critical
mod/port
[disable | enable]
Task
Command
Set the AAA fail policy.
set port eou
mod/port
aaa-fail-policy
policy-name