211
Configuring IEEE 802.1x Port-Based Authentication
Information About Configuring IEEE 802.1x Port-Based Authentication
For more configuration information, see
Authentication Manager, page 194
.
Cisco IOS Release 12.2(55)SE and later supports filtering of verbose MAB system messages. See
Manager CLI Commands, page 195
.
802.1x User Distribution
You can configure 802.1x user distribution to load-balance users with the same group name across multiple different
VLANs.
The VLANs are either supplied by the RADIUS server or configured through the switch CLI under a VLAN group name.
Configure the RADIUS server to send more than one VLAN name for a user. The multiple VLAN names can be sent
as part of the response to the user. The 802.1x user distribution tracks all the users in a particular VLAN and achieves
load balancing by moving the authorized user to the least populated VLAN.
Configure the RADIUS server to send a VLAN group name for a user. The VLAN group name can be sent as part of
the response to the user. You can search for the selected VLAN group name among the VLAN group names that you
configured by using the switch CLI. If the VLAN group name is found, the corresponding VLANs under this VLAN
group name are searched to find the least populated VLAN. Load balancing is achieved by moving the corresponding
authorized user to that VLAN.
Note:
The RADIUS server can send the VLAN information in any combination of VLAN-IDs, VLAN names, or VLAN
groups.
802.1x User Distribution Configuration Guidelines
Confirm that at least one VLAN is mapped to the VLAN group.
You can map more than one VLAN to a VLAN group.
You can modify the VLAN group by adding or deleting a VLAN.
When you clear an existing VLAN from the VLAN group name, none of the authenticated ports in the VLAN are
cleared, but the mappings are removed from the existing VLAN group.
If you clear the last VLAN from the VLAN group name, the VLAN group is cleared.
You can clear a VLAN group even when the active VLANs are mapped to the group. When you clear a VLAN group,
none of the ports or users that are in the authenticated state in any VLAN within the group are cleared, but the VLAN
mappings to the VLAN group are cleared.
For more information, see
Configuring 802.1x User Distribution, page 229
.
Network Admission Control Layer 2 802.1x Validation
The switch supports the Network Admission Control (NAC) Layer 2 802.1x validation, which checks the antivirus
condition or
posture
of endpoint systems or clients before granting the devices network access. With NAC Layer 2 802.1x
validation, you can do these tasks:
Download the Session-Timeout RADIUS attribute (Attribute[27]) and the Termination-Action RADIUS attribute
(Attribute[29]) from the authentication server.
Set the number of seconds between reauthentication attempts as the value of the Session-Timeout RADIUS attribute
(Attribute[27]) and get an access policy against the client from the RADIUS server.
Содержание IE 4000
Страница 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Страница 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Страница 108: ...104 Configuring Switch Clusters Additional References ...
Страница 128: ...124 Performing Switch Administration Additional References ...
Страница 130: ...126 Configuring PTP ...
Страница 140: ...136 Configuring CIP Additional References ...
Страница 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Страница 192: ...188 Configuring Switch Based Authentication Additional References ...
Страница 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Страница 274: ...270 Configuring SGT Exchange Protocol over TCP SXP and Layer 3 Transport Configuring Cisco TrustSec Caching ...
Страница 298: ...294 Configuring VLANs Additional References ...
Страница 336: ...332 Configuring STP Additional References ...
Страница 408: ...404 Configuring DHCP Additional References ...
Страница 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Страница 490: ...486 Configuring SPAN and RSPAN Additional References ...
Страница 502: ...498 Configuring Layer 2 NAT ...
Страница 559: ...555 Configuring Network Security with ACLs How to Configure Network Security with ACLs Creating a Numbered Extended ACL ...
Страница 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Страница 930: ...926 Configuring IP Unicast Routing Related Documents ...
Страница 956: ...952 Configuring IPv6 Unicast Routing Configuring IPv6 network 2010 AB8 2 48 network 2010 AB8 3 48 exit address family ...
Страница 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Страница 978: ...974 Dying Gasp ...
Страница 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Страница 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Страница 996: ...992 Ethernet CFM ...
Страница 1030: ...1026 Working with the Cisco IOS File System Configuration Files and Software Images Working with Software Images ...
Страница 1066: ...1062 Using an SD Card SD Card Alarms ...