xStack
®
DGS-3400 Series Layer 2 Gigabit Managed Switch CLI Manual
189
D G S – 3 4 2 6 : 5 # s h o w 8 0 2 . 1 x a u t h _ c o n f i g u r a t i o n p o r t s 1 : 1
C o m m a n d : s h o w 8 0 2 . 1 x a u t h _ c o n f i g u r a t i o n p o r t s 1 : 1
P o r t n u m b e r : 1 : 1
C a p a b i l i t y : N o n e
A d m i n C r l D i r : B o t h
O p e n C r l D i r : B o t h
P o r t C o n t r o l : A u t o
Q u i e t P e r i o d : 6 0 s e c
T x P e r i o d : 3 0 s e c
S u p p T i m e o u t : 3 0 s e c
S e r v e r T i m e o u t : 3 0 s e c
M a x R e q : 2 t i m e s
R e A u t h P e r i o d : 3 6 0 0 s e c
R e A u t h e n t i c a t e : D i s a b l e d
F o r w a r d E A P O L P D U O n P o r t : D i s a b l e d
M a x U s e r s O n p o r t : 1 6
C T R L + C
E S C
q
Q u i t
S P A C E
n
N e x t P a g e
E n t e r
N e x t E n t r y
a
A l l
show 802.1x auth_state ports
Purpose
Used to display the current authentication state of the 802.1X server on the Switch.
Syntax
show 802.1x auth_state ports <portlist>
Description
This command is used to display the current authentication state of the 802.1X Port–
based or MAC–based Network Access Control server application on the Switch.
Parameters
<portlist>
−
Specifies a port or range of ports to be viewed. The port list is specified by
listing the lowest switch number and the beginning port number on that switch, separated
by a colon. Then the highest switch number, and the highest port number of the range
(also separated by a colon) are specified. The beginning and end of the port list range are
separated by a dash. For example, 1:3 specifies switch number 1, port 3. 2:4 specifies
switch number 2, port 4. 1:3–2:4 specifies all of the ports between switch 1, port 3 and
switch 2, port 4
−
in numerical order. Non–contiguous portlist entries are separated by a
comma. (ex: 1:1–1:3,1:7–1:9)
The following details what is displayed:
Ports
−
Shows the physical port number on the Switch.
Restrictions None.
Example usage:
To display the 802.1X authentication state
If port 1 is in host-based mode:
MAC 00-00-00-00-00-01 is authenticated without VLAN assigned (may be the specified target VLAN does not
exist or target VLAN has not been specified at all), the ID of RX VLAN will be displayed (RX VLAN ID is
4004 in this example).
MAC 00-00-00-00-00-02 is authenticated with target VLAN assigned, the ID of target VLAN will be displayed
(target VLAN ID is 1234 in this example)
MAC 00-00-00-00-00-03 failed to pass authentication, the VID field will be shown as “-” indicating that packets
with SA 00-00-00-00-00-03 will be dropped no matter which VLAN these packets are from.
MAC 00-00-00-00-00-04 attempts to start authentication, the VID field will be shown as “-“ until authentication
completed.
If port 2 is in port-based mode:
MAC 00-00-00-00-00-10 is the MAC which made port 2 pass authentication, MAC address is followed by “(P)”
to indicate the port-based mode authentication.
If port 3 is linked_down.
Supposed that port 4 is in port-based mode: