
MES3000 Ethernet switch series
173
no dot1x max-req
Restore the default value.
dot1x timeout supp-
timeout
period
1..65535/30 seconds
Specify the period between the recurrent request transfers to EAP
client.
no dot1x timeout supp-
timeout
Restore the default value.
dot1x timeout server-
timeout
period
1..65535/30 seconds
Specify the period, during which the switch will wait for response
from authentication server.
no dot1x timeout server-
timeout
Restore the default value.
Privileged EXEC mode commands
Command line request in Privileged EXEC mode appears as follows:
console#
Table 5.202 —Privileged EXEC mode commands
Command
Value
Action
dot1x re-authenticate
[gigabitethernet
gi_port
|
tengigabitethernet
te_port
]
gi_port: (1..8/0/1..24);
te_port: (1..8/0/1..4)
Enable manual re-authentication of the port specified in the
command, or all ports supporting 802.1X.
show dot1x interface
{gigabitethernet
gi_port
|
tengigabitethernet
te_port
}
gi_port: (1..8/0/1..24);
te_port: (1..8/0/1..4)
Show IEEE 802.1X state for the switch or selected interface.
show dot1x users
[username
username
]
(1..160) characters
Show active authenticated IEEE 802.1X switch users.
show dot1x statistics
interface {gigabitethernet
gi_port
|
tengigabitethernet
te_port
}
gi_port: (1..8/0/1..24);
te_port: (1..8/0/1..4)
Show IEEE 802.1X statistics for the selected interface.
Example execution of commands
Enable IEEE 802.1X authentication mode on the switch. Use RADIUS server for client
authentication checks on IEEE 802.1X interfaces. Use IEEE 802.1x authentication mode on the
Ethernet interface 18.
console#
configure
console(config)#
dot1x system-auth-control
console(config)#
aaa authentication dot1x default radius
console(config)#
interface gigabitethernet
1/0/18
console(config-if)#
dot1x port-control
auto
Show IEEE 802.1X state for the switch, for the Ethernet interface 12.
console#
show dot1x
802.1x is disabled
Admin Oper Reauth Reauth Username
Port Mode Mode Control Period
-------- ------------------ ------------- -------- ---------- -----------------
gi0/1 Force Authorized Authorized* Disabled 3600 n/a
gi0/2 Force Authorized Authorized* Disabled 3600 n/a
gi0/3 Force Authorized Authorized* Disabled 3600 n/a
gi0/4 Force Authorized Authorized* Enabled 3600 n/a
gi0/5 Force Authorized Authorized* Disabled 3600 n/a
…
gi0/10 Force Authorized Authorized* Disabled 3600 n/a
gi0/11 Force Authorized Authorized Disabled 3600 n/a