Verifying Access Guardian Users Configuring Access Guardian
page 34-42 OmniSwitch AOS Release 6 Network Configuration Guide September 2009
Verifying Access Guardian Users
The following set of show aaa-device commands provide a centralized way to verify the status of users
authenticated and classified through Access Guardian security mechanisms:
1 The show aaa-device all-users command displays the Access Guardian status of all users learned on
802.1x ports:
-> show aaa-device all-users
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
1/1 00:11:50:a6:12:00 User101 100 Brdg 10.133.0.100 1X Pass Marketing
1/1 00:11:50:a6:12:01 User101 100 Brdg 10.133.0.101 1X Pass Marketing
1/1 00:11:50:a6:12:02 User101 100 Brdg 10.133.0.102 1X Pass Marketing
1/1 00:11:50:a6:12:03 User101 100 Brdg 10.133.0.103 1X Pass Marketing
1/1 00:1a:50:a6:12:50 -- 100 Blk 10.133.2.128 None N/A engr_no_internet
1/1 00:1a:50:a6:12:51 -- 100 Blk 10.133.2.129 None N/A engr_no_internet
1/1 00:1a:50:a6:12:52 -- 100 Blk 10.133.2.130 None N/A engr_no_internet
1/1 00:1a:50:a6:12:53 -- 100 Blk 10.133.2.131 None N/A engr_no_internet
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
1/2 00:00:39:47:4f:0c pc2006 1000 Brdg - 1X Pass Marketing
1/2 00:b0:d0:77:fa:72 -- 1000 Brdg - MAC Pass Marketing
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
5/9 00:90:27:17:91:a8 pc2006 1000 Brdg - 1X Pass engr
5/9 00:00:39:93:46:0c -- 1 Blk - MAC Fail -
2 The show aaa-device supplicant-users command displays the Access Guardian status of all suppli-
cant (802.1x) users learned on the switch:
-> show aaa-device supplicant-users
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
1/1 00:11:50:a6:12:00 User101 100 Brdg 10.133.0.100 1X Pass Marketing
1/1 00:11:50:a6:12:01 User101 100 Brdg 10.133.0.101 1X Pass Marketing
1/1 00:11:50:a6:12:02 User101 100 Brdg 10.133.0.102 1X Pass Marketing
1/1 00:11:50:a6:12:03 User101 100 Brdg 10.133.0.103 1X Pass Marketing
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
1/2 00:00:39:47:4f:0c pc2006 1000 Brdg - 1X Pass Marketing
Slot MAC User Addr IP Authentication User Network
Port Address Name VLAN Mode Address Type Result Profile Name
---+------------------+-----------+----+----+------------+---+----+--------------
5/9 00:90:27:17:91:a8 pc2006 1000 Brdg - 1X Pass engr
5/9 00:00:39:93:46:10 -- 1 Blk - 1X Fail -