EasyManuals Logo

Cisco 3750G - Catalyst Integrated Wireless LAN Controller User Manual

Cisco 3750G - Catalyst Integrated Wireless LAN Controller
1204 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #269 background imageLoading...
Page #269 background image
10-15
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Understanding IEEE 802.1x Port-Based Authentication
Using IEEE 802.1x Authentication with Inaccessible Authentication Bypass
In Cisco IOS Release 12.2(25)SED and later, when the switch cannot reach the configured RADIUS
servers and hosts cannot be authenticated, you can configure the switch to allow network access to the
hosts connected to critical ports. A critical port is enabled for the inaccessible authentication bypass
feature, also referred to as critical authentication or the AAA fail policy.
When this feature is enabled, the switch checks the status of the configured RADIUS servers whenever
the switch tries to authenticate a host connected to a critical port. If a server is available, the switch can
authenticate the host. However, if all the RADIUS servers are unavailable, the switch grants network
access to the host and puts the port in the critical-authentication state, which is a special case of the
authentication state.
The behavior of the inaccessible authentication bypass feature depends on the authorization state of the
port:
• If the port is unauthorized when a host connected to a critical port tries to authenticate and all servers
are unavailable, the switch puts the port in the critical-authentication state in the
RADIUS-configured or user-specified access VLAN.
• If the port is already authorized and re-authentication occurs, the switch puts the critical port in the
critical-authentication state in the current VLAN, which might be the one previously assigned by
the RADIUS server.
• If the RADIUS server becomes unavailable during an authentication exchange, the current
exchanges times out, and the switch puts the critical port in the critical-authentication state during
the next authentication attempt.
When a RADIUS server that can authenticate the host is available, all critical ports in the
critical-authentication state are automatically re-authenticated.
Inaccessible authentication bypass interacts with these features:
• Guest VLAN—Inaccessible authentication bypass is compatible with guest VLAN. When a guest
VLAN is enabled on IEEE 8021.x port, the features interact as follows:
–
If at least one RADIUS server is available, the switch assigns a client to a guest VLAN when
the switch does not receive a response to its EAP request/identity frame or when EAPOL
packets are not sent by the client.
–
If all the RADIUS servers are not available and the client is connected to a critical port, the
switch authenticates the client and puts the critical port in the critical-authentication state in the
RADIUS-configured or user-specified access VLAN.
–
If all the RADIUS servers are not available and the client is not connected to a critical port, the
switch might not assign clients to the guest VLAN if one is configured.
–
If all the RADIUS servers are not available and if a client is connected to a critical port and was
previously assigned to a guest VLAN, the switch keeps the port in the guest VLAN.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 3750G - Catalyst Integrated Wireless LAN Controller and is the answer not in the manual?

Cisco 3750G - Catalyst Integrated Wireless LAN Controller Specifications

General IconGeneral
Switching Capacity32 Gbps
RAM128 MB
Flash Memory32 MB
Power DeviceInternal power supply
Ports48 x 10/100/1000 + 4 x SFP
Performance38.7 Mpps
Wireless LAN Controller Capacity50
StackingYes
FeaturesVLAN support, QoS
Compliant StandardsIEEE 802.3, IEEE 802.3u, IEEE 802.3ab, IEEE 802.3z
Operating Humidity10% to 85% non-condensing
Power over Ethernet (PoE)Yes (optional)

Related product manuals