EasyManuals Logo

Cisco Catalyst 2950 Command Reference

Cisco Catalyst 2950
686 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #121 background imageLoading...
Page #121 background image
2-91
Catalyst 2950 and Catalyst 2955 Switch Command Reference
OL-10102-01
Chapter 2 Catalyst 2950 and 2955 Cisco IOS Commands
dot1x auth-fail vlan
When a restricted VLAN port is moved to an unauthorized state, the authentication process is restarted.
If the user fails the authentication process again, the authenticator waits in the held state. After the user
has correctly re-authenticated, all IEEE 802.1x ports are reinitialized and treated as normal IEEE 802.1x
ports.
When you reconfigure a restricted VLAN to a different VLAN, any ports in the restricted VLAN are also
moved, and the ports stay in their current authorized state.
When you shut down or remove a restricted VLAN from the VLAN database, any ports in the restricted
VLAN are immediately moved to an unauthorized state, and the authentication process is restarted. The
authenticator does not wait in a held state because the restricted VLAN configuration still exists. While
the restricted VLAN is inactive, all authentication attempts are counted. As soon as the restricted VLAN
becomes active, the port is placed in the restricted VLAN.
The restricted VLAN is supported only in single-host mode (the default port mode).
When a port is placed in a restricted VLAN, the users MAC address is added to the MAC address table.
If a new MAC address appears on the port, it is treated as a security violation.
Examples This example shows how to configure a restricted VLAN on Gigabit Ethernet interface 1:
Switch# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)# interface gigabitethernet0/1
Switch(config-if)# dot1x auth-fail vlan 40
Switch(config-if)# end
Switch(config)# end
Switch#
You can verify your configuration by entering the show dot1x [interface interface-id] privileged EXEC
command.
Related Commands Command Description
dot1x auth-fail max-attempts
[max-attempts]
Configures the number of authentication attempts allowed
before assigning a user to the restricted VLAN.
show dot1x [interface interface-id] Displays IEEE 802.1x status for the specified port.

Table of Contents

Other manuals for Cisco Catalyst 2950

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 2950 and is the answer not in the manual?

Cisco Catalyst 2950 Specifications

General IconGeneral
Forwarding Bandwidth8.8 Gbps
Switching Capacity13.6 Gbps
Forwarding Rate6.6 Mpps
Weight3.6 kg
RAM16 MB
Flash Memory8 MB
Operating Humidity10% to 85% non-condensing
Uplink Ports2 x 10/100/1000Base-T
Dimensions4.4 cm x 44.5 cm x 24.2 cm
Remote Management ProtocolSNMP, Telnet, HTTP
FeaturesQuality of Service (QoS), VLAN support
Compliant StandardsIEEE 802.3, IEEE 802.3u, IEEE 802.1D, IEEE 802.1Q, IEEE 802.1p
Status Indicatorssystem
Operating Temperature0 to 45°C
Ports24 x 10/100 Ethernet ports
MAC Address Table Size8, 192 entries
Power SupplyInternal 100-240V AC, 50-60Hz

Related product manuals