EasyManuals Logo

Cisco Catalyst 2960-XR User Manual

Cisco Catalyst 2960-XR
404 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #298 background imageLoading...
Page #298 background image
PurposeCommand or Action
(Optional) Configures the parameters for inaccessible authentication bypass:dot1x critical {eapol | recovery delay
milliseconds}
Step 5
eapolSpecifies that the switch sends an EAPOL-Success message when the
switch successfully authenticates the critical port.
Example:
Switch(config)# dot1x critical eapol
recovery delay millisecondsSets the recovery delay period during which
the switch waits to re-initialize a critical port when a RADIUS server that was
recovery delay 2000
unavailable becomes available. The range is from 1 to 10000 milliseconds.
The default is 1000 milliseconds (a port can be re-initialized every second).
Specify the port to be configured, and enter interface configuration mode.
interface interface-id
Example:
Switch(config)# interface
Step 6
gigabitethernet 1/0/1
Moves hosts on the port if the RADIUS server is unreachable:authentication event server dead action
{authorize | reinitialize} vlan vlan-id]
Step 7
authorizeMoves any new hosts trying to authenticate to the
user-specified critical VLAN.
Example:
Switch(config-if)# authentication
reinitializeMoves all authorized hosts on the port to the user-specified
critical VLAN.
event server dead action
reinitialize vlan 5
Enables the inaccessible authentication bypass feature, and use these keywords
to configure the feature:
dot1x critical [recovery action
reinitialize | vlan vlan-id]
Step 8
Example:
Switch(config-if)# dot1x critical
authorizeAuthorizes the port.
reinitializeReinitializes all authorized clients.
recovery action reinitialize
Returns to privileged EXEC mode.end
Example:
Switch(config-if)# end
Step 9
Example of Configuring Inaccessible Authentication Bypass
This example shows how to configure the inaccessible authentication bypass feature:
Switch(config)# radius-server dead-criteria time 30 tries 20
Switch(config)# radius-server deadtime 60
Switch(config)# radius-server host 1.1.1.2 acct-port 1550 auth-port 1560 test username user1
idle-time 30 key abc1234
Switch(config)# dot1x critical eapol
Switch(config)# dot1x critical recovery delay 2000
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
276 OL-29434-01
Configuring IEEE 802.1x Port-Based Authentication
Configuring the Inaccessible Authentication Bypass Feature

Table of Contents

Other manuals for Cisco Catalyst 2960-XR

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 2960-XR and is the answer not in the manual?

Cisco Catalyst 2960-XR Specifications

General IconGeneral
Stacking Bandwidth80 Gbps
Layer SupportLayer 2 and Layer 3
Jumbo Frame Support9198 bytes
RAM512 MB
Input Voltage100-240V AC
ModelCatalyst 2960-XR
Uplink Interfaces4 x 1G SFP or 2 x 10G SFP+
Downlink Interfaces24 or 48 x Gigabit Ethernet ports
Power SupplyInternal
MAC Address Table Size16, 000 entries
PoEAvailable on PoE models
Weight4.5 kg
Featuresenergy efficiency
StackingUp to 8 switches
Operating Temperature0 to 45°C

Related product manuals