49-40
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 49 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Port-Based Authentication
The following show authentication sessions command displays the authentication sessions that contains the downloadable
ACL obtained from ACS:
Note The show epm command will be deprecated, displaying a warning message when used. Use the show
authentication sessions command instead.
Switch-2033# show authentication sessions interface g2/9 details
Interface: GigabitEthernet2/9
MAC Address: 2c54.2d6a.0345
IPv6 Address: Unknown
IPv4 Address: 8.8.8.11
User-Name: 2C-54-2D-6A-03-45
Status: Authorized
Domain: DATA
Oper host mode: multi-auth
Oper control dir: both
Session timeout: N/A
Common Session ID: 0404040400000610081AA183
Acct Session ID: 0x000006F2
Handle: 0x760005B9
Current Policy: POLICY_Gi2/9
Server Policies:
ACS ACL: xACSACLx-IP-PERMIT_ALL_TRAFFIC-51de4498
Method status list:
Method State
mab Authc Success
The show authentication sessions interface interface-name policy displays session information in the form of Local
Policies(features defined locally on the box), Server policies(features downloaded from radius) and Resultant Policies(the one
with higher precedence when both local and server policies are present). By default, server policies have higher precedence
than those defined locally.
AUTH# show authentication sessions interface e0/0 policy
Interface: Ethernet0/0
MAC Address: aabb.cc01.ff00
IPv6 Address: Unknown
IPv4 Address: Unknown
User-Name: gupn
Status: Authorized
Domain: DATA
Security Policy: Should Secure
Security Status: Unsecure
Oper host mode: multi-host
Oper control dir: both
Session timeout: N/A
Common Session ID: 0D0102330000000D0003329A
Acct Session ID: Unknown
Handle: 0x6F000002
Current Policy: POLICY_Et0/0
Local Policies:
Template: SVC_1 (priority 10)
Idle timeout: 500 sec
TAG: blue
URL Redirect: www.a.com
URL Redirect ACL: a
Template: SVC_3 (priority 20)
Idle timeout: 300 sec