EasyManua.ls Logo

Cisco Catalyst 4500 Series - Cisco AV Pair Configuration

Cisco Catalyst 4500 Series
1610 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
44-86
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
OL-25340-01
Chapter 44 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Port-Based Authentication
When CISP is enabled on a trunk port, the following features are inert. When CISP is neither running
nor configured, these features operate as expected:
VLAN assignment
Guest, Authentication Failure, voice, and critical VLANs
Critical authentication
Wake-on-LAN
Web authentication
Port security
Violation modes (restrict, shut down, and shut down VLAN)
The following example shows how to enable CISP on a port. You must configure the following procedure
in the Cisco ACS server. Configuring a user with Cisco AV Pair value, allows SSW to authenticate itself
with the ASW. Because the user is attached with the AV pair value, upon successful authentication on
ASW, the macro is executed on the interface on which SSW is authenticated:
Switch# configure terminal
Switch(config)# cisp enable
Switch(config)# interface GigabitEthernet5/23
Switch(config-if)# switchport mode access
Switch(config-if)# spanning-tree portfast
Switch(config-if)# dot1x pae authenticator
Switch(config-if)# authentication port-control auto
Cisco AV Pair Configuration
Next, you need to configure a Cisco AV pair value.
Log into ACS, and Select/Create a User. Go to User Setup and scroll down to the [009\001]
cisco-av-pair Tab. Enter device-traffic-class=switch (Figure 44-17).

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Related product manuals