9-25
Catalyst 2960 Switch Software Configuration Guide
OL-8603-04
Chapter 9 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
You also need to configure some settings on the RADIUS server. These settings include the IP address
of the switch and the key string to be shared by both the server and the switch. For more information,
see the RADIUS server documentation.
Configuring the Host Mode
Beginning in privileged EXEC mode, follow these steps to allow a single host (client) or multiple hosts
on an IEEE 802.1x-authorized port that has the dot1x port-control interface configuration command set
to auto. This procedure is optional.
To disable multiple hosts on the port, use the no dot1x host-mode multi-host interface configuration
command.
This example shows how to enable IEEE 802.1x authentication and to allow multiple hosts:
Switch(config)# interface gigabitethernet/0/1
Switch(config-if)# dot1x port-control auto
Switch(config-if)# dot1x host-mode multi-host
Switch(config-if)# end
Configuring Periodic Re-Authentication
You can enable periodic IEEE 802.1x client re-authentication and specify how often it occurs. If you do
not specify a time period before enabling re-authentication, the number of seconds between attempts
is 3600.
Command Purpose
Step 1
configure terminal Enter global configuration mode.
Step 2
radius-server vsa send authentication Configure the network access server to recognize and use vendor-specific
attributes (VSAs).
Step 3
interface interface-id Specify the port to which multiple hosts are indirectly attached, and enter
interface configuration mode.
Step 4
dot1x host-mode {single-host |
multi-host}
The keywords have these meanings:
• single-host–Allow a single host (client) on an
IEEE 802.1x-authorized port.
• multi-host–Allow multiple hosts on an IEEE 802.1x-authorized port
after a single host has been authenticated.
Make sure that the dot1x port-control interface configuration command
set is set to auto for the specified interface.
Step 5
switchport voice vlan vlan-id (Optional) Configure the voice VLAN.
Step 6
end Return to privileged EXEC mode.
Step 7
show dot1x interface interface-id Verify your entries.
Step 8
copy running-config startup-config (Optional) Save your entries in the configuration file.