10-11
Catalyst 3750 Switch Software Configuration Guide
78-16180-02
Chapter 10 Configuring 802.1x Port-Based Authentication
Configuring 802.1x Authentication
• Configuring the Switch-to-RADIUS-Server Communication, page 10-15 (required)
• Configuring Periodic Re-Authentication, page 10-16 (optional)
• Manually Re-Authenticating a Client Connected to a Port, page 10-16 (optional)
• Changing the Quiet Period, page 10-17 (optional)
• Changing the Switch-to-Client Retransmission Time, page 10-17 (optional)
• Setting the Switch-to-Client Frame-Retransmission Number, page 10-18 (optional)
• Configuring the Host Mode, page 10-19 (optional)
• Configuring a Guest VLAN, page 10-20 (optional)
• Resetting the 802.1x Configuration to the Default Values, page 10-21 (optional)
• Configuring 802.1x Accounting, page 10-21 (optional)
Default 802.1x Configuration
Table 10-1 shows the default 802.1x configuration.
Table 10-1 Default 802.1x Configuration
Feature Default Setting
AAA Disabled.
RADIUS server
• IP address
• UDP authentication port
• Key
• None specified.
• 1812.
• None specified.
Switch 802.1x enable state Disabled.
Per-port 802.1x enable state Disabled (force-authorized).
The port sends and receives normal traffic without
802.1x-based authentication of the client.
Periodic re-authentication Disabled.
Number of seconds between
re-authentication attempts
3600 seconds.
Re-authentication number 2 times (number of times that the switch restarts the
authentication process before the port changes to the
unauthorized state).
Quiet period 60 seconds (number of seconds that the switch remains in
the quiet state following a failed authentication exchange
with the client).
Retransmission time 30 seconds (number of seconds that the switch should
wait for a response to an EAP request/identity frame
from the client before resending the request).
Maximum retransmission number 2 times (number of times that the switch will send an
EAP-request/identity frame before restarting the
authentication process).