988 BigIron RX Series Configuration Guide
53-1002253-01
Displaying 802.1x information
33
When the dynamically assigned IP ACL is removed from the port, the display shows the following
information.
BigIron RX#show dot1x ip-acl ethernet 1/1
Port 1/1 IP ACL information:
Port default IP ACL in:
ip access-list 100 in
No outbound ip access-list is set
Syntax: show dot1x ip-acl [all | ethernet <slot/port> | | begin <expression> | exclude
<expression> | include <expression>]
The all keyword displays all dynamically applied IP ACLs active on the device.
Use the ethernet <slot>/<port> parameter to display information for one port.
Displaying information about the dot1x-mac-sessions on
each port
To display information about the dot1x-mac-sessions on each port on the device, enter the
following command.
Syntax: show dot1x mac-session [brief | [begin <expression> | exclude <expression> | include
<expression>]]
Table 163 describes the information displayed by the show dot1x mac-session command.
TABLE 163 Output from the show dot1x mac-session command
This field... Displays...
Port The port on which the dot1x-mac-session exists.
MAC The MAC address of the Client
Username The username used for RADIUS authentication.
Vlan The VLAN to which the port is currently assigned.
Auth-State The authentication state of the dot1x-mac-session. This can be one of
the following.
permit – The Client has been successfully authenticated, and traffic
from the Client is being forwarded normally.
blocked – Authentication failed for the Client, and traffic from the Client
is being dropped in hardware.
restricted – Authentication failed for the Client, but traffic from the Client
is allowed in the restricted VLAN only.
init - The Client is in is in the process of 802.1x authentication, or has
not started the authentication process.
BigIron RX# show dot1x mac-session
Port MAC Username VLAN Auth State ACL|MAC Age
i|o|f
-------------------------------------------------------------------------------
1/1 0050.da0b.8cd7 Mary M 1 DENIED n|n|n 0
1/2 0050.da0b.8cb3 adminmorn 4094 PERMITTED y|n|n 0
1/3 0050.da0b.8bef reports 4094 PERMITTED y|n|n 0
1/4 0010.5a1f.6a63 testgroup 4094 PERMITTED y|n|n 0
1/5 0050.da1a.ff7e admineve 4094 PERMITTED y|n|n 0