C
HAPTER
27
| Authentication Commands
802.1X Port Authentication
– 702 –
show dot1x This command shows general port authentication related settings on the
switch or a specific interface.
SYNTAX
show dot1x [statistics] [interface interface]
statistics - Displays dot1x status for each port.
interface
ethernet unit/port
unit - Stack unit. (Range: 1)
port - Port number. (EC-S4626F: 1-26, EC-S4650F: 1-50)
COMMAND MODE
Privileged Exec
COMMAND USAGE
This command displays the following information:
◆ Global 802.1X Parameters – Shows whether or not 802.1X port
authentication is globally enabled on the switch (page 695).
◆ Authenticator Parameters – Shows whether or not EAPOL pass-through
is enabled (page 694).
◆ 802.1X Port Summary – Displays the port access control parameters
for each interface that has enabled 802.1X, including the following
items:
â–
Type – Administrative state for port access control (Enabled,
Authenticator, or Supplicant).
â–
Operation Mode–Allows single or multiple hosts (page 697).
â–
Control Mode– Dot1x port control mode (page 698).
â–
Authorized– Authorization status (yes or n/a - not authorized).
◆ 802.1X Port Details – Displays the port access control parameters for
each interface, including the following items:
â–
Reauthentication – Periodic re-authentication (page 698).
â–
Reauth Period – Time after which a connected client must be re-
authenticated (page 699).
â–
Quiet Period – Time a port waits after Max Request Count is
exceeded before attempting to acquire a new client (page 699).
â–
TX Period – Time a port waits during authentication session before
re-transmitting EAP packet (page 700).
â–
Supplicant Timeout – Supplicant timeout.
â–
Server Timeout – Server timeout.
â–
Reauth Max Retries – Maximum number of reauthentication
attempts.
â–
Max Request – Maximum number of times a port will retransmit an
EAP request/identity packet to the client before it times out the
authentication session (page 696).