xvii
Static Multicast Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-14
Protocol Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-15
Configuring Traffic/Security Filters . . . . . . . . . . . . . . . . . . . . . . . . . . 12-16
Configuring a Source-Port Traffic Filter . . . . . . . . . . . . . . . . . . . . . . 12-17
Example of Creating a Source-Port Filter . . . . . . . . . . . . . . . . . . 12-18
Configuring a Filter on a Port Trunk . . . . . . . . . . . . . . . . . . . . . . 12-18
Editing a Source-Port Filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-19
Configuring a Multicast or Protocol Traffic Filter . . . . . . . . . . . . . . 12-20
Filter Indexing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-21
Displaying Traffic/Security Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-22
13 Configuring Port-Based and
User-Based Access Control (802.1X)
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-1
Why Use Port-Based or User-Based Access Control? . . . . . . . . . . . . 13-1
General Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-1
User Authentication Methods . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-2
802.1X User-Based Access Control . . . . . . . . . . . . . . . . . . . . . . . . 13-3
802.1X Port-Based Access Control . . . . . . . . . . . . . . . . . . . . . . . . 13-3
Alternative To Using a RADIUS Server . . . . . . . . . . . . . . . . . . . . . 13-4
Accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-4
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-4
General 802.1X Authenticator Operation . . . . . . . . . . . . . . . . . . . . . . 13-8
Example of the Authentication Process . . . . . . . . . . . . . . . . . . . . . . . . 13-8
VLAN Membership Priority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-9
General Operating Rules and Notes . . . . . . . . . . . . . . . . . . . . . . . . . . 13-11
General Setup Procedure for 802.1X Access Control . . . . . . . . . . 13-13
Do These Steps Before You Configure 802.1X Operation . . . . . . . . 13-13
Overview: Configuring 802.1X Authentication on the Switch . . . . . 13-16
Configuring Switch Ports as 802.1X Authenticators . . . . . . . . . . . 13-17
1. Enable 802.1X Authentication on Selected Ports . . . . . . . . . . . . . 13-18
A. Enable the Selected Ports as Authenticators and Enable
the (Default) Port-Based Authentication . . . . . . . . . . . . . . . . . . 13-18